Chapter 3 Flashcards
What are the keywords for chapter 3?
authorities, external organizations, organizational structure, reporting structure, roles and responsibilities
What are the key factors in determining the security organizational structure of a company?
mission, risk appetite, culture, size, budget
It an org’s mission the most important factor to determine it’s security structure?
yes
What are the risk-appetite factors of a risk-averse org?
more technical controls, higher tech cost, large security organization, emphasis on asset governance and management
smaller number of assets to protect, outsourcing of asset hosting, smaller staff, more emphasis on asset governance is characteristic of what risk level?
risk willing
What are the two types of cultures that determine an org’s security structure?
authoritative culture and open-minded/free culture
Characteristics of an authoritative culture are
large org with a variety of security tools, high data protection measures, high protection against malware and attacks, heavy emphasis on following compliance and regulations
Characteristics of an open-minded/free culture are
work from home/byod policies, no unified OS or app use, heavy collaboration between disparate teams, Open source intellectual properties, free intellectual property, emphasis on availability and integrity of assets more than protection of them, smaller staff, importsant assets are assets with code
What are the org sizes that determine a security team’s structure?
small organization and large organization
Characteristics of a small organization are
limited budgets, lack of specialized teams and roles, jack of all trade team members, great dependence on vendor support for difficult problems and large projects
Characteristics of large organizations are
teams and roles segmented by product and specialty, larger budgets, less reliance on vendor support
characteristics of small budgets are
usually associated with small orgs, cost to equip and train have to be low, may be staffed by volunteers and students
what are the characteristics of a large budget?
multiple levels of staff and clear organizational hierarchy, heavy cost to support and train large teams , need to ensure rules and responsibilities are clear
what are the organizational options for security teams to report to?
cep, cio, GRC (governance, risk, and compliance),cso, ciso , legal department, cfo, cto, coo
What are the best organization positions that the security team should report to?
CSO and CISO
Why are CSO and CISOs the best positions for the security team to report to?
Brings direct support to security teams and removes the need for the security team to compete for a seat at the decision table
Why is reporting to the CEO and CIO the worst option for the security team?
Having opposing IT and security team viewpoints reporting to the same CIO could lead to conflict between the teams.
Should the security team hamper business? Why or why not?
Security teams should not hamper business. If the security team looks obstructionist it could lead to the business not taking the security team’s advice. Don’t say no, say Let me see how I can help you securely achieve that goal”.
How can reporting to the GRC (government , risks, and compliance) impede the security team?
GRC tends to favor regulatory and risk perfection which could slow the completion of security projects and task achievement
How can reporting to the GRC (government, risks, and compliance) help the security team?
helps align security team’s task with business objectives and give the team quick access to risk identification