Chapter 3 Flashcards

1
Q

What does a CISO do?

A
  • Creates strategic IS plan.
  • Suggests IS solutions to protect business activities.
  • Improving IS by managing and planning.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What’s a Security Systems
Development Life Cycle (SecSDLC)?

A

a methodology for the design and
implementation of an information system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 6 steps in SecSDLC?

A
  1. Investigation.
  2. Analysis.
  3. Logical Design.
  4. Physical Design.
  5. Implementation.
  6. Maintenance.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What’s “Investigation” in SecSDLC?

A

budgeting, and defining the scope and goals, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What’s “Analysis” in SecSDLC?

A

Analyzing existing security
policies, programs and threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What’s “Logical Design” in SecSDLC?

A

Developing a blueprint and policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What’s “Physical Design” in SecSDLC?

A

Evaluating the blueprint and agreeing on a final design.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What’s “Implementation” in SecSDLC?

A

Implementing and testing the security program.
An employee signature of acknowledgement is important.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What’s “Maintenance” in SecSDLC?

A

Keeping the program up to date.
Includes a report mechanism for users with complaints or suggestions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly