Chapter 4 Flashcards

1
Q

3 basic rules when making a policy:

A
  • Policy shouldn’t conflict with the law.
  • Policy must be able to stand in court.
  • Policy should be supported and administered.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 4 Bulls-eye model layers?

A
  • Policies.
  • Networks.
  • Systems.
  • Applications.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Explain the difference between the following:
1- Policy
2- Standard
3- Guidelines
4- Procedures
5- Practices

A

1- policy is the guidelines for behavior in an organization.

2- standards are specifications in how the policy should be followed.

3- guidelines are non-mandatory recommendations.

4- procedures are step-by-step instructions to help follow policies.

5- practices are examples of actions that follow policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are 6 guidelines for effective policy? / How to make policies effective?

A

1- approved by management.
2- properly spread.
3- read.
4- understood.
5- agreed-to.
6- fairly enforced.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 3 types of IS policy?

A
  • Enterprise IS program policy.
  • Issue-specific IS policy.
  • System-specific policy.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What’s “Enterprise Information Security Policy” (EISP)?

A

It sets the strategic direction of the organization’s security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What’s “Issue-specific IS policy” (ISSP) and it’s elements?

A

It provides guidance and regulation for usage of IT.

ISSP elements:
- Statement of purpose.
- Authorized usage.
- Prohibition.
- System management.
- Violations of policy.
- Policy review and updates.
- Limitations of liability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What’s “System-specific policy” (SysSP) and it’s elements?

A

They often function as procedures that are used when configuring or maintaining systems.

2 types of SysSP’s:
– Managerial guidance
– Technical specifications
Or combined in a single document.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

2 types of SysSP’s:

A

– Managerial guidance
– Technical specifications
Or combined in a single document.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are “Managerial Guidance SysSP’s”?

A
  • Created by management
  • Guides implementation of tech.
    -Informs technologists of management intent.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are “Technical specification SysSPs”?

A

It’s the system admins directions on implementing managerial policy.

Has 2 methods:
- Access Control Lists (ACLs).
- Configuration rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Name and explain the 2 methods for Technical specification SysSPs:

A

1- Access control lists: enables restricted access according to user, computer, time, etc.

2- Configuration rules: instructional codes that guide the execution of the system when information is passing through it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What can ACLs regulate?
Name 4:

A
  • Type of user. (Who)
  • Time. (When)
  • Location. (Where)
  • Device. (How)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

It is useful to view policy development as a 3 part project.
Explain the 3 parts of developing policy:

A

1- The policy is designed and written.
2- then, formal approval to the policy by the management.
3- lastly, the policy is applied in the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How is policy distribution done?

A

Can be distributed by:
- hard copy.
- electronic.

*The organization must prove that the policy reached the end user.

*Destruction of old versions must be done to assure confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are some barriers to policy reading?
name 2:

A

There can be language barriers, and visually impaired employees that require additional assistance.

17
Q

You have to be certain that employees can comprehend the policy.
How do u make sure that is the case?

A

Scored quizzes and exams.

18
Q

Why do we need policy?

A

to inform what is and is not acceptable behavior in the organization and increase productivity.