Chapter 4 - Policy Flashcards

1
Q

Policy

  • should never conflict with law
  • must be able to stand up in court if challenged
  • must be properly supported and administered
A

..

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Bulls Eye model

A

Policies

Networks

Systems

Applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Policies
Standards
Guidelines
Procedures

A

Policies : Sanctioned by management, defines what you can do and not do

Standards: Detailed minimum specification

Guidelines: Recommendation for compliance

Procedures: Step by step instructions for compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Example

Policies :
Standards:
Guidelines:
Procedures:

A

Policies : Use strong policy, frequently changed

Standards:must be at least 8 characters, with ag least…

Guidelines: We recommend you don’t use family or pet names

Procedures: in order to change your password, first click on the Windows Start button, then …

practices: according to X, most organisations requires employees to change passwords semi annually

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Enterprise infosec policy (EISP), based on and supports organisation’s mission and vision.

Issues specific Infosec policy (ISSP), provides guidance to all members of the organisation regarding the use of IT

System specific infosec policy (SysPs), guides the management and technical specifications of particular technologies and systems.

A

Guidelines for development and implementation:

  1. Develop using industry accepted practices, and formally approved by management
  2. Distributed to all employees
  3. Read by all employees
  4. Understood by all employees
  5. Formally agreed by act of affirmation
  6. Uniformly applied and enforced
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Three general causes lead to unethical and illegal behaviour: ignorance, accident, and intent.

A

Deterrence can be created when three conditions are present:

  1. fear of penalty
  2. probability of being caught
  3. probability of the penalty being applied
How well did you know this?
1
Not at all
2
3
4
5
Perfectly