Chapter 7: Security Governance Processes Flashcards

Understand Governance Processes

1
Q

{Blank} are the bedrock documents that provide the foundation for an organization’s information security program. They are often developed over a long period of time and carefully written to describe an organization’s security expectations.

Compliance with policies is mandatory, and policies are often approved at the very highest levels of an organization.

A

Security Policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

{Blank} prescibe the specific details of security controls that the organization must follow. They derive their authority from policy.

Even though they might not go through as rigorous a process as policies, compliance with them is still mandatory.

A

Security Standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security professionals use {blank} to provide advice to the rest of the organization, including best practices for information security.

These are advice and compliance with them are not mandatory.

A

Security Guidelines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

{Blank} are step-by-step instructions that employees must follow when performing a specific security tasks. Compliance with this is mandatory.

A

Security Procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Compliance with policies, standards, and procedures is always {blank}.

A

Mandatory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Complying with guidelines is {blank}.

A

Optional

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the common types of security documents?

A

Polices, Standards, Guidelines, and Procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

{Blank} regulates the storage, processing, and transmission of credit and debit card information.

A

Payment Card Industry Data Security Standard (PCI DSS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Your organization is planning to accept credit cards for the first time and you are concerned about the regulations that may affect this processing. You already handle a large amount of personally identifiable information (PII). Which new regulation is m ost likely to affect your organization?

A. GDPR
B. PCI DSS
C. CCPA
D. HIPAA

A

PCI DSS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

YOuare writing a document that explains the step-by-step process that your organization’s help desk should follow when helping a user reset a forgotten password. Which type if document are you creating?

A. Policy
B. Standard
C. Procedure
D. Guideline

A

Procedure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

{Blank} governs protected health ingormation (PHI).

A

Health Insurance Portability and Accountability Act (HIPAA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

The European Union says that thier {blank} applies to the personal information of all EU residents, wherever they might be located.

A

General Data Protection Regulation (GDPR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly