Chapter 7: Security Governance Processes Flashcards
Understand Governance Processes
{Blank} are the bedrock documents that provide the foundation for an organization’s information security program. They are often developed over a long period of time and carefully written to describe an organization’s security expectations.
Compliance with policies is mandatory, and policies are often approved at the very highest levels of an organization.
Security Policies
{Blank} prescibe the specific details of security controls that the organization must follow. They derive their authority from policy.
Even though they might not go through as rigorous a process as policies, compliance with them is still mandatory.
Security Standards
Security professionals use {blank} to provide advice to the rest of the organization, including best practices for information security.
These are advice and compliance with them are not mandatory.
Security Guidelines
{Blank} are step-by-step instructions that employees must follow when performing a specific security tasks. Compliance with this is mandatory.
Security Procedures
Compliance with policies, standards, and procedures is always {blank}.
Mandatory
Complying with guidelines is {blank}.
Optional
What are the common types of security documents?
Polices, Standards, Guidelines, and Procedures
{Blank} regulates the storage, processing, and transmission of credit and debit card information.
Payment Card Industry Data Security Standard (PCI DSS)
Your organization is planning to accept credit cards for the first time and you are concerned about the regulations that may affect this processing. You already handle a large amount of personally identifiable information (PII). Which new regulation is m ost likely to affect your organization?
A. GDPR
B. PCI DSS
C. CCPA
D. HIPAA
PCI DSS
YOuare writing a document that explains the step-by-step process that your organization’s help desk should follow when helping a user reset a forgotten password. Which type if document are you creating?
A. Policy
B. Standard
C. Procedure
D. Guideline
Procedure
{Blank} governs protected health ingormation (PHI).
Health Insurance Portability and Accountability Act (HIPAA)
The European Union says that thier {blank} applies to the personal information of all EU residents, wherever they might be located.
General Data Protection Regulation (GDPR)