Chapter 9 - Cyber security processes Flashcards
What does the AICPA framework highlight the importance of governance?
How management must consider tone from the top
IT expertise
Hiring and training of cyber security personnel
Reporting lines and responsibility
What roles are specifically mentioned by the AICPA framework?
Chief information officer
Risk committee
Chief risk officer
Chief technology officer reporting to CIO
Chief information security officer also reporting into the CIO
Why is communication important internally in accordance with AICPA framework?
Policies and procedures
Employee handbook
Training
Escalation procedure
Why is communication important externally in accordance with AICPA framework?
Legal/law enforcement communications
Disclosure policies with third parties
Media communications
What are some methods of protection?
Policies
Software updates
Configurations
Security products
Application software controls
How do we protect networks/systems?
Network configuration management
Firewalls
Antivirus endpoint security
What is blockchain?
Described as a decentralised, distributed and public digital ledger that is used to record transactions across many computers