Domain 1 Flashcards
process of how an org is managed. Includes all aspects of how decisions are made for that org and can include policy, roles, and procedures the org uses to make those decisions.
governance
the entirety of the polices, roles, and processes the org uses to make security decisions, Specific to its purpose and objectives
security governance
Makes strategic decisions and which policies are required for all corp
legislation
Might impose corp mandate for part types of decisions
Board of directors
Might dictate who within the corp participate and finalizes part decisions
Local and federal regulators
Typically responsible for mandating policy , determining strategic goals for the org, and making final determination according to the org governance for both security and non-security.
Senior management
Responsible for advising senior management on security matters, may assist in drafting policies , manages day-to-day security operations represents the org security needs in groups and meetings, selects and contracts for security products , and may manage the incident and disasters response.
Security manage, director, or officer
Tasked with performing the security processes and activities with the org.
Security personnel
Recognized globally, know as ISMS, comprehensive holistic view of security governance within an org. Mostly focused on policy.
ISO 27001
comprehensive list of security controls
ISO 27002
Created and maintained by ISACA, Designed in a way to manage and document enterprise IT and Security functions for an org. Attending to address IT performance, security ops, risk management, and regulatory compliance
COBIT
IT service delivery set of best practices. Concentrates on how an org it env should enhance and benefit its business goals.
ITIL
Legal concept pertaining to the duty owed by a provider to a customer.
Due care
An activity used to demonstrate or provide due care.
Due diligence
publishing a policy is an insufficient form of due diligence. What must you have?
To meet the legal duty, an org must also have a documented monitoring and enforcement capability in place and active to ensure the org is adhering to the policy.