Domain 5 Task Statements Flashcards
Domain 5—Protection of Information Assets (25%)
Provide assurance that the organization’s policies, standards, procedures and controls ensure the confidentiality, integrity and availability of information assets.
T5.1
Evaluate the information security and privacy policies, standards and procedures for completeness, alignment with generally accepted practices and compliance with applicable external requirements.
T5.2
Evaluate the design, implementation, maintenance, monitoring and reporting of physical and environmental controls to determine whether information assets are adequately safeguarded.
T5.3
Evaluate the design, implementation, maintenance, monitoring and reporting of system and logical security controls to verify the confidentiality, integrity and availability of information.
T5.4
Evaluate the design, implementation and monitoring of the data classification processes and procedures for alignment with the organization’s policies, standards, procedures and applicable external requirements.
T5.5
Evaluate the processes and procedures used to store, retrieve, transport and dispose of assets to determine whether information assets are adequately safeguarded.
T5.6
Evaluate the information security program to determine its effectiveness and alignment with the organization’s strategies and objectives.