Domain1: laws Regulations & Compliance and investigations Flashcards
What 3 main security objectives of security fundamentals?
- Availability
- Integrity
- Confidentiality
3 example of Tangible assets
*Computers
*Facilities
*Supplies
3 example of Intangible assets
*Reputation
*Data
*Intellectual property
What is risk analysis? explain
Risk Analysis is a part of overall Risk Management. Risk Analysis is used to determine whether security is cost effective, relevant, timely and responsive to threats. Risk Analysis helps prioritize their risks and how much money should be spent to safeguard against risks
Steps in risk analysis
- Risk Identification
* Determine risks, identify hazards,
* Who or what can be harmed and how? - Implement policies and controls
- Monitor systems and practices involved
- Promote awareness
Risk analysis process
Step 1: Asset and Information Value
Assignment
Step 2: Risk Analysis andAssessment
Step 3: Countermeasure Selection
and Implementation
3 types of security policies
*Organizational Policy
*Issue Specific Policy
*System Specific Policy
What is security policy?
An overall general statement produced by senior management that dictates what role security plays within the organization
Security program lifecycle
- Plan & Organize
- Implement
- Operate & Maintain
- Monitor & Evaluate
Who appoints a Security Officer (CSO and/or CISO)?
Senior management appoints a Security Officer (CSO
and/or CISO).
Six principal of cobit
- Meet stakeholder needs,
- Holistic approach,
- Dynamic governance system,
- Distinct governance from management,
- Tailored to enterprise needs,
- End-to-end governance system
Domains of COBIT
- Plan and Organize
- Acquire and Implement
- Deliver and Support
- Monitor and Evaluate
What is security Governance?
Information security governance is all of the tools, personnel and
business processes that ensure that security is carried out to meet an organization’s specific needs”
Committee of Sponsoring Organizations of the Treadway Commission (COSO) Areas:
- Control Environment
- Risk Assessment
- Control Activities
- Information and Communication
- Monitoring
Fullform of ITIL
The Information Technology
Infrastructure Library