F. Business Model for Information Security (BMIS) Flashcards

1
Q

What is Business Model for Information Security (BMIS)

A

A guide developed by ISACA for business-aligned, risk based security governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the use of BMIS do

A

It helps security leadership ensure that the organization’s security program continues to address emerging threats, developing regulations, and changing business needs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

element of IT model

A

People, process, technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

elements of BMIS model

A

It’s a three-dimensional, three-sided pyramid which includes element of IT model (people, process, technology) and a fourth element i.e. organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Element of organization

A

Culture, governing, Architecture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the apex (highest) element of the BMIS pyramid

A

The organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How are the elements of BMIS model connected

A

By dynamic interconnections which are culture, governing, architecture, emergence, enabling and support, and human factors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Organization as element of BMIS model

A

Organization is viewed as a network of people interacting using processes to channel this interaction.
Organization includes permanent staff, temporary staff, contractors, people of outsourced organizations, third parties that play a role in helping the organization achieve its objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Defining the people element in the BMIS

A

They represent all of the people in an organization, including people in outsources organizations that do business with the entity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Defining the process element in the BMIS

A

It’s the formal structure of all defined activities,

Process defines practices and procedures that describe how activities are to be carried out.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is an effective process per ISACA’s Risk IT framework?

A

A reliable and repetitive collection of activities and controls to perform a certain task.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Defining the Technology element in the BMIS

A

It’s represents all of the systems, application, and tools used. It’s a powerful enabler of an organization’s processes and its strategic objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Defining culture in the dynamic interconnection of the organization

A

Culture is a pattern of behaviors, beliefs, assumptions, and ways of doing things.

Culture connects the organization and people elements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Why is culture the most critical factors in the success or failure of an information security program

A

Because culture reflects the attitudes, habits, and customs adopted by the people in the organization. Culture cannot be legislated or controlled directly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Civil culture in which organization resides

A

It plays a large role in sharping role the organization’s culture.

It makes it difficult for organization that have many global or regional location to establish a single culture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Defining governing in the dynamic interconnection of the organization

A

Set of responsibilities and practices exercised by the board and executives management with the goal of providing strategic direction.

Governing connects organization and process elements.

17
Q

Tools used in government

A

Policies, standards, guidelines, process documentation, resources allocation, compliance.

18
Q

What is vital in governing dynamic interconnection

A

Communication is.

19
Q

Defining Architecture in the dynamic interconnection of the organization

A

As systems and software engineering.

Architecture connects the organization and technology elements.

20
Q

What does the practice of architecture ensure

A

Alignment, consistency, efficiency, low cost, resilience, flexibility, stability, and security.