Governance Flashcards
IT Governance
A comprehensive security management framework
Policy (Security)
*Defines the role of security inside of an organization
*Establishes the desired end state for that program
Organizational Policy (Security)
*Meet business goals
*Define the roles, responsibilities, and terms associated with it
System-specific Policy (Security)
Addresses the security o a specific technology, application, network, or computer
Issue-specific Policy (Security)
Addresses a specific security issue *Email privacy,
*Employee termination procedures *Other specific issues
Standard (Sec Policy)
Implements a policy in an organization
Baseline (Sec Policy)
Creates a reference point in network architecture and design
Guideline (Sec Policy)
Recommended action that allows for exceptions in unique situations
Procedure (Sec Policy)
Detailed step-by step instructions to perform a give task or series of actions
Change Management
Structured way of changing the state of a computer system, network, or IT procedure
Incident Response Plan
Instructions to detect, respond to , and recover from security incidents
Steps of an Incident Response Plan
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Lessons learned
Business Continuity Plan
- How a business will continue operating during an unplanned disruption
- Long-Term
- Contains a Disaster Recovery Plan
System Life Cycle Plan
Describes the approach to maintaining an asset from creation to disposal
Planning
Planning and requirement analysis for a system, including architecture outlining risk identification
Standard Operating Procedure
Step-by-step instructions to carry out routine operations