Information Security Governance Flashcards
Is a guideline discretionary or mandatory?
A guideline is discretionary.
Is a policy discretionary or mandatory?
A policy is mandatory.
All policies should contain what basic components?
Purpose.
Scope.
Responsibilities.
Compliance.
What is the purpose of a policy?
The need for the policy, typically to protect the confidentiality, integrity, and availability of protected data.
What is the scope of a policy?
The scope describes what systems, people, facilities, and organizations are included in the policy. To avoid confusion, any related entities not in scope should be documented.
What is the responsiblities of a policy?
Responsibilities include responsibilities of the information security staff, policy, and management teams as well as all members of the organization.
What is compliance in terms of being one of the basic components of a policy?
Compliance describes two related issues: how to judge the effectiveness of the policies (how well they are working), and what happens when policy is violated (the sanction). All policy must have “teeth”: a policy that forbids accessing explicit content on the Internet is not useful if there are no consequences for doing so.
Are procedures mandatory or discretionary?
Procedures are mandatory.
What is a procedure?
A procedure is a step by step guide for accomplishing a task.
Are standards mandatory or discretionary?
Standards are mandatory.
Why are standards important and necessary?
Standards lower the Total Cost of Ownership of a safeguard. Standards also support disaster recovery.
Are guidelines mandatory or discretionary?
Guidelines are discretionary.
What is a guideline and what is an example?
A guideline is a recommendation or advice. An example of a guideline is “to create a strong password, take the first letter of each word in a sentence, and mix in some numbers and symbols.”
What is a baseline?
Baselines are uniform ways of implementing a standard. “Harden the system by applying the Center for Internet Security Linux benchmarks” is an example of a baseline. The system must meet the baseline described by those benchmarks.
Besides technical risks, what else can pose the biggest risk to an organization?
People can pose the biggest risk to an organization.