Information Security Management Flashcards
Know the description
1
Q
Information Security Management - General Management Practices
A
Purpose - The practice of protecting an organisation by understanding and managing risks to the confidentiality, integrity, and availability of information (CIA)
Establishing - Policies, processes, behaviours, risk management, and controls in relation to authentication, authorisation, encryption, and non-repudiation
Must be driven top-down
Interacts with every other ITIL practice