IT Security Department Flashcards

1
Q

What is the cycle that a security department runs?

A

Validation and Remediation. (after establishment)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is included in Security Validation?

A
  1. Technology Aspect, most urgent technologies you need to implement IE training program if you have a lot of phishing attacks.
  2. Network configuration. Find all misconfigurations that make you vulnerable.
  3. Patching, validate that all security updates and updating with all software inside organization.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the human factor in security validation?

A

Make sure employees have correct education. Make sure people are using passwords, managing domain admins correctly. IF you arne’t doing it right you are opening up yourself to vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What percentage is spent on validation vs remediation?

A

10% Validation, 90% Remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the three pieces needed for REAL security validation?

A
  1. Comprehensiveness, needs to be conducted across the entire network.
  2. Continuous, IT infrastructure is chaning all the time, it is not enough to have a yearly cycle. Dynamic changes need to be followed up on, also there is a growing list of attacks.
  3. Zero false positives or negatives. In other words, dont be spending limited resources on remediations that aren’t necessary.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly