IT Security Department Flashcards
1
Q
What is the cycle that a security department runs?
A
Validation and Remediation. (after establishment)
2
Q
What is included in Security Validation?
A
- Technology Aspect, most urgent technologies you need to implement IE training program if you have a lot of phishing attacks.
- Network configuration. Find all misconfigurations that make you vulnerable.
- Patching, validate that all security updates and updating with all software inside organization.
3
Q
What is the human factor in security validation?
A
Make sure employees have correct education. Make sure people are using passwords, managing domain admins correctly. IF you arne’t doing it right you are opening up yourself to vulnerabilities.
4
Q
What percentage is spent on validation vs remediation?
A
10% Validation, 90% Remediation
5
Q
What are the three pieces needed for REAL security validation?
A
- Comprehensiveness, needs to be conducted across the entire network.
- Continuous, IT infrastructure is chaning all the time, it is not enough to have a yearly cycle. Dynamic changes need to be followed up on, also there is a growing list of attacks.
- Zero false positives or negatives. In other words, dont be spending limited resources on remediations that aren’t necessary.