L9 - Security policies and Management Flashcards
What is social engineering?
It’s the study of a target in order to get close enough to it, so that the attacker may either directly get access to the targets system or indirectly by leaving for example a rubber ducky.
What are IT security management concepts?
- Information security governance
- Information security management
- IT Security Operations.
What is information security governance?
It provides a strategic directions, ensures objectives are achieved, manages risks appropriately, use of organisational resources responsibly and monitors the success of failure.
What information security governance is effecive and not?
It’s when all of IT security management is actively working to achieve IT security governance. Ineffective when not.
What are some security policys?
An organizational security policy may include any of these:
* Acceptable use policy
* Risk management policy
* Vulnerability management policy
* Data protection policy
* Access control policy
* Business continuity policy
* Personnel security policy
* Physical security policy
* Secure application development policy
What are the prinicipal problems associated with employee behaviour?
- Errors and omissions
- Fraud
- Actions by disgruntled employees
What is awareness?
Seeks to inform and focus on an employees attention on security issues within their organisation.
How do you address awareness?
- Make employees aware of their responsibilities
- Make employees understand the importance for the well-being of the company.
- Promote enthusiasm and management buy-in.
- Tailor the program to the needs of the organisation
What is ISO?
It’s a general code of practice standars for organisations.
How does ISO 27002 work?
It provides a checklist of general security controls to be considered implemented/used by organisations. It contains 14 categories, each of these categories contains a set of security controls.
Name a few categories in ISO 27002
- Introduction
- Scope
- Information security policies
- Human resources security
- Access control
- Operations security
- Compliance
- etc.
What is ISO 27001?
It specifies specific requirements for establishing, implementing and continually improving a securit management system.
What is the difference between ISO 27002 and 27001
- 27002: defines the security goals and controls.
- 27001: defines how to manage the implementation of security controls.