Lesson 14: Summarize Security Governance Concepts Flashcards

1
Q

What are policies, and what do they support?

A

High-level documents defining security commitments, ensuring compliance, and supporting governance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Can you give examples of common security policies?

A

Examples: Acceptable Use Policy (AUP), Incident Response, Business Continuity, and Disaster Recovery policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the purpose of guidelines?

A

Flexible recommendations to support policy implementation, providing best practices for tasks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are procedures, and why are they important?

A

Step-by-step instructions ensuring tasks align with policy, promoting consistency and efficiency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How does personnel management contribute to security?

A

Through recruitment, onboarding, and termination policies that ensure security and compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is critical during onboarding?

A

Background checks,
Secure transmission of credentials,
Asset allocation,
Training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does offboarding prevent security risks?

A

By disabling accounts, retrieving company assets, and revoking privileges.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What frameworks establish compliance and security benchmarks as industry standards?

A

ISO/IEC 27001, NIST SP800-63, PCI DSS, and GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are internal standards focused on?

A

Organizational practices ensuring consistent access control, encryption, and physical security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are playbooks used for in security operations?

A

Providing centralized strategies for consistent operations, incident response, and continuous improvement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What do change management programs handle?

A

Changes to software, configurations, infrastructure, and updates with robust planning and risk assessment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the purpose of impact analysis in change management?

A

o evaluate the implications of proposed changes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why are test results and backout plans necessary?

A

To ensure changes can be reversed if they cause issues.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How can you reduce confusion regarding documentation?

A

Keep the documentation (policies, diagrams, and procedures) up to date in order to improve accuracy and reduce confusion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Why is it critical to consider dependencies in change management?

A

Its critical to consider interconnections between services to avoid unintended outages.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What challenges do legacy systems pose in change management?

A

Outdated technology, lack of vendor support, and extensive customizations, requiring cautious management.

17
Q

How does automation benefit security operations?

A

It reduces manual tasks, improves efficiency, and combats operator fatigue.

18
Q

What are some tasks that can be automated?

A

You can automate baseline enforcement, vulnerability scanning, patching, and ticket generation for improved detection and response times.

19
Q

What is the purpose of provisioning in automation?

A

To automate resource allocation.

20
Q

How does automation support continuous integration and testing?

A

When you are automating you are code testing and the more you do it you are able to improve the quality of the automation/code.

21
Q

What role do APIs play in automation?

A

APIs enhance workflows and system communication, ensuring seamless integration between applications.

22
Q

What challenges can arise during automation implementation?

A

High initial cost, complexity, risk of single points of failure, and technical debt.

23
Q

What benefits does automation provide?

A

Enforces standard configurations, improves compliance, streamlines auditing, and strengthens governance.