Module 2.1 Flashcards

1
Q

What are the tasks of the CISO and Information security team?

A

1) Creation of a strategic plan
2.) How security objectives will be implemented

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are policies?

A

laws within an organization still has penalties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the three principles to take note of in governance

A

oversight (covers everything)
accountability
strategic perspective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the goals of information security governance

A

1) Strategic alignment (if IS supports business objectives)
2) Risk management (have appropriate measures to manage threats)
3) Resource management (using information security resources properly)
4) Performance measurement (measuring information security metrics)
5) Value delivery (optimizing IS investments)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 4 governance committees

A

IT Strategy, Information Security, Change Control Board, Internal Audit (quality assurance people)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the four major organizational changes

A

Labor disruptions, Acquisitions, Reorganization, and Divestitures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

RACI Model

A

R - Responsible (task-oriented)
A - Accountable (final authority)
C - Consulted (insights for the team)
I - Informed (should be updated but isn’t directly part)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the difference between information owners and systems owners

A

Information Owners = owns the info (data)
System Owners = works on the system (data analyst)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the roles of IT Security

A

Custodian - highest access, managers
Developer - make systems
Auditor - check the system to ensure that they are policy compliant
User - end user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the security frameworks

A

Authoritative - strict
Auditable - technical frameworks
Holistic - overall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the purpose of frameworks

A

To know if you’re doing the right things, marketing (our company uses these frameworks), development of security framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

ISO 27000

A

IT Security Standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

OWASP

A

Open Web Application Security Project

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

PCI-DSS / PA-DSS

A

Payment Application Data Security Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly