Module 5: L1 Flashcards

1
Q

What are some processes an organization needs to have specific information security plans for (5x)?

A
  1. Document preparation and review
  2. Online transactions
  3. Inventory control
  4. Content management
  5. Remote access to databases
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Strategy adjustments have security implications. What are the 3x listed?

A
  1. Systems may change when an intranet is set up
  2. New roles of staff may change access to info
  3. Decentralized use of computers and smart phones
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security must be considered within certain organizational processes like work vs. personal use. What are some of the other considerations mentioned (4x)?

A
  1. Information disclosure rules
  2. Physical security measures
  3. Breach responses and reporting
  4. Prevention of malicious software
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

There are some other ISO norm dimensions mentioned in the lectures like; user access management. What are some others (5x listed)?

A
  1. Management of mobile computing
  2. Management of internet access
  3. Software development implications
  4. Encryption requirements
  5. Contingency planning
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Top management has a central role when implementing IS. What are 3x ways in which they develop organization security objectives?

A
  1. Clarity in policies & procedures: reduce uncertainty in daily activity
  2. Maximize regulatory compliance: set fundamental framework
  3. Responsibility & accountability: transparency and ownership
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are some vehicles for meeting the strategic security objectives?

A
  1. Group cohesiveness: group behavior shapes individual response
  2. Management commitment: reward commitment and compliance
  3. Training and education: improvement requires learning
  4. Ethical and moral values: aspirational environment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Implementing means requires a combination of “_______ _______” and “_______ _______”

A

top down and bottom up

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

T/F: Information security represents another area of uncertainty. It must be held separate from strategic goals.

A

False.

IS is integral to strategic goals. Should not be considered an “add on”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Strategic objectives for IS are _________

A

multidimensional

How well did you know this?
1
Not at all
2
3
4
5
Perfectly