Operational Procedures Flashcards
Includes procedures and guidelines for use of network resources written in terms appropriate to the user’s access level and technological knowledge, such as password creation and responsible network use
Acceptable use policies (AUPs)
Govern codified expectations of user privacy and consent to security-based monitoring of user activity.
Privacy policies
Specify exactly what steps will be taken in response to a security incident, in order to minimize and repair damage without exposing the network to further risk.
Incident response policies
Specify the steps that will be taken to secure assets, protect staff, and maintain business operations in terms of natural or artificial disasters and disruptions.
Disaster planning and business continuity
Guidelines for updating policies and procedures to suit changing needs, without introducing new vulnerabilities.
Change management policies
Lists of step by step instructions to perform routine tasks.
Standard operating procedures (standing operating procedures in military organizations)
Regulations for all federal government agencies
FISMA
Regulations for patient data in health care systems
HIPAA
Regulations for corporate financial data
Sarbanes-Oxley (SOX)
Standards for systems handling payment card data
PCI-DSS
Network and system documentation
- Physical and logical diagrams of the network
- A list of IT assets including hardware and software
- Vendor documentation and configuration baselines
for listed assets - Vendor documentation for deployed assets
- Assigned MAC and IP addresses, and available IP
addresses
Managing IT inventory
IT asset management (ITAM)
A way to track all assets in an automated fashion.
configuration management database (CMDB)
The change management process
- Identification
- Change request
- Approval
- Preparation
- Implementation
- Follow-up
Authority to determine whether the request is reasonable and necessary, and to identify any oversights or errors the original proposal might have.
change advisory board (CAB)
A statement describing how management intends the organization is to be run
Policy
A description of best practices or recommendations for achieving a certain policy goal
Guideline
A technical definition of specific methodologies or requirements which are needed to satisfy policies
Standard