Prelim - security policy Flashcards
What are the key characteristics of an effective Information Security Policy?
Cover end-to-end security processes
Be enforceable and practical
Regularly updated to address business needs and threats
Align with business goals
Explain the hierarchy of security documentation.
Policies (e.g., Access Control, Personal Security, Physical Security)
Standards (e.g., Encryption Standard, Information Disposal, Baseline Standards)
Procedures -Technical Controls (e.g., Incident Response, Employee Termination, IT System Settings )
Policies
To reduce risk and protect information
The purpose:
Standards
The how, how will be implemented, who is responsible, who will be affected
Procedures – Technical Controls
Step by step instruction that people will follow
Instructions
What is the 3-2-1 backup rule?
3 copies of data
2 different storage media
1 copy stored off-site
Name the three principles of information security (CIA Triad).
Confidentiality (accessible only to authorized parties)
Integrity (data remains complete and unaltered)
Availability (data is accessible when needed)
What are the two primary ISO information security standards?
ISO 27001
ISO 27002
List four types of information security.
Application Security
Network Security
Cloud Security
Cryptography
What are the key elements of an Information Security Policy?
Purpose, Audience, Objectives
Access Control, Data Classification
Security Training, Employee Responsibilities
Encryption, Backup Policies, Compliance References
What is the purpose of security standards?
To provide detailed guidance for implementing policies organization-wide.
Name three benefits of a strong security culture.
Reduced risk of breaches
Increased employee compliance
Proactive reporting of security concerns
What are the 7 dimensions of security culture?
Attitudes
Behaviors
Cognition
Communication
Compliance
Norms
Responsibilities
Why do companies need to meet information security standards?
Prevent cyberattacks
Avoid legal fines
Enhance reputation
Increase risk awareness
What are the benefits of a strong Security Culture?
- Increased compliance with protective measures
- Reduced risk of security incidents
- Employees identify and report concerns
- Greater sense of security among employees
- Enhanced security without large expenditure
What defines Security Culture?
Ideas, customs, and social behaviors of a group that influence its security