Sec+ Chapter 16: Security Policies, Standards, and Compliance Flashcards
NIST
National Institute of Standards for Technology
ISO
International Organization for Standardization
Information security policy framework
Series of documents that describe an orgs cybersecurity program and contain:
1) Policies
2) Standards
3) Procedures
4) Guidelines
Policies
High level statements of management intent
EX: InfoSec policy, AUP, Data governance policy, Data classification policy, Data retention policy, Credential management policy, Password policy, Continuous monitoring policy, Code of conduct, Asset management
Standards
Requirements that describe how an org will carry out its InfoSec policies
EX: Configuration settings for common OS, controls for highly sensitive info, etc
Procedures
Detailed step by step processes that individuals or orgs must follow in specific circumstances
A consistent process for achieving a security objective
EX: Monitoring procedures, Evidence production procedures, Patching procedures
Guidelines
Best practices and recommendations related to a given concept, tech, or task
Least privilege
People should only get the minimum set of permissions they need to carry out their job
Separation of duties
Takes two different and sensitive tasks and creates a rule that no single person may have the privileges required to perform both tasks
EX: One person has half the safe combo, another person has the other half
Two person control
Requires the participation of two people to perform a single action
Job rotation
Takes employees with sensitive roles and periodically moves them to other positions in the organization
Mandatory vacations
Forces employees to take annual vacations of a week or more consecutive time, revoking their access privileges during that time
A way we can identify fraud, especially in high security environments
Clean desk policy
Limits the amount of paper left exposed on unattended desks
Any time you get up from your desk, you have to clean your desk and lock everything away
MSA
Master service agreement
Umbrella contract for the work a vendor does with an org over extended period of time
SLA
Service level agreement
Specifies the conditions of service provided by the vendor and the remedies to the customer if the vendor fails to meet the SLA
EX: Uptime or response time agreements