Section 5.3 Importance of Policies to Organizational security Flashcards

1
Q

What is a basic security principle that ensures that no single person can control all the elements of a critical function or system?

A

Separation of Duties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the concept that employees are rotated into different jobs, or tasks are assigned to different employees?

A

Job Rotation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What policy increases the physical security of data by requiring employees to limit what is on their desk to what they are working on at the present time?

A

Clean Desk Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a legal contract intended to cover confidentiality? The scope of this agreement will vary based on situation.

A

Non-Disclosure Agreement (NDA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What policy states that all potential employees should be thoroughly screened with an extensive background check before being hired and granted network access?

A

Background Checks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What policy describes how the employees in an organization can use company systems and resources, including software, hardware, and access?

A

Acceptable Use Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What policy does not allow one person to be in one position for a long period of time?

A

Job Rotation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What policy requires employees (especially those in sensitive areas) to take their vacations?

A

Mandatory Vacation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is used in computer-based training (CBT) to provide employees with a question/challenge? Can help to gauge learner retention of the information presented.

A

Gamification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a security related competition where someone is trying to hack into a resource to gain access to data?

A

Capture the flag

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is it called when false phishing emails are sent to employees by IT using a service that measures response? (pass/fail)

A

Phishing Simulations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What do you call self-paced training available via computer, whether for job role or skill enhancement?

A

Computer-based training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is it called when the company carries out related training specific to a user’s specific job role?

A

Role-based Training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is used between two companies who want to participate in a business venture to make a profit? Details how much each partner’s contributions, rights and responsibilities, as well as the details of operations, decision making, and sharing profits.

A

Business Partnership Agreement (BPA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a formal agreement between two or more parties indicating their intention to work together toward a common goal? More formal alternative to handshake but lacks the binding power of a contract.

A

Memorandum of Understanding (MOU)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is similar to an MOU but serves as a legal document and describes terms and details of the agreement?

A

Memorandum of Agreement (MOA)

17
Q

What provides a way for an organization to evaluate the quality of the process used in their measurement systems? Will assess the measurement process itself, and then calculate any uncertainty or variation in the measurement process.

A

Measurement Systems Analysis

18
Q

What is the point at which a vendor stops selling a product and may limit replacement parts and support?

A

End of Life

19
Q

What is the point at which the product is no longer sold by the manufacturer, updates cease, and support agreements are not renewed?

A

End of Service Life