Section 5.3 Importance of Policies to Organizational security Flashcards
What is a basic security principle that ensures that no single person can control all the elements of a critical function or system?
Separation of Duties
What is the concept that employees are rotated into different jobs, or tasks are assigned to different employees?
Job Rotation
What policy increases the physical security of data by requiring employees to limit what is on their desk to what they are working on at the present time?
Clean Desk Policy
What is a legal contract intended to cover confidentiality? The scope of this agreement will vary based on situation.
Non-Disclosure Agreement (NDA)
What policy states that all potential employees should be thoroughly screened with an extensive background check before being hired and granted network access?
Background Checks
What policy describes how the employees in an organization can use company systems and resources, including software, hardware, and access?
Acceptable Use Policy
What policy does not allow one person to be in one position for a long period of time?
Job Rotation
What policy requires employees (especially those in sensitive areas) to take their vacations?
Mandatory Vacation
What is used in computer-based training (CBT) to provide employees with a question/challenge? Can help to gauge learner retention of the information presented.
Gamification
What is a security related competition where someone is trying to hack into a resource to gain access to data?
Capture the flag
What is it called when false phishing emails are sent to employees by IT using a service that measures response? (pass/fail)
Phishing Simulations
What do you call self-paced training available via computer, whether for job role or skill enhancement?
Computer-based training
What is it called when the company carries out related training specific to a user’s specific job role?
Role-based Training
What is used between two companies who want to participate in a business venture to make a profit? Details how much each partner’s contributions, rights and responsibilities, as well as the details of operations, decision making, and sharing profits.
Business Partnership Agreement (BPA)
What is a formal agreement between two or more parties indicating their intention to work together toward a common goal? More formal alternative to handshake but lacks the binding power of a contract.
Memorandum of Understanding (MOU)