security Governance: policies standards and procedures Flashcards

1
Q

what is the characteristics of policies?

A

organization wide, high level and broad scoped
deigned for long terms (several years)

they are few in number, they’re high lvl and broad natured

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what is standard

A

rules to achieve the intent of the policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

which one has the greater number polices or standards?

A

There’s more standards than polices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what are procedure?

A

specific steps
train employees and ensure consistency in security related business processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what are guidelines

A

it ranked the same lvl as procedure.
it’s optional recommendation, which mean they are suggest best practices, but not mandatory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

why is risk important?

A

if you missed risk that i likely to materialized, your information security policy would have serious flaw.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

legal and regulatory

A

every industry has it own set of legal and regulatory compliance requirement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

enforcement

A

your policies should have a clear identify instance which are considered as violations and the penalties associated with them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

why is staff engagement important?

A

because they can help streamline the policy and they can sometimes identify issues that might have been over looked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

why is employee training important

A

you can have the best policy in the world. if you were employees are not properly trained. it is useless. which is why it’s important to have training workshop to refresh your employees knowledge.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

management support

A

if policies are written and visible, employees are more likely to follow it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly