security Governance: policies standards and procedures Flashcards
what is the characteristics of policies?
organization wide, high level and broad scoped
deigned for long terms (several years)
they are few in number, they’re high lvl and broad natured
what is standard
rules to achieve the intent of the policy
which one has the greater number polices or standards?
There’s more standards than polices
what are procedure?
specific steps
train employees and ensure consistency in security related business processes
what are guidelines
it ranked the same lvl as procedure.
it’s optional recommendation, which mean they are suggest best practices, but not mandatory
why is risk important?
if you missed risk that i likely to materialized, your information security policy would have serious flaw.
legal and regulatory
every industry has it own set of legal and regulatory compliance requirement
enforcement
your policies should have a clear identify instance which are considered as violations and the penalties associated with them
why is staff engagement important?
because they can help streamline the policy and they can sometimes identify issues that might have been over looked
why is employee training important
you can have the best policy in the world. if you were employees are not properly trained. it is useless. which is why it’s important to have training workshop to refresh your employees knowledge.
management support
if policies are written and visible, employees are more likely to follow it