01. Enterprise Governance Flashcards
(125 cards)
Enterprise Governance
“A process whereby senior management exerrts strategic control over business functions through policies, objectives, delegation of authority, and monitoring”
This is a definition of what fucntion
GOVERNANCE
33
Enterprise Governance
GOVERNANCE is a process whereby senior management exerts strategic control over business functions through what 4 methods
- POLICIES
- OBJECTIVES
- DELEGATION OF AUTHORITY
- MONITORING
33
Enterprise Governance
GOVERNANCE provides the management oversight of the business to ensure business processes effectively meet the organisations business ____ and ____
- VISION
- OBJECTIVES
33
Enterprise Governance
- Organisations usually establish governance through the use of what body of people
- This body of people is usually responsible for seeting what business strategy
- STEERING COMMITTEE
- LONG TERM
- Organisations usually establish governance through steering committees responsible for setting long term business strategy and making changes ot ensure that busines sprocesses continue to support business stragegy and the oragnisations overall needs
33
Enterprise Governance
“Organisations usually establish governance through steering committees responsible for setting long term business strategy and making changes ot ensure that busines sprocesses continue to support business stragegy and the oragnisations overall needs”
This is accomplished through the development and enforcement of what 4 things
- POLICIES
- STANDARDS
- PROCEDURES
- REQUIREMENTS
33
Enterprise Governance
Information security governance typically focuses on several key processes which include;
[ ] Personnel Management
[ ] Vendor hardware selection
[ ] Sourcing
[ ] Risk Management
[ ] Certicication and Training
[ ] Configuration Management
[ ] Change Management
[ ] Operating system selection
[ ] Access Management
[ ] Vulnerability Management
[ ] Team resource size
[ ] Incident Management
[ ] BCP
[X] Personnel Management
[ ] Vendor hardware selection
[X] Sourcing
[X] Risk Management
[ ] Certicication and Training
[X] Configuration Management
[X] Change Management
[ ] Operating system selection
[X] Access Management
[X] Vulnerability Management
[ ] Team resource size
[X] Incident Management
[X] BCP
33
Enterprise Governance
Information Security is a BUSINESS or STRATEGIC issue
BUSINESS
34
Enterprise Governance
The main reason typically cited for an information security business issue is what, in relation to individuals in particular roles
LACK OF UNDERSTANDING AND COMMITMENT
(board of directors and snr. exec)
34
Enterprise Governance
- Many people in a business see information security as what sort of issue
- In order to be successful, information security must be considered what sort of issue
- TECHNOLOGY ISSUE
- PEOPLE ISSUE
34
Enterprise Governance
How can a business be in a position of reduced risk in relation to people at all levels
UNDERSTAND ROLES AND RESPONSIBILITIES
- When people at each level in the organisation understand the importance and impact of information security, their own roles and responsibilities, the organisation will be in a position of reduced risk
34
Enterprise Governance
Information security governance is a set of established activities that helps management understand what 3 things in relation to the organisation
- STATE OF SECURITY PROGRAM
- CURRENT RISKS
- DIRECT ACTIVITIES
34
Enterprise Governance
A goal of the security program is to contribute towards what in relation to the wider business
SECURITY STRATEGY
34
Enterprise Governance
in order for a security governance program to succeed, what else should the business have established and in place
IT GOVERNANCE PROGRAM
34
Enterprise Governance
“The desired capabilities or end states are ideally expressed in achievable, measurable terms”
This is the defnition of what artifact or action that forms part of a healthy security governance program
OBJECTIVES
35
Enterprise Governance
“This is a plan to achieve one or more objectivies”
This is the defnition of what artifact or action that forms part of a healthy security governance program
STRATEGY
35
Enterprise Governance
“At a minimum, ____ should directly reflect the mission, objectives, and goals of the overall organisation”
This is the defnition of what artifact or action that forms part of a healthy security governance program
POLICY
35
Enterprise Governance
“These should flow directly from the organisations mission, objectives and goals. Whatever is most important to the organisation should also be essential to information security”
This is the defnition of what artifact or action that forms part of a healthy security governance program
PRIORITIES
35
Enterprise Governance
“The technologies, protocols, and practices used by IT should align with the organisations needs. On their own, ____ help drive a consistent approac to solving business challenges. A choice of these should facilitate solutions that meet the organisations needs in a cost-effective and secure manner”
This is the defnition of what artifact or action that forms part of a healthy security governance program
STANDARDS
- The choice of standards should facilitate solutions that meet the organisations needs in a cost effective and secure manner
35
Enterprise Governance
“Formalised descriptions of repeated business activities include instructions to applicable personnel. Include one or more procedures and definitions of business records and other facts that help workers understand how things are supposed to be done”
This is the defnition of what artifact or action that forms part of a healthy security governance program
PROCESSES
35
Enterprise Governance
“The are formal descriptions of critical activities to ensure desired outcomes”
This is the defnition of what artifact or action that forms part of a healthy security governance program
CONTROLS
35
Enterprise Governance
“The organisations IT and security programs and projects should be organised and performed in a consistent manner that reflects business priorities and supports the business”
This is the defnition of what artifact or action that forms part of a healthy security governance program
PROGRAM & PROJECT MANAGEMENT
35
Enterprise Governance
“____ includes the formal measurement of processes and controls so that management understands and can measure them”
This is the defnition of what artifact or action that forms part of a healthy security governance program
METRICS/REPORTING
35
Enterprise Governance
Security governance should be practiced in a business in the same way it performs governance in what 2 other areas
- IT GOVERNANCE
- CORPORATE GOVERNANCE
35
Enterprise Governance
“Management will ensure that risk assessments are performed to identify risks in information systems and supported processes. Follow up actions will bec arried out to reduce the risk of system failure and compromise”
This is a definition of which activity required to protect the organisation
RISK MANAGEMENT
36