01. Intro to Sec Governance Flashcards
(38 cards)
Intro to Sec Governance
What is GOVERNANCE
Senior management exrts strategic control over business functions through
1. policies
2. objectives
3. delegation of authority
4. monitoring
33
Intro to Sec Governance
How is governance usually established
Steering committees
33
Intro to Sec Governance
9 typical processes that information security GOVERNANCE focuses on
- Personnel Management
- Sourcing
- Risk Management
- Configuration Management
- Change Management
- Access Management
- Vulnerability Management
- Incident Management
- Business Continuity P.anning (BCP)
Intro to Sec Governance
Organisations not adequately protecting their information through an information security program have a ____ problem
Business Problem
34
Intro to Sec Governance
A lack of understanding and committment by these parties is typically the reason why business have a problem protecting their information
The most typical reason why a business will have a problem implementing or putting in place an information security program to protect their information
Board of directors and Senior Management
34
Intro to Sec Governance
When information security becomes a people issue and people from each level in the organisation understand the importance, the organisation will be in a position of what
Reduced Risk
34
Intro to Sec Governance
reduction in risk results in;
1. Fewer ____
2. When they do occur, have lower ____
3. This is felt on the organisations ____ and ____
- Incidents
- Impact
- Reputation and Operations
34
Intro to Sec Governance
Information Security Governance is a set of established activities that helps management understand the state of the organisations ____, its current ____, and its direct ____
- security program
- risks
- activities
34
Intro to Sec Governance
A goal of the ____ is to continue to contribute toward the fulfilment of the security strategy
Security Program
34
Intro to Sec Governance
The security strategy will continue to align with the ____
Business and Business Objectives
34
Intro to Sec Governance
What does GOVERNANCE begin with establishing, that is translated into actions, policies, processes, procedures, and other activities down through the levels of the organisation
Top-Level Strategic Objectives
34
Intro to Sec Governance
What other program must an organisation have in place in order for the information security governance to succeed
Effective IT Governance Program
34
Intro to Sec Governance
What is the purpose of security governance
Align SECURITY PROGRAM with the NEEDS OF THE BUSINESS
35
Intro to Sec Governance
A collection of top-down activities intended to control the security of the organisation from a strategic perspective
Information Security Governance
35
Intro to Sec Governance
Desired capabilities or end states are ideally expressed in achievable, measureable terms
Artifacts and actions that flow out of a healthy security governance program
Objectives
35
Intro to Sec Governance
A plance to achieve one or more objectives
Artifacts and actions that flow out of a healthy security governance program
Strategy
35
Intro to Sec Governance
At its minimum, this should directly reflect the mission, objectives, and goals of the overall organisation
Artifacts and actions that flow out of a healthy security governance program
Policy
35
Intro to Sec Governance
These should flow directly from the organisations mission, objectives and goals. Whatever is most important to the organisation should also be essential to information security
Artifacts and actions that flow out of a healthy security governance program
Priorities
35
Intro to Sec Governance
These help drive a consistent approach to solving business challenges. The choice of these should facilitate solutions that meet the organisations needs in a cost-effective and secure manner
Artifacts and actions that flow out of a healthy security governance program
Standards
35
Intro to Sec Governance
Formalised descriptions of repeated business activities inlcuding instructions to applicable personnel.
Artifacts and actions that flow out of a healthy security governance program
Processes
35
Intro to Sec Governance
Formal descriptions of critical activities to ensure desired outcomes
Artifacts and actions that flow out of a healthy security governance program
Controls
35
Intro to Sec Governance
These should be organised and performed in a consistent manner that reflects the business priorities and supports the business
Artifacts and actions that flow out of a healthy security governance program
Programs and project management
35
Intro to Sec Governance
Formal measurements of processes and controls so that management understands and can measure them
Artifacts and actions that flow out of a healthy security governance program
Metrics / Reporting
35
Intro to Sec Governance
What 2 things must the information security manager understand withn the business concerning confidentiality, integrity, and availability (CIA)
Appetite and priority
36