Documentation and Proceses Flashcards

(40 cards)

1
Q

What is IT Governance?

A

Used to provide a comprehensive security management framework for the organization

IT Governance is implemented using policies, standards, baselines, guidelines, and procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does a policy define?

A

Defines the role of security inside of an organization and establishes the desired state for that security program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the levels of security policies?

A
  • Organizational
  • System-specific
  • Issue-specific
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the purpose of an organizational security policy?

A

Provide framework to meet the business goals and define the roles, responsibilities, and terms associated with it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does a system-specific policy address?

A

Address the security of a specific technology, application, network, or computer system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the function of a standard in an organization?

A

Implements a policy in an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a guideline?

A

Recommended action that allows for exceptions and allowances in unique situations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a physical network diagram used for?

A

Used to show the physical arrangement of network components, including cabling and hardware layout.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does a logical network diagram illustrate?

A

Illustrates data flow and device communication, including subnets, network objects, routing protocols, and domains.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the purpose of a site survey report?

A

Conducted for wireless network assessments to show access point locations and signal strength.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a wired site survey typically part of?

A

Preparation for a major upgrade or installation, checking power, space, and cooling for new equipment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is included in an audit and assessment report?

A
  • Executive summary
  • Scope and objectives
  • Assumptions and limitations
  • Methods and tools
  • Environment and system diagram
  • Security requirements
  • Findings and recommendations
  • Audit results
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a baseline configuration?

A

Most stable versions of device configurations documented and changeable only through change control procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is asset management?

A

A systematic approach to the governance and realization of value of things over their entire life cycle.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the types of assets?

A
  • Tangible Assets
  • Intangible Assets
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are key processes in asset management?

A
  • Developing
  • Operating
  • Maintaining
  • Upgrading
  • Disposing of assets
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is asset inventory?

A

Maintain a complete list of all assets in the organization using a database system.

18
Q

What is the purpose of asset identification?

A

Each asset should have a unique asset tag and ID for tracking purposes.

19
Q

What is the procurement lifecycle?

A

Birth to death of an asset, including change management procedures for proper procurement and deployment.

20
Q

What is the purpose of warranty and licensing in asset management?

A

Keep track of asset warranties and support contracts and ensure software licensing compliance for all devices.

21
Q

What is IP Address Management (IPAM)?

A

A methodology and suite of tools used to plan, track, and manage the IP address space inside a network infrastructure.

22
Q

What are the benefits of automated IPAM?

A
  • Detects and resolves IP conflicts
  • Integrates with DHCP and DNS servers
  • Supports horizontal cloud scaling
23
Q

What is the strategic importance of IPAM?

A

Involves a strategic shift in managing network infrastructure to enhance efficiency, security, and resilience.

24
Q

What are the three main types of agreements in network management?

A
  • Non-Disclosure Agreements (NDAs)
  • Memorandum of Understanding (MOU)
  • Service Level Agreement (SLA)
25
What does a Non-Disclosure Agreement (NDA) do?
Defines confidential data between two parties to protect intellectual property.
26
What is a Memorandum of Understanding (MOU)?
A non-binding agreement detailing common actions and responsibilities between two or more organizations.
27
What is a Service Level Agreement (SLA)?
Documented commitment between a service provider and a client defining quality, availability, and responsibilities.
28
What is the product lifecycle?
Every product follows a product life cycle, specified by manufacturers regarding support levels.
29
What are the two types of support in Microsoft's Lifecycle Policy?
* Mainstream Support * Extended Support
30
What happens when an operating system reaches end of life?
It is no longer supported by mainstream or extended support.
31
What is change management?
Orchestrated strategy to transition from an existing state to a more desirable future state.
32
What is the purpose of the change approval process?
Changes must be approved and assessed for their value and potential impacts.
33
What is the role of the Change Advisory Board (CAB)?
Responsible for evaluating any proposed changes.
34
What is impact analysis?
Conducted before implementing any proposed change to understand potential fallout and immediate effects.
35
What is configuration management?
Focuses on maintaining up-to-date documentation of network configuration.
36
What is the purpose of patch management?
Planning, testing, implementing, and auditing of software patches.
37
What are the four critical steps in patch management?
* Planning * Testing * Implementation * Auditing
38
What is a testing strategy for patches?
Use patch rings to deploy patches in stages, starting with a small group of machines.
39
What is firmware management?
Applies to routers, switches, firewalls, and other network devices to update firmware.
40
What are considerations for effective patch management?
* Ensure patches are compatible with systems * Test patches before deployment * Use automated tools for large networks * Conduct auditing to verify patch installation