GCGA Ch. 11 Security Governance (ST) Flashcards

(11 cards)

1
Q

Security governance

A

the set of responsibilities and processes established by an organization’s top-level management to direct, evaluate, and control the organization’s security efforts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Boards (company)

A

often consist of executives and high-ranking individuals within the organization who make critical decisions about security policy and strategy. Committees are usually specialized groups focusing on specific aspects of security, such as risk management or compliance. Government entities might have a role if the organization operates in a heavily regulated industry or if it deals with sensitive data like protected health information or national security matters.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Centralized vs decentralized governance structures

A

centralized governance structures concentrate decision-making authority at the top of the organization. Decentralized structures allow different parts of the organization to make their own security decisions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Setting up/managing security governance

A

In setting up and managing security governance, organizations need to take into account a range of external considerations. These may include regulatory requirements, legal obligations, industry standards, and the security environment at local, regional, national, and global levels.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Written security policies

A

administrative controls that identify an overall security plan for an organization and reduce overall risk. Procedures identify security controls used to enforce security policies. Common security policies include acceptable use policies (AUP), information security policies, business continuity and disaster recovery policies, incident response policies, software development lifecycle (SDLC) policies, and change management policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Security standards

A

outline technical and business requirements for security. Common security standards include password standards, access control standards, physical security standards, and encryption standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Security procedures

A

provide very specific step-by-step instructions for carrying out security-related tasks. Security guidelines offer advice on achieving security objectives. Common security procedures include change management procedures and employee onboarding/offboarding procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Security guidelines

A

optional advice, while compliance with policies, procedures, and standards is mandatory. Data owners have primary responsibility for a specific type of data within the organization. The data owner is typically a senior executive responsible for the area with oversight of the data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Data owners

A

typically have senior-level positions and can’t do the day-to-day work of data governance. For this reason, they typically delegate authority to data stewards on their teams who are responsible for carrying out the intent of the data owner’s requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Data custodian

A

responsible for routine daily tasks such as backing up data, storage of the data, and implementation of business rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Data controller

A

the organization that is responsible for a dataset. A data processor handles information on behalf of a data controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly