Information Secirity Governance Flashcards

1
Q

Values

A

Ethics: What we believe in
Principles: what we adhere to
Beliefs: what we stand for

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Vision

A

What we aspire to be
Hope and ambition
Should be clearly defined for entire org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Mission

A

What the purpose of the org
Who do we do it for
Motivation and Purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Strategic Objectives

A

Plans, goals and sequencing
Where we make the plans, goals, order all activities that we have that can help us fulfill our mission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Strategic Plan

A

Long term plan made by senior leadership
Example: insource IT and build a best in class IT org with procedures and policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Tactical

A

Usually completed by management.1 year project, acquisition, hiring, budgets. Example: 1st year we need to do this figure out budget for each year, how many people to hire

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Operational

A

Usually completed by the staff. Highly detailed and updated frequently. Examples: how do hire a server team, networking team, streamline workstation servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Policies

A

Are mandatory; don’t change that much; high level non specific.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Types of policies

A

Regulatory- have to follow based on industry
Advisory- outlines behaviors and activities that are acceptable or not acceptable in our organization
Informational- there to inform people

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Standards

A

Mandatory; more detailed than policies; describes a specific use of technology ( all laptops are W10, 64bit, 8gig memory)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Guidelines

A

Non mandatory; recommendations, discretionary; suggestions on how you would to it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Procedures

A

Mandatory; low level step by step guides, very specific; can contain the OS, encryption type, vendor technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Baseline(Benchmarks)

A

Mandatory; benchmarks for server hardening, apps, network. Minimum requirements, we can implement stronger if needed. Need to implement the same security posture across the organization meaning servers in the same protection profile having the same baselines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly