L9 - Security policies and Management Flashcards

1
Q

What is social engineering?

A

It’s the study of a target in order to get close enough to it, so that the attacker may either directly get access to the targets system or indirectly by leaving for example a rubber ducky.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are IT security management concepts?

A
  • Information security governance
  • Information security management
  • IT Security Operations.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is information security governance?

A

It provides a strategic directions, ensures objectives are achieved, manages risks appropriately, use of organisational resources responsibly and monitors the success of failure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What information security governance is effecive and not?

A

It’s when all of IT security management is actively working to achieve IT security governance. Ineffective when not.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are some security policys?

A

An organizational security policy may include any of these:
* Acceptable use policy
* Risk management policy
* Vulnerability management policy
* Data protection policy
* Access control policy
* Business continuity policy
* Personnel security policy
* Physical security policy
* Secure application development policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the prinicipal problems associated with employee behaviour?

A
  • Errors and omissions
  • Fraud
  • Actions by disgruntled employees
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is awareness?

A

Seeks to inform and focus on an employees attention on security issues within their organisation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do you address awareness?

A
  • Make employees aware of their responsibilities
  • Make employees understand the importance for the well-being of the company.
  • Promote enthusiasm and management buy-in.
  • Tailor the program to the needs of the organisation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is ISO?

A

It’s a general code of practice standars for organisations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How does ISO 27002 work?

A

It provides a checklist of general security controls to be considered implemented/used by organisations. It contains 14 categories, each of these categories contains a set of security controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Name a few categories in ISO 27002

A
  • Introduction
  • Scope
  • Information security policies
  • Human resources security
  • Access control
  • Operations security
  • Compliance
  • etc.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is ISO 27001?

A

It specifies specific requirements for establishing, implementing and continually improving a securit management system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the difference between ISO 27002 and 27001

A
  • 27002: defines the security goals and controls.
  • 27001: defines how to manage the implementation of security controls.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly