Security Govenance Flashcards
(10 cards)
1
Q
Policies
A
Describe an organizations security expectations
Mandatory Compliance
Highest level approval
2
Q
Standards
A
Describe specific security controls
Mandatory Compliance
IT level approval
3
Q
Guidelines
A
Describe best practice
Not Mandatory Compliance
4
Q
Procedures
A
Step by step instructions
Compliance depends on procedure
5
Q
Acceptance Use Policies (AUP)
A
Authorized uses of technology
6
Q
Data handling policies
A
How to protect sensitive data
7
Q
Password policies
A
Password security practices
8
Q
Bring your own device policies (BYOD)
A
Use of personal devices with company information
9
Q
Privacy policies
A
Use of personally identifiable information
10
Q
Change management policies
A
Documentation, approval and rollback of technology changes