Security Management Flashcards
(18 cards)
What does CIRT stand for and what is its primary responsibility?
Cyber Incident Response Team – responsible for responding to security breaches, viruses, and other cybersecurity incidents.
What does SOC stand for and what is its primary responsibility?
Security Operations Center – responsible for continuously monitoring and analyzing an organization’s security posture.
What is Security Awareness in an organization?
A formal process for training and educating employees about IT protection, ensuring they understand and follow security policies.
Name three key components of a Security Awareness program.
Programs to educate employees
Emphasizing individual responsibility for company security policies
Measures to audit and assess awareness efforts
What is A.5 Information security policies?
Controls on how the policies are written and reviewed
What is A.6 Organization of information security?
Controls how responsibilities are assigned; includes mobile & teleworking
What is A.7 Human resources security
Controls prior to employment, during employment, and after employment
What is A.8 Asset management
Controls related to inventory of assets and acceptable use
What is A.9 Access control ?
Controls for Access control policy, user access management, system and application
What is A.10 Cryptography?
Controls related to encryption and key management
What is A.11 Physical and environmental security?
Controls defining secure areas, entry controls, protection against threats,..
What is A.12 Operational security?
Controls related to management of IT production
What is A.13 Communication security?
Controls related to network security, segregation, network services
What is A.14 System acquisition, development and maintenance?
Controls defining security requirements and security development/support process
What is A.15 Supplier relationships?
Controls on what to include in agreements, and how to monitor the suppliers
What is A.16 Information security incident management?
Controls for reporting events and weaknesses, defining responsibilities,…
What is A.17 Information security aspects of business continuity management?
Controls requiring the planning of business continuity, procedures, verification and reviewing
What is A.18 Compliance?
Controls requiring identification of applicable laws and regulations