Week 6 Flashcards

(19 cards)

1
Q

What are the main areas in a security team?

A

Security Operations, Strategy & Policies, Risk Management, Assurance & Testing, Comms & Training, Projects, Physical Security & Business Continuity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does Security Operations involve?

A

Monitoring, SOC, Incident Response, Threat Intelligence, Pen Testing, Network Security, Identity & Access Management, Recovery.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the role of Strategy & Policies?

A

Create security strategy, write policies, assess current capabilities, and fix security gaps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does Risk Management include?

A

Risk visuals, meetings, impact assessments, legal reviews, accepting risks, and managing GRC tools.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Assurance & Controls Testing?

A

Test controls, plan assurance, work with auditors, handle third-party assessments, support certification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does Communication & Training cover?

A

User training, phishing tests, awareness campaigns, training plans, stakeholder materials.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are key tasks in Security Projects?

A

Budgeting, planning delivery, securing resources, managing change and stakeholders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does Physical Security & Business Continuity include?

A

Site access, insider threats, crisis planning, executive protection, high-risk travel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does a CISO do?

A

Leads security, makes key decisions, manages security messages, and works with senior leaders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Who might a CISO report to?

A

CIO, CTO, Head of Operations, Corporate Security, Audit, Risk Controller, or CEO.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What framework is used for cyber security best practices?

A

NIST Cybersecurity Framework.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are common real-world challenges in cyber security?

A

Complexity, competing priorities, and limited capacity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What makes a system complex?

A

Many parts (dimensions) and high interdependence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are top risks in a company merger?

A

Mismatched systems, data issues, compliance, supply chain risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Who should be in a merger security taskforce?

A

IT, Security, Legal, HR, Compliance, and Business Reps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What affects security over time in a business?

A

Evolving threats, business changes, and need for fast adaptation.

17
Q

What are examples of competing priorities?

A

Business speed vs. security needs, user convenience vs. protection.

18
Q

What limits security capacity?

A

Budget, skills shortage, low attention, and resistance to change.

19
Q

What traits help build a career in security?

A

Be practical, curious, and centred.