Week 6 Flashcards
(19 cards)
What are the main areas in a security team?
Security Operations, Strategy & Policies, Risk Management, Assurance & Testing, Comms & Training, Projects, Physical Security & Business Continuity.
What does Security Operations involve?
Monitoring, SOC, Incident Response, Threat Intelligence, Pen Testing, Network Security, Identity & Access Management, Recovery.
What is the role of Strategy & Policies?
Create security strategy, write policies, assess current capabilities, and fix security gaps.
What does Risk Management include?
Risk visuals, meetings, impact assessments, legal reviews, accepting risks, and managing GRC tools.
What is Assurance & Controls Testing?
Test controls, plan assurance, work with auditors, handle third-party assessments, support certification.
What does Communication & Training cover?
User training, phishing tests, awareness campaigns, training plans, stakeholder materials.
What are key tasks in Security Projects?
Budgeting, planning delivery, securing resources, managing change and stakeholders.
What does Physical Security & Business Continuity include?
Site access, insider threats, crisis planning, executive protection, high-risk travel.
What does a CISO do?
Leads security, makes key decisions, manages security messages, and works with senior leaders.
Who might a CISO report to?
CIO, CTO, Head of Operations, Corporate Security, Audit, Risk Controller, or CEO.
What framework is used for cyber security best practices?
NIST Cybersecurity Framework.
What are common real-world challenges in cyber security?
Complexity, competing priorities, and limited capacity.
What makes a system complex?
Many parts (dimensions) and high interdependence.
What are top risks in a company merger?
Mismatched systems, data issues, compliance, supply chain risks.
Who should be in a merger security taskforce?
IT, Security, Legal, HR, Compliance, and Business Reps.
What affects security over time in a business?
Evolving threats, business changes, and need for fast adaptation.
What are examples of competing priorities?
Business speed vs. security needs, user convenience vs. protection.
What limits security capacity?
Budget, skills shortage, low attention, and resistance to change.
What traits help build a career in security?
Be practical, curious, and centred.