5.1 Security Procedures Flashcards

(24 cards)

1
Q

What is change management?

A

A set of processes and procedures for managing changes to systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does change management help prevent?

A

Downtime, confusion, and mistakes during changes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the first step in the change management process?

A

Determining the scope of the change.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What factors should be considered when assessing the risk of a change?

A

Whether the change affects an entire operating system or a specific application.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a change control board?

A

A group responsible for analyzing, approving, and scheduling proposed changes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the purpose of a backup plan in change management?

A

To restore systems to their previous state if a change fails.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is onboarding?

A

The process of integrating a new hire into the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What documents are typically provided during onboarding?

A

Employee handbook and acceptable use policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What needs to be created for a new user during onboarding?

A

New accounts with the correct rights and permissions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is offboarding?

A

The process of managing a user’s exit from the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What should be considered during offboarding regarding user assets?

A

What happens to assigned hardware and stored data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a playbook in a security context?

A

A defined set of steps to follow during a specific event.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is an example of an event that might require a playbook?

A

Investigating a data breach.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does SOAR stand for?

A

Security, Orchestration, Automation, and Response.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the benefit of using a SOAR platform?

A

To integrate diverse systems and automate mundane tasks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What should organizations do to maintain security?

A

Continuously monitor and revise processes and procedures.

17
Q

What is one way to strengthen a security posture?

A

Tightening the change control process.

18
Q

What should be done if new technologies are integrated?

A

Create new playbooks or update existing ones.

19
Q

What is the governance structure typically initiated by?

A

A board, such as a board of directors.

20
Q

What is the role of committees in governance?

A

To implement broad objectives set by the board.

21
Q

How do public sector governance policies differ from private sector?

A

They often involve legal, administrative, and political issues.

22
Q

What are the two forms of governance?

A

Centralized and decentralized.

23
Q

In centralized governance, who makes the decisions?

A

One group for the entire organization.

24
Q

In decentralized governance, who typically makes decisions?

A

Individuals performing specific jobs.