Governance
Compliance
What are the aspects that make up a governance framework?
Governance Monitoring
Governance Revisions
Board of Directors
Committees
Government Entities
EXAMPLES: Federal Trade Commissions makes laws against unfair trade practices you must adhere to
Centralized Structures
DeCentralized Structures
Acceptable Use Policy (AUP)
EXAMPLE: Might prohibit users from visiting unwanted websites, or downloading files they shouldn’t
Information Security Policies
*** This covers a range of areas including Data Classification, Access Control, Encryption, and Physical Security
Business Continuity
Disaster Recovery
Incident Response
EXAMPLE: States the who/what/when/where of disaster actions
Change Management
Standards
Password Standards
*** Minimum length of characters, upper/lower case, numbers, and special characters
Access Control Standards
*** This includes…
Discretionary Access Control (DAC) - resource owner decides who gets access
Mandatory Access Control (MAC) - system enforces access based on security clearances and data classifications
Role-Based Access Control (RBAC) - access is tied to job functions/roles rather than individual users
Physical Security Standards
Encryption Standards
Procedures
EXAMPLE: Data back-up procedure, Emergency Evacuation Procedure
Onboarding/Off-boarding Procedures
Playbooks