Week 2 Flashcards

(11 cards)

1
Q

What is required for effective security in an organization?

A

Active engagement of executive management to assess emerging threats and provide strong cyber security leadership

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Corporate governance?

A

A set of policies and internal controls by organizations are directed and managed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Security governance?

A

How a company controls its approach to security through procedures, strategies, and programs to manage risk and meet security goals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does information security governance relate to overall governance?

A

It is a subset of the organizations overall governance program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does Information Security Governance provide?

A
  • strategic direction
  • ensures that objectives and achieved
  • manages risks appropriately
  • uses organizational resources responsibly,
  • monitors the success or failure of the enterprise security program
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the benefits of Information Security Governance?

A
  • Increase in share value with good governance
  • Makes operations predictable and reduces uncertainty
  • Protect from legal or civil liabilities
  • Optimizes use of limited security resources
  • Ensures policies are effective and followed
  • Supports strong risk management and fast incident responses
  • Helps makes reliable decisions (not based on faulty information)
  • Keeps people accountable for securing information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what are the outcomes of effective information security (IS) governance?

A
  1. Strategic alignment - with businesses goals
  2. Risk management - Reduce IS risk to acceptable levels
  3. Value Delivery - Get most business benefit from IS investments
  4. Performance Measurement - monitoring on IS to sure that objectives are achieved
  5. Resource Management - Use IS knowledge and tools efficiently
  6. Integration - Ensures all security processes operates as intended from end to end
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why were frameworks developed?

A

To support the rapid effective deployment of security governance infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what does government framework provide in information security? (definition)(must know)

A
  • The basis for the developing a cost-effective information security program that supports the organization’s goals

and

  • an acceptable level of predictability in operations by limiting the impacts of adverse events.

overall: Ensures information assets are protected at a level matching their value and associated risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What will a governance framework generally consist of?

A
  • security strategy linked with business objective
  • security policies that addresses, control and regulate each aspect of strategy
  • Standards for each policy to ensure that procedures comply with policy
  • Effective security organizational structure with sufficient authority and adequate resources
  • Metrics and monitoring to ensure rules are followed, spot problems, and guide better decisions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly