5.1a security policies ·

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/13

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:57 PM on 8/15/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

14 Terms

1
New cards

Security policy (general)

Documented rules covering both broad goals and detailed procedures, existing to support CIA (Confidentiality, Integrity, Availability).

2
New cards

Information security policy

The master document or list of all policies an organization must follow to maintain security and availability.

3
New cards

AUP (Acceptable Use Policy)

Defines what employees are and aren't allowed to do with company-provided technology; also serves as legal protection/documentation if someone is disciplined or terminated for violations.

4
New cards

Business continuity policy

Plan for continuing operations when normal technology or processes are unavailable, e.g. manual credit card processing when the network is down.

5
New cards

Disaster recovery plan

A broader, organization-wide version of business continuity, covering larger-scale disasters: natural, technological, or human-caused.

6
New cards

Business continuity vs disaster recovery

BCP keeps critical business functions operating during disruption (business-focused). DRP specifically restores IT systems and infrastructure after a disaster (technical-focused), often a subset of the overall BCP.

7
New cards

Disaster recovery components

Alternate recovery location, data recovery method, application restoration, staff availability at the recovery site.

8
New cards

Security incident policies

Documented procedures for handling specific incident types: malware infections, DDoS/botnet attacks, data exfiltration.

9
New cards

Incident response roles

Incident response team, IT security management, compliance officers, technical staff, and the general user community all play distinct roles in handling incidents.

10
New cards

SDLC (Software Development Lifecycle)

The structured process of moving from an idea to a deployed application: requirements, development, testing, deployment.

11
New cards

Waterfall (SDLC model)

Linear, sequential lifecycle: requirements, development, testing, deployment, maintenance, each phase completed before the next begins.

12
New cards

Agile (SDLC model)

Faster, iterative lifecycle: design, develop, test, deploy, and review repeatedly in cycles rather than a single linear pass.

13
New cards

Change management

Formal process for making any modification, with documentation of frequency, duration, install process, and a fallback/rollback plan.

14
New cards

Change management neglect risk

Skipping formal change management is common and can have serious negative organizational impact.