1/19
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the difference between a policy, a standard, a procedure, and a guideline?
Policy — high-level statement of intent and requirement, mandatory. Standard — specific mandatory technical or operational requirement supporting the policy. Procedure — step-by-step instructions for carrying it out. Guideline — recommended best practice, not mandatory.
What is an acceptable use policy (AUP)?
Defines what employees may and may not do with company systems, networks, and data. Signed at onboarding, and it's what makes disciplinary action defensible.
What is an information security policy?
The organization's overarching statement of how information is protected — scope, objectives, responsibilities, and the authority behind the security program.
What is a business continuity policy?
Defines how the organization keeps critical operations running during a disruption, including acceptable downtime and continuity priorities.
What is a disaster recovery policy?
Defines how systems and data are restored after a major outage or disaster, including recovery objectives and responsibilities.
What is an incident response policy?
Establishes the authority, scope, roles, and escalation paths for handling security incidents. The IR plan and playbooks sit beneath it.
What is an SDLC policy?
Governs how software is developed and maintained securely, embedding security requirements, code review, and testing into each phase of the development lifecycle.
What is a change management policy?
Requires that all changes to systems be requested, assessed, approved, documented, and reversible — preventing unauthorized or untested changes.
What is a password standard?
Defines mandatory password requirements: minimum length, complexity, reuse limits, age, and lockout thresholds.
What is an access control standard?
Specifies how access is granted, reviewed, and revoked — the model used, approval requirements, least privilege, and recertification frequency.
What is a physical security standard?
Defines required physical controls for facilities and equipment — badge access, visitor handling, server room restrictions, surveillance.
What is an encryption standard?
Specifies approved algorithms, key lengths, and where encryption is required for data at rest and in transit. Prevents teams from choosing weak or obsolete crypto.
What are onboarding and offboarding procedures?
Onboarding provisions accounts and access, issues equipment, and delivers security training. Offboarding revokes access immediately, recovers assets, and disables accounts.
What is a playbook?
A detailed, scenario-specific procedure for responding to a particular event — ransomware, phishing, data breach — so response doesn't depend on improvisation.
What are the common governance structures?
Boards — set direction and hold ultimate accountability. Committees — focused groups advising on specific areas. Government entities — impose external regulatory requirements. Centralized vs. decentralized — whether decision authority sits in one group or is distributed.
What is the difference between centralized and decentralized governance?
Centralized puts decision-making in one authority — consistent and easier to audit, but slower and less responsive to local needs. Decentralized distributes it to business units — flexible and fast, but risks inconsistency and gaps.
What is a data owner?
A senior business role accountable for a data set — classifying it, defining who may access it, and approving access requests. Accountability doesn't transfer.
What is a data custodian or steward?
The technical role implementing the owner's decisions — applying access controls, backups, encryption, and retention. A steward focuses more on data quality and metadata.
What is the difference between a data controller and a data processor?
The controller determines why and how personal data is processed and bears legal responsibility. The processor handles the data on the controller's behalf and only per its instructions.
What is a data privacy officer (DPO)?
The role accountable for privacy compliance — overseeing how personal data is collected, used, and protected, and serving as contact for regulators. Required under GDPR for certain organizations.