Module 4

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/27

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:32 AM on 9/23/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

28 Terms

1
New cards

Policy

Your rules and requirements for operations, and your contingency plans

2
New cards

Standards

The particulars of the systems, including specific security technologies and methods for protecting information

3
New cards

Guidelines

Written recommendations and best practices

4
New cards

Procedures

They detail how to implement the security policy, standards, and guidelines

5
New cards

Policies

must both protect and support an organization

You can’t write if you don’t understand your organization does

6
New cards

Management Support

What level?

What do they really care about?

Do they care about security?

Identify The Senior Management Champion for Information Assurance

7
New cards

Risk

is the likelihood of a given threat source exercising a particular potential vulnerability and the resulting impact of that adverse event on the organization.

8
New cards

Risk Management

The technique whereby an organization identifies, analyzes, controls, and monitors risks to its assets or objectives

A formal process, taking into account threats to your organization’s situation and lets you tailor your security program to its needs.

Someone must be designated to be in charge of risk management

9
New cards

–Uncertain outcome

–Possibility of loss

Key elements of risk

10
New cards

Public

Sensitive

Private

Confidential

Corporate Classification Levels

11
New cards

Public

information explicitly approved for release to the public

12
New cards

Sensitive

unauthorized disclosure is against the policy, but won’t impact the company

13
New cards

Private

intended for use within the company, could impact the company

14
New cards

Confidential

unauthorized disclosure could seriously and adversely impact the company

15
New cards

Privacy

Business Sensitive

Legal

What Do You Have To Protect?

16
New cards

Specific Competitors

General Public

Insiders (Need to know)

Who Are You Protecting It From?

17
New cards

Backups

How often do you backup?

How many hours of work can you afford to lose? For each group of data you have?

How long does it take to recover?

Backup Security?

18
New cards

Anti-Virus/Anti-Spyware Software

How will you update workstations?

Do you trust your users to keep the software/signature files updated?

How are you going to handle teleworkers (including travelers)?

How about mobile devices?

19
New cards

Firewall

Is there a Firewall? If not, who made that decision, and what was the justification?

If you use them, have a policy (What is allowed, everything else is forbidden)

Consider Host Firewalls if you use windows, especially for mobile workers/travelers

20
New cards

Passwords

How many User IDs and Passwords can you remember?

Let's write them down in a little book you always carry!

Physical device

21
New cards

Warning Banner


So users/employees know they are subject to be monitored

Why Monitor?

–Bandwidth

–Embarrassment

–Secrets

22
New cards

Continuity Of Operations Plan (COOP)

Backup – Frequency

What to do in case of an incident (natural or manmade)

Any Alternate Site’s security should be the same as a normal computer center

23
New cards

E-Mail

Usage policies, monitoring

OOPs – Procedures

Use of Messages Policy

24
New cards

Web

–Are there separate public and private sites and servers?

–Warning Banner, Consent to Monitor

–Public release of information policies

–Usage policies for surfing

–Monitoring

25
New cards

Web Application Security

SSL only protects data during transmission

Protect your information and data (in or connected to your web application)

Setting up a web application is an invitation to someone to try and get your information and data

Web application security should depend on a positive security model that allows input that is expected and is within expected boun

26
New cards

Security Awareness Training

Initial Security Training

Annual Security Refresher Training

27
New cards

–Social engineering

–Passwords

–Insider threats

–Ethical computing (Performing inappropriate computer tasks and accessing inappropriate sites)

To be most effective, a security-awareness program should address the following risk areas:

28
New cards

Turn off unneeded services in boxes attached to the Internet.

Never use a Web server for anything else.

Regularly apply security patches to critical machines.

Block all executable attachments at the gateway.

Use screen saver lockouts.

Five Easy Security Fixes