1/25
These flashcards cover key concepts in information security governance, including definitions, roles, policies, compliance, and frameworks.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
Information Security Governance
The system by which an organization directs and controls information security to support business objectives.
Primary Goal of Security Governance
Align security with business goals and ensure risk is managed at the enterprise level.
Responsibility for Information Security Governance
Senior management and the board of directors.
Role of Security Manager in Governance
Implement and manage the security program to support business strategy.
Difference between Governance and Management
Governance involves direction, oversight, and strategy; Management involves execution, implementation, and operations.
Risk Appetite
The amount of risk the organization is willing to accept.
Policy
High-level management statement of intent and direction.
Standard
Mandatory rules that support policies.
Procedure
Step-by-step instructions on how to perform tasks.
Guideline
Recommended practices; optional and flexible.
Board's Role in Security
Provide oversight, approve strategy, set risk appetite.
Senior Management's Role
Allocate resources, support the program, enforce policies.
Information Security Manager's Role
Implement and operate the security program.
Due Care
Acting responsibly to protect assets.
Due Diligence
Ongoing monitoring to ensure controls remain effective.
COBIT
IT governance and management framework.
ISO 27001
International standard for establishing and maintaining an ISMS (Information Security Management System).
ISMS
A structured approach to managing information security risks.
Primary Driver of the Security Program
Business objectives.
Most Important Factor in Security Initiatives
Business impact.
Risk Tolerance
Acceptable deviation from risk appetite.
Purpose of a Steering Committee
Provide oversight, resolve conflicts, ensure alignment with business.
Purpose of Metrics in Governance
Measure program effectiveness and support decision-making.
Purpose of a Charter
Define authority, scope, and responsibilities of the security function.
Purpose of Compliance Requirements
Ensure the organization meets legal, regulatory, and contractual obligations.
Responsibility for Ensuring Compliance
Senior management (security manager supports).