1/36
Comprehensive vocabulary flashcards covering the CISM exam topics including information security governance, the SABSA model, GRC processes, and security strategy development.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Information security governance driver
Business strategy
Risk Analysis Driver
The Security Manager
Application Data Access Rights
Security administrators are responsible for enforcing these.
Notifications
The MOST important component of a privacy policy.
Information Security Governance (Definition)
A set of policies and procedures establishing a framework of security strategies and a practice area ensuring efficient utilization of information resources.
Main Purpose of Information Security Governance
To ensure the safety of information including its Confidentiality, Integrity, and Availability.
Six Basic Outcomes of Information Security Governance
Strategic alignment, value delivery, risk management, performance measurement, resource management, and integration.
Security Investment Goal
Optimized so that they support business objectives.
Primary Goals of Resource Management
Keeping a record of security practices, acquiring and making knowledge accessible, and building a security architecture for proper infrastructure resource use.
Corporate Governance
A set of procedures and duties performed by the board of directors and executive management to direct and control the organization.
Steering Committee
Consists of senior representatives of departments affected by security policies and aims to involve all stakeholders influenced by security aspects.
Board of Directors (Information Security Responsibility)
Responsible for identifying information assets that need protection and assigning appropriate priorities and protection levels.
CISO (Chief Information Security Officer)
Responsible for establishing reporting and communication channels to ensure effective information security governance.
GRC
Governance, Risk Management, Compliance.
Governance (GRC process)
The process senior management uses to direct and control an organization, developing methods to ensure employees adhere to policies and standards.
Risk Management (GRC process)
The process for mitigating risks, establishing risk tolerance, recognizing potential impacts, and deciding mitigation priorities based on business goals.
Compliance (GRC process)
The process of supervising controls and methods to ensure adherence to policies, standards, and procedures.
Systems Theory
A network of processes, people, technologies, relationships, events, reactions, and results interacting to achieve one common goal.
Information Security Business Model Elements
Organization design and strategy, people, process, and technology.
Governance Dynamic Interconnection
Links the organization and process elements; involves guiding and controlling an organization.
Culture Dynamic Interconnection
Links the organization and people elements; represents people's beliefs, opinions, and behaviors.
Enablement and Support Dynamic Interconnection
Links the technology and process elements; involves creating security policies, guidelines, and standards.
Emergence Dynamic Interconnection
Links people and process elements; indicates patterns that appear without evident reason and have results difficult to forecast.
Human Factors Dynamic Interconnection
Links the people and technology elements, indicating the relationship and gap between these elements.
Architecture Dynamic Interconnection
Links organization and technology elements; covers the policies, processes, people, and technology composing security practices.
SABSA
Sherwood Applied Business Security Architecture.
SABSA Layers
Business View, Architect's View, Designer's View, Builder's View, Tradesman's View, and Service Manager's View.
Business Case
Contains justifications for a security program, including cost, ROI, benefits, success factors, and Total Cost of Ownership (TCO).
COBIT 5
An information security governance model providing processes and best practices for the control and governance of information technology.
Security Baseline
The current state of security encompassing people, processes, and technologies used to measure progress toward the desired state.
Security Roadmap
A set of actions or steps executed to close the gaps between the current and desired states of security.
Policies
The foundation of a security strategy; high-level statements describing management's intent and expectations.
Procedures
Step-by-step instructions used to carry out a policy.
Standards
Written in conjunction with policies, providing specific configuration setups and protocols required (e.g., wireless protocols).
Guidelines
Suggestions and examples that clarify procedures; often used as a precursor for what may become a policy issue.
Risk Treatment Strategies
Risk mitigation, risk avoidance, risk transference, and risk acceptance.
Balanced Scorecard
An effective tool for evaluating the degree to which information security objectives are met and tracking the effectiveness of strategy execution.