1/9
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Security standard
Documented, specific requirement defining exactly how a security policy must be implemented; more concrete/technical than a broad policy statement.
Policy vs standard vs procedure
Policy is the broad statement of intent (why). Standard is the specific, measurable requirement (what). Procedure is the step-by-step instructions (how).
Password policy standards
Change frequency, secure storage method, approved password manager requirements, standardized across the organization.
Access provisioning standard
Formal process for granting access; may require management sign-off or completion of training before access is granted.
Access de-provisioning standard
Formal process for removing access, triggered by security issues, account expiration, employee departure, or contract expiration.
Physical security standard
Requirements for badge-based building access, electronic door locks, potentially biometric locks, monitoring, and motion detection.
Visitor/contractor differentiation
Physical security standards may differ by person type: employee vs contractor vs guest, e.g. escort requirements for visitors.
Encryption standard
Documented requirements for which algorithms to use and how encryption technologies must be implemented across the organization.
Password storage standard (reinforced)
Specifies exact requirements like salted hash storage and which hashing algorithm must be used.
State-specific encryption standards
Different encryption requirements may apply depending on whether data is at rest, in transit, or in use.