16.2: Personnel Policies

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/26

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:50 PM on 9/15/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

27 Terms

1
New cards

What is separation of duties?

Splitting a critical process so no single person can complete it alone. Prevents one individual from committing and concealing fraud.

2
New cards

What is job rotation?

Periodically moving staff between roles. Exposes irregularities that a permanent occupant could hide and cross-trains the team.

3
New cards

What is mandatory vacation?

Requiring employees in sensitive roles to take consecutive time off, so schemes requiring ongoing concealment surface while they're away.

4
New cards

What is least privilege as a personnel policy?

Granting each employee only the access their role requires, reviewed when they change roles so rights don't accumulate.

5
New cards

What is a clean desk policy?

Requiring sensitive materials be secured when unattended, preventing casual observation, theft, or photography of documents and credentials.

6
New cards

What is a background check?

Pre-employment verification of identity, employment history, credentials, and criminal record, scaled to the sensitivity of the role.

7
New cards

What are onboarding security responsibilities?

Signing the AUP and NDA, provisioning least-privilege access, issuing equipment, and completing initial security awareness training.

8
New cards

What are offboarding security responsibilities?

Immediately disabling accounts and revoking access, recovering assets and credentials, conducting an exit interview, and confirming NDA obligations continue.

9
New cards

What is an acceptable use policy (AUP)?

Defines permitted and prohibited use of company systems, networks, and data. Signed by employees, and the basis for enforcement action.

10
New cards

What is a social media policy?

Governs what employees may disclose publicly about the organization, limiting information useful for social engineering and reconnaissance.

11
New cards

What is a remote and hybrid work policy?

Sets security requirements for working outside the office — approved devices, VPN use, home network standards, and physical privacy expectations.

12
New cards

What is security awareness training?

Ongoing education teaching employees to recognize and respond to threats, turning the workforce from the weakest link into a detection layer.

13
New cards

What is role-based security training?

Tailoring training content to job function — developers get secure coding, finance gets BEC and wire fraud, executives get whaling awareness.

14
New cards

What is phishing?

A social engineering attack using fraudulent messages to trick recipients into revealing credentials, sending money, or executing malware.

15
New cards

What is spear phishing?

Phishing targeted at a specific individual or group using researched personal details, making it far more convincing than bulk phishing.

16
New cards

What is whaling?

Spear phishing aimed at executives and other high-value targets who hold broad authority and access.

17
New cards

What are vishing, smishing, and pharming?

Vishing uses voice calls. Smishing uses SMS. Pharming redirects users to a fraudulent site through DNS manipulation rather than a lure.

18
New cards

What is business email compromise (BEC)?

An attacker impersonates or compromises an executive or vendor account to authorize fraudulent payments or data transfers. Often uses no malware at all.

19
New cards

What are common indicators of a phishing message?

Urgency and pressure, unexpected requests, mismatched sender and reply-to addresses, hovering links that don't match their text, unexpected attachments, and requests to bypass normal process.

20
New cards

What is a phishing simulation campaign?

Sending controlled fake phishing emails to employees to measure click rates and reporting rates, identifying who needs additional training.

21
New cards

What is anomalous behavior recognition training?

Teaching users to notice risky, unexpected, or unintentional behavior — their own and others' — such as unusual requests, tailgating, or a coworker's account acting oddly.

22
New cards

Why is user reporting critical to security awareness?

Users often detect attacks before tools do. An easy, blame-free reporting path converts individual detections into organization-wide defense.

23
New cards

Why should reporting be non-punitive?

If users fear blame, they hide mistakes, which delays response. Rewarding reports — including of one's own errors — surfaces incidents faster.

24
New cards

What metrics are used to monitor security awareness effectiveness?

Phishing simulation click and report rates, training completion rates, time to report, and incident volume traced to user behavior.

25
New cards

What is the development phase of a security awareness program?

Building the program: assessing risks and gaps, defining objectives and audiences, and creating role-appropriate content and delivery methods.

26
New cards

What is the execution phase of a security awareness program?

Delivering the training, running simulations and campaigns, measuring results, reporting to stakeholders, and revising content based on what the metrics show.

27
New cards

Under the General Data Protection Regulation (GDPR), how soon must an organization report a breach of personal data?

72 hours