ch 5

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/27

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

28 Terms

1
New cards

InfoSec Program

Structure managing risks to information assets.

2
New cards

Essential Functions

Basic InfoSec functions performed organization-wide.

3
New cards

Policy

Includes program, issue-specific, and system-specific policies.

4
New cards

Program Management

Central and system-level security program oversight.

5
New cards

Risk Management

Involves assessment, mitigation, and uncertainty analysis.

6
New cards

Life-cycle Planning

Security plan phases: initiation to maintenance.

7
New cards

Personnel/User Issues

Staffing and user administration responsibilities.

8
New cards

Contingency Planning

Business plan and resource identification strategies.

9
New cards

Incident Handling

Includes detection, reaction, recovery, and follow-up.

10
New cards

Awareness and Training

SETA plans and policy/procedure training.

11
New cards

Physical Security

Involves guards, locks, and alarms.

12
New cards

Organizational Culture

Positive view enhances InfoSec program support.

13
New cards

Organizational Size

Large firms have dedicated InfoSec divisions.

14
New cards

Reporting Structure

InfoSec can report to various departments.

15
New cards

CIO vs CISO

CIO focuses on efficiency; CISO on security.

16
New cards

CISO

Oversees InfoSec program and strategic planning.

17
New cards

Security Managers

Responsible for daily operations and objectives.

18
New cards

Security Technicians

Configure systems and troubleshoot security issues.

19
New cards

SETA Purpose

Reduce breaches by promoting secure behavior.

20
New cards

SETA Elements

Education, training, and awareness for security.

21
New cards

Work Breakdown Structure

Breaks projects into manageable tasks.

22
New cards

Gantt Chart

Displays project activities and timelines visually.

23
New cards

Certifications

Professional credentials for InfoSec roles.

24
New cards

CISSP

Certification for security managers and CISOs.

25
New cards

CISM

For experienced InfoSec managers and consultants.

26
New cards

CISA

Certification for auditors and security professionals.

27
New cards

GIAC

Series of InfoSec certifications across domains.

28
New cards

Career Paths

Includes law enforcement, military, and IT.