ITEP 413 Chapter 1 - Information Systems Security Policy Management

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/18

flashcard set

Earn XP

Description and Tags

Practice flashcards in Question and Answer format covering Information Systems Security, Information Assurance, IT Governance, Security Policies, and Policy Management Life Cycles.

Last updated 9:26 AM on 9/26/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

19 Terms

1
New cards

What is Information Systems Security?

Information Systems Security is the protection of information systems and their resources from unauthorized access, use, modification, disclosure, disruption, or destruction.

2
New cards

What resources does Information Systems Security protect beyond computers?

It protects information and data, hardware, software, networks, users, and processes.

3
New cards

What are the five steps of the Information Systems Security Management Life Cycle?

  1. Align, Plan, and Organize; 2. Build, Acquire, and Implement; 3. Deliver, Service, and Support; 4. Monitor, Evaluate, and Assess; 5. Improve.
4
New cards

What does ISO/IEC 38500 provide for organizations?

ISO/IEC 38500 provides principles and guidance for the governance of IT within organizations.

5
New cards

What is Information Assurance (IA)?

Information Assurance (IA) is concerned with protecting and ensuring the reliability, availability, integrity, confidentiality, authenticity, and accountability of information and information systems.

6
New cards

How is Confidentiality defined in Information Assurance?

Confidentiality ensures that information is available only to authorized individuals or systems.

7
New cards

How is Integrity defined in Information Assurance?

Integrity ensures that information remains accurate, complete, and protected from unauthorized modification.

8
New cards

How is Availability defined in Information Assurance?

Availability ensures that authorized users can access information and systems when needed.

9
New cards

How is Authentication defined in Information Assurance?

Authentication confirms the identity of a user, device, or system.

10
New cards

How is Nonrepudiation defined in Information Assurance?

Nonrepudiation provides evidence that a particular person or entity performed an action or transaction and cannot reasonably deny having done so.

11
New cards

What is Governance in an organizational context?

Governance refers to how an organization is directed, controlled, and guided in making decisions about its resources, processes, and overall operations.

12
New cards

What are the five key elements of governance?

Decision-making structure, Accountability, Policies and rules, Risk management, and Compliance monitoring.

13
New cards

What is an Information Systems Security Policy?

A security policy is a formal set of rules and guidelines that tells people how information and information systems should be protected and used.

14
New cards

How do Policy, Standard, and Procedure differ?

Policy states WHAT the organization requires; Standard provides a SPECIFIC REQUIREMENT; Procedure explains HOW to perform a task.

15
New cards

What are the seven steps involved in creating security policies?

  1. Identify the Need; 2. Identify the Assets; 3. Identify Threats and Vulnerabilities; 4. Assess the Risk; 5. Create the Policy; 6. Implement the Policy; 7. Monitor and Review.
16
New cards

Where do Information Systems Security Policies fit within an organization's structural flow?

Organizational Goals -> Governance -> Risk Management -> Security Policies -> Standards and Procedures -> Security Controls -> Monitoring and Improvement.

17
New cards

What is Business Process Reengineering (BPR)?

Business Process Reengineering (BPR) involves examining and redesigning existing organizational processes to achieve significant improvements in performance, efficiency, quality, or service.

18
New cards

What sequence represents the continuous improvement cycle for information security?

Plan -> Implement -> Monitor -> Evaluate -> Improve.

19
New cards

How can organizations gain acceptance for security policies?

  1. Explain the Reason; 2. Involve Stakeholders; 3. Provide Training; 4. Make Policies Practical; 5. Communicate Clearly; 6. Monitor and Improve.