1/18
Practice flashcards in Question and Answer format covering Information Systems Security, Information Assurance, IT Governance, Security Policies, and Policy Management Life Cycles.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is Information Systems Security?
Information Systems Security is the protection of information systems and their resources from unauthorized access, use, modification, disclosure, disruption, or destruction.
What resources does Information Systems Security protect beyond computers?
It protects information and data, hardware, software, networks, users, and processes.
What are the five steps of the Information Systems Security Management Life Cycle?
What does ISO/IEC 38500 provide for organizations?
ISO/IEC 38500 provides principles and guidance for the governance of IT within organizations.
What is Information Assurance (IA)?
Information Assurance (IA) is concerned with protecting and ensuring the reliability, availability, integrity, confidentiality, authenticity, and accountability of information and information systems.
How is Confidentiality defined in Information Assurance?
Confidentiality ensures that information is available only to authorized individuals or systems.
How is Integrity defined in Information Assurance?
Integrity ensures that information remains accurate, complete, and protected from unauthorized modification.
How is Availability defined in Information Assurance?
Availability ensures that authorized users can access information and systems when needed.
How is Authentication defined in Information Assurance?
Authentication confirms the identity of a user, device, or system.
How is Nonrepudiation defined in Information Assurance?
Nonrepudiation provides evidence that a particular person or entity performed an action or transaction and cannot reasonably deny having done so.
What is Governance in an organizational context?
Governance refers to how an organization is directed, controlled, and guided in making decisions about its resources, processes, and overall operations.
What are the five key elements of governance?
Decision-making structure, Accountability, Policies and rules, Risk management, and Compliance monitoring.
What is an Information Systems Security Policy?
A security policy is a formal set of rules and guidelines that tells people how information and information systems should be protected and used.
How do Policy, Standard, and Procedure differ?
Policy states WHAT the organization requires; Standard provides a SPECIFIC REQUIREMENT; Procedure explains HOW to perform a task.
What are the seven steps involved in creating security policies?
Where do Information Systems Security Policies fit within an organization's structural flow?
Organizational Goals -> Governance -> Risk Management -> Security Policies -> Standards and Procedures -> Security Controls -> Monitoring and Improvement.
What is Business Process Reengineering (BPR)?
Business Process Reengineering (BPR) involves examining and redesigning existing organizational processes to achieve significant improvements in performance, efficiency, quality, or service.
What sequence represents the continuous improvement cycle for information security?
Plan -> Implement -> Monitor -> Evaluate -> Improve.
How can organizations gain acceptance for security policies?