1602 final guide
A-1
Making IT security policies available on an internal intranet ensures easy employee access. Regular updates improve policy adherence, keep information current, and reduce policy confusion or outdated references.
π Your notes/example: _____________________________________________
A-2
A baseline standard specifies technical configurations and security settings required for devices and systems.
β’ Goals/objectives: Found in strategic documents like a mission statement.
β’ General guidelines: Part of broader policies, not strict baselines.
β’ IT staff responsibilities: Typically detailed in roles/responsibilities sections.
π Your notes/example: _____________________________________________
A-3
Automating the documentation process increases efficiency, consistency, and accuracy. It helps reduce manual errors, keeps logs up-to-date, and improves compliance with auditing and regulatory frameworks.
π Your notes/example: _____________________________________________
A-4
RPO: how much data loss is acceptable during an incident.
RTO: Time to recover services.
MTD: Max tolerable downtime before serious impact.
MTTR: Time to repair a failed system.
π Your notes/example: _____________________________________________
A-5
The first line of defense is generally operational management and control owners. ERM is part of the second line, focusing on policy development, oversight, and integration with strategic business goals.
π Your notes/example: _____________________________________________
A-6
System administrators: hold the highest level of access, allowing them to perform system maintenance, configuration, and advanced troubleshooting.
Employees: Typically have user-level access.
Contractors: May have temporary or restricted access.
Vendors: Usually have access limited to specific platforms.
π Your notes/example: _____________________________________________
A-7
PAAs are formal agreements that outline the expectations, limitations, and responsibilities of users with elevated system access. They help ensure accountability and track the use of administrative privileges.
π Your notes/example: _____________________________________________
A-8
The Scope: What resources, systems, people, and environments are subject to the policy.
Purpose: States the objective of the policy.
Background: Provides context or reason.
Effective Dates: Specifies when the policy goes into effect.
π Your notes/example: _____________________________________________
A-9
Operational risk committee manages day-to-day IT risks and aligns them with business processes.
π Your notes/example: _____________________________________________
A-10
The Proportionality Principle ensures that security controls are matched to the value and sensitivity of data. For example, highly confidential data may require multi-factor authentication, while public-facing content may not.
π Your notes/example: _____________________________________________
B-1
Risk transference involves shifting the financial burden of risk to another party, such as through insurance or outsourcing.
π Your notes/example: _____________________________________________
B-2
Spear phishing is often more dangerous than general phishing because it is targeted and tailored, increasing the chance of success. While it reaches fewer people, it often targets high-value individuals.
π Your notes/example: _____________________________________________
B-3
Defense-in-Depth means deploying multiple, overlapping layers of security such as firewalls, endpoint protection, user training, and encryption.
π Your notes/example: _____________________________________________
B-4
Critical data refers to information that must be recovered quickly (often within 30 minutes) to avoid major disruption.
π Your notes/example: _____________________________________________
B-5
The Remote Access Domain covers policies for secure authentication of remote users, use of VPNs, and endpoint protection while accessing internal networks.
π Your notes/example: _____________________________________________
B-6
Separation of duties prevents fraud, error, and misuse by ensuring no single person controls a critical process end-to-end. For example, one person authorizes a transaction and another approves it.
π Your notes/example: _____________________________________________
B-7
In the U.S. military system, βConfidentialβ refers to data that, if disclosed, could cause damage to national securityβa mid-level classification below βSecretβ and βTop Secret.β
π Your notes/example: _____________________________________________
B-8
A BIA identifies critical business processes, dependencies, and potential impacts of disruptions. It supports recovery planning by prioritizing what must be restored first during outages or disasters.
π Your notes/example: _____________________________________________
B-9
A secure data handling policy should include controlled encryption key access and a retrievable but protected key management process.
π Your notes/example: _____________________________________________
B-10
A Security Awareness Policy educates users on identifying, reporting suspicious activity, and understanding basic cyber hygiene. It is a crucial element of organizational defense.
π Your notes/example: _____________________________________________
C-1
Strategic risks are high-level risks that can influence long-term business direction or operations.
π Your notes/example: _____________________________________________
C-2
The IRT is responsible for containing threats, performing forensic analysis, identifying the root cause, and helping to restore normal operations.
π Your notes/example: _____________________________________________
C-3
Mitigating insider threats involves layered security, access monitoring, and policy enforcement.
π Your notes/example: _____________________________________________
C-4
Defense-in-depth uses multiple layers of controls (physical, technical, and administrative) to reduce the likelihood of successful attacks.
π Your notes/example: _____________________________________________
C-5
An IDS (Intrusion Detection System) monitors network traffic and system activities to detect potential threats.
π Your notes/example: _____________________________________________
C-6
Least privilege limits access rights to only what's necessary for users to perform their duties.
π Your notes/example: _____________________________________________
C-7
The first step in responding to an incident is to contain the incident to limit its spread or damage.
π Your notes/example: _____________________________________________
C-8
A DMZ (Demilitarized Zone) houses public-facing services (web, DNS, email servers) and separates them from the internal network, minimizing the risk of internal exposure if these public systems are breached.
π Your notes/example: _____________________________________________
C-9
Encryption keys should be stored separately from the data they protect. Keeping them together compromises confidentiality and integrity in the event of a breach or backup theft.
π Your notes/example: _____________________________________________
C-10
COBIT: IT governance and management framework that aligns IT processes with business goals and emphasizes risk management.
ITIL: Focuses on IT service management.
PCI DSS: Enforces security for cardholder data.
ISO 27001: Focuses on information security management systems (ISMS).
π Your notes/example: _____________________________________________
D-1
CEO or Board of Directors: signs off on major security policies to ensure executive-level accountability and support.
CISO: May draft or recommend policies but lacks final approval authority.
CFO: Oversees finance.
CMO: Focuses on marketing and external communication.
π Your notes/example: _____________________________________________
D-2
The Executive Committee helps eliminate organizational roadblocks, allocates funding, and sets high-level security priorities.
π Your notes/example: _____________________________________________
D-3
ACL: restrict access to systems, making them a preventive control.
IDS: Detects threats but doesnβt prevent them.
SIEM: Aggregates logs and alerts.
Backups: Help recovery.
π Your notes/example: _____________________________________________
D-4
Classification policies are designed to identify, label, and protect data based on its sensitivity and value.
π Your notes/example: _____________________________________________
D-5
An Intrusion Prevention System (IPS) differs from an IDS because it can detect and actively block threats in real time, especially within the LAN environment, helping to reduce attack success rates.
π Your notes/example: _____________________________________________
D-6
Firewall rules for public web servers fall under server or network domain policies.
π Your notes/example: _____________________________________________
D-7
Nessus is widely used for automated vulnerability scans across networks.
π Your notes/example: _____________________________________________
D-8
PAAs ensure that users with elevated privileges acknowledge responsibilities, risks, and acceptable use standards.
π Your notes/example: _____________________________________________
D-9
A detailed guide on configuring IDS is a procedure document, offering step-by-step technical instructions.
π Your notes/example: _____________________________________________
D-10
Least privilege restricts users to only the access needed to perform their role.
π Your notes/example: _____________________________________________
E-1
PCI DSS is the standard created for handling credit card data securely.
π Your notes/example: _____________________________________________
E-2
Vendors and contractors should have limited, controlled access tailored to their function. Providing the same access as full-time employees can expose sensitive systems to higher risk due to limited oversight or turnover.
π Your notes/example: _____________________________________________
E-3
Risk avoidance means eliminating exposure by not engaging in the activity at all.
π Your notes/example: _____________________________________________
E-4
Separation of duties divides responsibilities among individuals to prevent fraud and error. For example, the person who approves a change shouldn't be the one to implement it.
π Your notes/example: _____________________________________________
E-5
BYOD (Bring Your Own Device) policies should enforce access controls, such as network segmentation and device registration. Unrestricted access increases vulnerability to malware, data leakage, and compliance issues.
π Your notes/example: _____________________________________________
E-6
Risk and Control Self-Assessment evaluates operational risks, internal controls, and process weaknesses, not just financial risks. It helps departments self-identify gaps in risk management and compliance posture.
π Your notes/example: _____________________________________________
E-7
An AUP defines appropriate behaviors and restrictions regarding the use of corporate technology, email, internet, and data.
π Your notes/example: _____________________________________________
E-8
Social engineering relies on manipulating people into giving up confidential information.
π Your notes/example: _____________________________________________
E-9
Effective security policy development should include HR, Legal, Compliance, and IT to align controls with organizational goals, laws, and human factors. Lack of collaboration can lead to gaps and noncompliance.
π Your notes/example: _____________________________________________
E-10
An IRT should include a diverse team from IT (technical response), Legal (liability), Public Relations (communications), and Business Continuity (recovery coordination) to ensure well-rounded incident management.
π Your notes/example: _____________________________________________