1602 final guide

A-1

Making IT security policies available on an internal intranet ensures easy employee access. Regular updates improve policy adherence, keep information current, and reduce policy confusion or outdated references.

πŸ“ Your notes/example: _____________________________________________

A-2

A baseline standard specifies technical configurations and security settings required for devices and systems.

β€’ Goals/objectives: Found in strategic documents like a mission statement.

β€’ General guidelines: Part of broader policies, not strict baselines.

β€’ IT staff responsibilities: Typically detailed in roles/responsibilities sections.

πŸ“ Your notes/example: _____________________________________________

A-3

Automating the documentation process increases efficiency, consistency, and accuracy. It helps reduce manual errors, keeps logs up-to-date, and improves compliance with auditing and regulatory frameworks.

πŸ“ Your notes/example: _____________________________________________

A-4

RPO: how much data loss is acceptable during an incident.

RTO: Time to recover services.

MTD: Max tolerable downtime before serious impact.

MTTR: Time to repair a failed system.

πŸ“ Your notes/example: _____________________________________________

A-5

The first line of defense is generally operational management and control owners. ERM is part of the second line, focusing on policy development, oversight, and integration with strategic business goals.

πŸ“ Your notes/example: _____________________________________________

A-6

System administrators: hold the highest level of access, allowing them to perform system maintenance, configuration, and advanced troubleshooting.

Employees: Typically have user-level access.

Contractors: May have temporary or restricted access.

Vendors: Usually have access limited to specific platforms.

πŸ“ Your notes/example: _____________________________________________

A-7

PAAs are formal agreements that outline the expectations, limitations, and responsibilities of users with elevated system access. They help ensure accountability and track the use of administrative privileges.

πŸ“ Your notes/example: _____________________________________________

A-8

The Scope: What resources, systems, people, and environments are subject to the policy.

Purpose: States the objective of the policy.

Background: Provides context or reason.

Effective Dates: Specifies when the policy goes into effect.

πŸ“ Your notes/example: _____________________________________________

A-9

Operational risk committee manages day-to-day IT risks and aligns them with business processes.

πŸ“ Your notes/example: _____________________________________________

A-10

The Proportionality Principle ensures that security controls are matched to the value and sensitivity of data. For example, highly confidential data may require multi-factor authentication, while public-facing content may not.

πŸ“ Your notes/example: _____________________________________________

B-1

Risk transference involves shifting the financial burden of risk to another party, such as through insurance or outsourcing.

πŸ“ Your notes/example: _____________________________________________

B-2

Spear phishing is often more dangerous than general phishing because it is targeted and tailored, increasing the chance of success. While it reaches fewer people, it often targets high-value individuals.

πŸ“ Your notes/example: _____________________________________________

B-3

Defense-in-Depth means deploying multiple, overlapping layers of security such as firewalls, endpoint protection, user training, and encryption.

πŸ“ Your notes/example: _____________________________________________

B-4

Critical data refers to information that must be recovered quickly (often within 30 minutes) to avoid major disruption.

πŸ“ Your notes/example: _____________________________________________

B-5

The Remote Access Domain covers policies for secure authentication of remote users, use of VPNs, and endpoint protection while accessing internal networks.

πŸ“ Your notes/example: _____________________________________________

B-6

Separation of duties prevents fraud, error, and misuse by ensuring no single person controls a critical process end-to-end. For example, one person authorizes a transaction and another approves it.

πŸ“ Your notes/example: _____________________________________________

B-7

In the U.S. military system, β€œConfidential” refers to data that, if disclosed, could cause damage to national securityβ€”a mid-level classification below β€œSecret” and β€œTop Secret.”

πŸ“ Your notes/example: _____________________________________________

B-8

A BIA identifies critical business processes, dependencies, and potential impacts of disruptions. It supports recovery planning by prioritizing what must be restored first during outages or disasters.

πŸ“ Your notes/example: _____________________________________________

B-9

A secure data handling policy should include controlled encryption key access and a retrievable but protected key management process.

πŸ“ Your notes/example: _____________________________________________

B-10

A Security Awareness Policy educates users on identifying, reporting suspicious activity, and understanding basic cyber hygiene. It is a crucial element of organizational defense.

πŸ“ Your notes/example: _____________________________________________

C-1

Strategic risks are high-level risks that can influence long-term business direction or operations.

πŸ“ Your notes/example: _____________________________________________

C-2

The IRT is responsible for containing threats, performing forensic analysis, identifying the root cause, and helping to restore normal operations.

πŸ“ Your notes/example: _____________________________________________

C-3

Mitigating insider threats involves layered security, access monitoring, and policy enforcement.

πŸ“ Your notes/example: _____________________________________________

C-4

Defense-in-depth uses multiple layers of controls (physical, technical, and administrative) to reduce the likelihood of successful attacks.

πŸ“ Your notes/example: _____________________________________________

C-5

An IDS (Intrusion Detection System) monitors network traffic and system activities to detect potential threats.

πŸ“ Your notes/example: _____________________________________________

C-6

Least privilege limits access rights to only what's necessary for users to perform their duties.

πŸ“ Your notes/example: _____________________________________________

C-7

The first step in responding to an incident is to contain the incident to limit its spread or damage.

πŸ“ Your notes/example: _____________________________________________

C-8

A DMZ (Demilitarized Zone) houses public-facing services (web, DNS, email servers) and separates them from the internal network, minimizing the risk of internal exposure if these public systems are breached.

πŸ“ Your notes/example: _____________________________________________

C-9

Encryption keys should be stored separately from the data they protect. Keeping them together compromises confidentiality and integrity in the event of a breach or backup theft.

πŸ“ Your notes/example: _____________________________________________

C-10

COBIT: IT governance and management framework that aligns IT processes with business goals and emphasizes risk management.

ITIL: Focuses on IT service management.

PCI DSS: Enforces security for cardholder data.

ISO 27001: Focuses on information security management systems (ISMS).

πŸ“ Your notes/example: _____________________________________________

D-1

CEO or Board of Directors: signs off on major security policies to ensure executive-level accountability and support.

CISO: May draft or recommend policies but lacks final approval authority.

CFO: Oversees finance.

CMO: Focuses on marketing and external communication.

πŸ“ Your notes/example: _____________________________________________

D-2

The Executive Committee helps eliminate organizational roadblocks, allocates funding, and sets high-level security priorities.

πŸ“ Your notes/example: _____________________________________________

D-3

ACL: restrict access to systems, making them a preventive control.

IDS: Detects threats but doesn’t prevent them.

SIEM: Aggregates logs and alerts.

Backups: Help recovery.

πŸ“ Your notes/example: _____________________________________________

D-4

Classification policies are designed to identify, label, and protect data based on its sensitivity and value.

πŸ“ Your notes/example: _____________________________________________

D-5

An Intrusion Prevention System (IPS) differs from an IDS because it can detect and actively block threats in real time, especially within the LAN environment, helping to reduce attack success rates.

πŸ“ Your notes/example: _____________________________________________

D-6

Firewall rules for public web servers fall under server or network domain policies.

πŸ“ Your notes/example: _____________________________________________

D-7

Nessus is widely used for automated vulnerability scans across networks.

πŸ“ Your notes/example: _____________________________________________

D-8

PAAs ensure that users with elevated privileges acknowledge responsibilities, risks, and acceptable use standards.

πŸ“ Your notes/example: _____________________________________________

D-9

A detailed guide on configuring IDS is a procedure document, offering step-by-step technical instructions.

πŸ“ Your notes/example: _____________________________________________

D-10

Least privilege restricts users to only the access needed to perform their role.

πŸ“ Your notes/example: _____________________________________________

E-1

PCI DSS is the standard created for handling credit card data securely.

πŸ“ Your notes/example: _____________________________________________

E-2

Vendors and contractors should have limited, controlled access tailored to their function. Providing the same access as full-time employees can expose sensitive systems to higher risk due to limited oversight or turnover.

πŸ“ Your notes/example: _____________________________________________

E-3

Risk avoidance means eliminating exposure by not engaging in the activity at all.

πŸ“ Your notes/example: _____________________________________________

E-4

Separation of duties divides responsibilities among individuals to prevent fraud and error. For example, the person who approves a change shouldn't be the one to implement it.

πŸ“ Your notes/example: _____________________________________________

E-5

BYOD (Bring Your Own Device) policies should enforce access controls, such as network segmentation and device registration. Unrestricted access increases vulnerability to malware, data leakage, and compliance issues.

πŸ“ Your notes/example: _____________________________________________

E-6

Risk and Control Self-Assessment evaluates operational risks, internal controls, and process weaknesses, not just financial risks. It helps departments self-identify gaps in risk management and compliance posture.

πŸ“ Your notes/example: _____________________________________________

E-7

An AUP defines appropriate behaviors and restrictions regarding the use of corporate technology, email, internet, and data.

πŸ“ Your notes/example: _____________________________________________

E-8

Social engineering relies on manipulating people into giving up confidential information.

πŸ“ Your notes/example: _____________________________________________

E-9

Effective security policy development should include HR, Legal, Compliance, and IT to align controls with organizational goals, laws, and human factors. Lack of collaboration can lead to gaps and noncompliance.

πŸ“ Your notes/example: _____________________________________________

E-10

An IRT should include a diverse team from IT (technical response), Legal (liability), Public Relations (communications), and Business Continuity (recovery coordination) to ensure well-rounded incident management.

πŸ“ Your notes/example: _____________________________________________