/
Information Security Policy Overview
Save to my account
Sign up
Information Security Policy Overview
Information Security Policy Overview
Study
1
Question
A set of rules and procedures that keeps an organization's data secure. The policy applies to all digital data.
Answer
Information Security Policy
2
Question
Who does the Information Security Policy apply to?
Answer
It applies to all digital data: - facilities - third and fourth parties users - programs, systems - data - infrastructure, network.
3
Question
What are the main objectives of INFOSEC Policy?
Answer
1. Laying out user access control policies and security measures. 2. Defining an overall approach to security. 3. Protecting an organization's reputation. 4. Detecting compromised assets and minimizing the impacts. 5. Protecting sensitive client data and limiting access to legitimate users. 6. Complying with applicable legal requirements.
4
Question
What are the characteristics of an effective information security policy?
Answer
It should be practical, enforceable, and flexible.
5
Question
Why is an information security policy important?
Answer
1. Helps protect against malicious threats. 2. Critical for protecting highly sensitive data. 3. Minimizing vendor risk.
6
Question
What are the 8 elements of an Information Security Policy?
Answer
- Purpose - Audience & Scope - Information Security Objectives - Authority & Access Control Policy - Data Classification - Data support and operations - Security awareness and behavior - Responsibilities, rights & duties of personnel
7
Question
What is the main purpose of an information security policy?
Answer
To protect your company's essential digital information.
8
Question
Create an overall approach to ___ (Purpose 1)
Answer
information security.
9
Question
___ and ___ information security ___ such as ___ of networks, data, applications, and ___. (Purpose 2)
Answer
Detect, Preempt, breaches, misuse, computer systems
10
Question
___ the ____ of the organization, and uphold ___ and ___ responsibilities (Purpose 3)
Answer
Maintain, Reputation, ethical, legal
11
Question
___ customer rights, including how to ___ to inquiries and complaints about ___ (Purpose 4)
Answer
Respect, React, Non-compliance
12
Question
What does the audience scope of the policy indicate?
Answer
Which users the policy will apply to and which it will not apply to.
13
Question
What are the three main objectives of information security?
Answer
1. confidentiality. 2. integrity. 3. availability.
14
Question
What does the Authority & Access Control Policy indicate?
Answer
It indicates what members of the organization have the authority to limit access to data.
15
Question
The policy should outline the level of authority over data and IT systems for each organizational role. (Authority Access Control Policy)
Answer
Heirarchal Pattern
16
Question
What is the policy that states "users are only able to access company networks and servers via unique logins." (Authority Access Control Policy)
Answer
Network Security Policy
17
Question
What are the categories of data classification?
Answer
1. Public. 2. Confidential. 3. Internal. 4. Restricted.
18
Question
Examples of high-risk, legally protected data include what?
Answer
1. Healthcare information protected under HIPAA. 2. Educational information protected under FERPA. 3. Payroll information.
19
Question
These are the three primary categories of data support operations:
Answer
- data protection regulations - data backup requirements - movement of data
20
Question
What are data protection regulations?
Answer
Most security standards and regulations require at least a firewall, data encryption, and malware protection.
21
Question
What are the data backup requirements?
Answer
Encrypt your backups and store the backup media securely. Storing backup data securely in the cloud is a highly secure option.
22
Question
What is important regarding the movement of data?
Answer
Ensure you transfer your data over secure protocols and encrypt any information you copy to portable devices.
23
Question
What should security awareness and behavior training include?
Answer
Conduct training sessions to inform employees of your security procedures and mechanisms.
24
Question
Examples of security awareness and behavior
Answer
social engineering, clean desk policy, and acceptable internet usage policy.
25
Question
What should responsibilities, rights, and duties of personnel outline?
Answer
The rights, responsibilities, and duties of staff members regarding data protection.
26
Question
Best practices for information security policies
Answer
- Make your policy a living document - Coordinate between departments - Develop a security incident response plan - Develop acceptable use policies - Comply with privacy regulations