FULLY SOLVED
Defining ISP – answer ISP- subset of it policy that specifies the requibments of
information security or cyber security.
ISP concepts - answer procedures- specific actions taken to address a situation
rules- specific statements of what are allowed and/or disallowed
standards- specific performance expectations
guidelines- non-mandatory recommendations the employee may use a s a reference.
Major types of ISP within a business - answer- enterprise wide policies
-systems specific policies
- issue- specific policies
(security issues may cross multiple systems)
EISP - answerhigh level isp that sets the strategic direction, scope, and tone for an
organization.
who leads an EISP - answerdirected by the chief information security officer
System-Specific Information Security Policy (SISP) - answerorganizational policy that
functions as standards or procedures to be used when configuring or maintaining a
specific information system.
SISP can be - answer- seperated into managerial guidance and technical specifications;
or
-combined in a single unified SISP docuement
ISSP- issue specific security policy - answeris an organizational policy that provides
detailed, targeted, guidance to instruct all members of the organization in the use of a
resource.
purpose of ISSP - answer- to establish a common understanding of the purposes for
which an employee can and cannot use the resource.
steps to creating the ISP - answer-determine which information assets to protect from
which threats
- determine access needs to system parts
-identify resources to protect assets
-develop written security policy
-commit sources
, General requirements of ISP - answer-policy should never conflict with law
-must be able to stand up in court
-policy must be properly supported and and administered
Guidelines for an effective ISP - answer-developed accepted industry practices
-distributed using all appropriate methods
-read by all employees
-understood
-formally agreed to
-uniformly applied and enforced
agreement by act - answeroccurs when the employee performs an action which
requires them to acknowledge understanding of the policy prior to the use of a
technology or resource
employee refuses to respond to policy - answer- may be grounds for termination
-seta programs
Violations of ISP - answer- Ignorance
-Accident
-Intent
PCIDSS - answerPayment card industry data security standard is a set of industry
standards mandated for any organization that handles cards.
SETA - answerSecurity Education Training Awareness
purpose of the SETA - answerreduce intentional or accidental security breaches by
members of the organization
Pros of SETA - answer- improves employees cybersecurity behavior
- informs employees where to report violations of ISP
* design an implementation of SETA - answer1. identify problem, scope, goals,
objective
2. identify target audience
3.identify training methods
4. motivate management and employees
5. administer the program, deliver training
6. maintain the program
7. evaluate program
Delivery of training methods for seta - answer1. one on one
2. formal class
3. computer based training