Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

INMT 441 QUESTIONS AND ANSWERS FULLY SOLVED

Rating
-
Sold
-
Pages
6
Grade
A+
Uploaded on
17-03-2026
Written in
2025/2026

INMT 441 QUESTIONS AND ANSWERS FULLY SOLVED Defining ISP ISP- subset of it policy that specifies the reequipments of information security or cyber security. ISP concepts procedures- specific actions taken to address a situation rules- specific statements of what are allowed and/or disallowed standards- specific performance expectations guidelines- non-mandatory recommendations the employee may use a s a reference. Major types of ISP within a business - enterprise wide policies -systems specific policies - issue- specific policies (security issues may cross multiple systems) EISP high level isp that sets the strategic direction, scope, and tone for an organization. who leads an EISP directed by the chief information security officer System-Specific Information Security Policy (SISP) organizational policy that functions as standards or procedures to be used when configuring or maintaining a specific information system. SISP can be - seperated into managerial guidance and technical specifications; or -combined in a single unified SISP docuement ISSP- issue specific security policy is an organizational policy that provides detailed, targeted, guidance to instruct all members of the organization in the use of a resource. purpose of ISSP - to establish a common understanding of the purposes for which an employee can and cannot use the resource. steps to creating the ISP -determine which information assets to protect from which threats - determine access needs to system parts -identify resources to protect assets -develop written security policy -commit sources General requirements of ISP -policy should never conflict with law -must be able to stand up in court -policy must be properly supported and and administered Guidelines for an effective ISP -developed accepted industry practices -distributed using all appropriate methods -read by all employees -understood -formally agreed to -uniformly applied and enforced agreement by act occurs when the employee performs an action which requires them to acknowledge understanding of the policy prior to the use of a technology or resource employee refuses to respond to policy - may be grounds for termination -seta programs Violations of ISP - Ignorance -Accident -Intent PCIDSS Payment card industry data security standard is a set of industry standards mandated for any organization that handles cards. SETA Security Education Training Awareness purpose of the SETA reduce intentional or accidental security breaches by members of the organization Pros of SETA - improves employees cybersecurity behavior - informs employees where to report violations of ISP * design an implementation of SETA 1. identify problem, scope, goals, objective 2. identify target audience ify training methods 4. motivate management and employees 5. administer the program, deliver training 6. maintain the program 7. evaluate program Delivery of training methods for seta 1. one on one 2. formal class 3. computer based training 4. distance learning user support groups 5. on job training 6. self study Gamification using game based mechanics for training Phishing Fraudulent emails - emails -websites -messages Business continuity (BC) plan is a set of policies, tools and procedures, or plan,to enable an organization to continue the delivery of goods and/or services at pre-defined acceptable levels following a disruptive event. Disaster recovery (DR) plan is a set of policies, tools and procedures to enablethe recovery or continuation of vital technology infrastructure and systemsfollowing a natural or human-induced disaster. Incident response (IR) plan is a set of policies, tools and procedures to dictatean organization's reactions to a cybersecurity incident. Crisis Management CM) plan is a set of policies, tools and procedures by which an organization deals with a disruptive and unexpected event thatthreatens the organization or its stakeholders.

Show more Read less
Institution
INMT
Course
INMT

Content preview

INMT 441 QUESTIONS AND ANSWERS
FULLY SOLVED

Defining ISP – answer ISP- subset of it policy that specifies the requibments of
information security or cyber security.

ISP concepts - answer procedures- specific actions taken to address a situation
rules- specific statements of what are allowed and/or disallowed
standards- specific performance expectations
guidelines- non-mandatory recommendations the employee may use a s a reference.

Major types of ISP within a business - answer- enterprise wide policies
-systems specific policies
- issue- specific policies
(security issues may cross multiple systems)

EISP - answerhigh level isp that sets the strategic direction, scope, and tone for an
organization.

who leads an EISP - answerdirected by the chief information security officer

System-Specific Information Security Policy (SISP) - answerorganizational policy that
functions as standards or procedures to be used when configuring or maintaining a
specific information system.

SISP can be - answer- seperated into managerial guidance and technical specifications;
or
-combined in a single unified SISP docuement

ISSP- issue specific security policy - answeris an organizational policy that provides
detailed, targeted, guidance to instruct all members of the organization in the use of a
resource.

purpose of ISSP - answer- to establish a common understanding of the purposes for
which an employee can and cannot use the resource.

steps to creating the ISP - answer-determine which information assets to protect from
which threats
- determine access needs to system parts
-identify resources to protect assets
-develop written security policy
-commit sources

, General requirements of ISP - answer-policy should never conflict with law
-must be able to stand up in court
-policy must be properly supported and and administered

Guidelines for an effective ISP - answer-developed accepted industry practices
-distributed using all appropriate methods
-read by all employees
-understood
-formally agreed to
-uniformly applied and enforced

agreement by act - answeroccurs when the employee performs an action which
requires them to acknowledge understanding of the policy prior to the use of a
technology or resource

employee refuses to respond to policy - answer- may be grounds for termination
-seta programs

Violations of ISP - answer- Ignorance
-Accident
-Intent

PCIDSS - answerPayment card industry data security standard is a set of industry
standards mandated for any organization that handles cards.

SETA - answerSecurity Education Training Awareness

purpose of the SETA - answerreduce intentional or accidental security breaches by
members of the organization

Pros of SETA - answer- improves employees cybersecurity behavior
- informs employees where to report violations of ISP

* design an implementation of SETA - answer1. identify problem, scope, goals,
objective
2. identify target audience
3.identify training methods
4. motivate management and employees
5. administer the program, deliver training
6. maintain the program
7. evaluate program

Delivery of training methods for seta - answer1. one on one
2. formal class
3. computer based training

Written for

Institution
INMT
Course
INMT

Document information

Uploaded on
March 17, 2026
Number of pages
6
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$16.49
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
julianah420 Phoenix University
Follow You need to be logged in order to follow users or courses
Sold
703
Member since
3 year
Number of followers
329
Documents
35748
Last sold
1 hour ago
NURSING,TESTBANKS,ASSIGNMENT,AQA AND ALL REVISION MATERIALS

On this page, you find all documents, package deals, and flashcards offered by seller julianah420

4.2

157 reviews

5
102
4
21
3
12
2
6
1
16

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions