What does information security protect in an organization?
An organization's valuable resources.
What are the three basic information security requirements?
Availability, integrity, and confidentiality.
What does availability assure in information security?
That authorized users can access a system whenever needed.
What does integrity protect in a computer system?
System information from unauthorized changes.
What does confidentiality assure about protected information?
That unauthorized people cannot access it.
What is identification in information security?
How users claim their identities.
What does authentication test in information security?
Evidence of identity.
What does authorization grant to users?
Rights and permissions.
Why does information classification focus protection on certain data?
Because not all data has the same value to an organization.
Which private-sector classification term is similar to unclassified?
Public
What classification term describes very sensitive data harming a company if disclosed?
Confidential
Who identifies the administrator or custodian in the classification procedure?
The classification procedure itself specifies the administrator or custodian.
What role does the information owner have in classification?
The information owner determines the required classification and delegates protection duties.
What is a security policy in information security?
The highest level of documentation guiding security implementation.
What does the senior management statement of policy acknowledge?
The importance of computing resources.
What does the senior management policy commit to managing?
Lower-level standards, procedures, and guidelines.
How do standards differ from guidelines in security policies?
Standards are compulsory and uniform, guidelines are flexible and non-compulsory.
What do procedures contain in security documentation?
Detailed steps for performing specific tasks.
Who has ultimate security responsibility in an organization?
The senior manager.
Who determines data classification in security roles?
The owner.
Why is security awareness training necessary?
Because people are often the weakest link in a security chain.
What does risk management do before mitigating or transferring risk?
It identifies, analyzes, and assesses risk.
What does risk analysis examine in a target environment?
It examines risk-related attributes and vulnerabilities.
What does risk analysis associate vulnerabilities with?
Affected assets.
What does risk analysis determine and evaluate?
Potential undesirable results and risk-reducing countermeasures.
What does risk assessment assign value to?
Assets, threat frequency, consequences, and elements of chance.
What must risk decisions consider about the impact?
How severe the impact could be.
What frequency aspect must risk decisions consider?
How often the risk could happen annually.
What cost-related factors must risk decisions consider?
Annualized cost and cost-effectiveness of mitigation.
What formula defines Single Loss Expectancy (SLE)?
What does Exposure Factor measure in risk management?
The magnitude of loss on an asset as a percentage of its value.
How is Exposure Factor expressed?
As a percentage from 0 to 100% of asset value lost.
What does Annualized Rate of Occurrence (ARO) represent?
The frequency a threat is expected to occur annually.
Give an example of an Annualized Rate of Occurrence (ARO).
50 occurrences in one year produce an ARO of 50.
What formula defines Annualized Loss Expectancy (ALE)?
What formula calculates the value of a safeguard?
What does Business Continuity Planning ensure during an emergency?
Business can continue during an emergency.
What is the main goal of Disaster Recovery Planning?
To recover from an emergency with minimum organizational impact.
Name one objective of Business Continuity Planning.
Preventing interruptions.
What type of events are fires and earthquakes classified as?
Natural disruptive events.
What type of events include bombings and sabotage?
Man-made disruptive events.
What does BCP scope and plan initiation examine?
Operations and support services.
What document does Business Impact Analysis create?
A document that helps determine the impact of a disruptive event on the business.
What is Maximum Tolerable Downtime?
The longest period a critical process can be interrupted before the company cannot recover.
What does BIA identify regarding business processes?
Interdependencies and acceptable interruption periods.
What impacts does BIA record?
Quantitative and qualitative impacts.
What does BIA recommend to senior management?
Recovery priorities.
What information is used to create a recovery strategy in continuity plan development?
Business Impact Analysis (BIA) information.
What must senior management do for disaster recovery plan approval?
Provide approval for the plan.
What is one objective of disaster recovery planning (DRP)?
To organize crisis decisions effectively.
What does continuity plan documentation include besides recovery strategy?
Computing, facilities, people, supplies, and equipment details.
What is required to ensure personnel readiness in disaster recovery plan implementation?
Training for personnel with specific duties.
What does disaster recovery planning aim to reduce in personnel during disasters?
Disaster-time decision-making by personnel.
What must be prevented to maintain disaster recovery plan integrity?
Multiple versions of the plan.
What reliability aspect is tested in disaster recovery planning objectives?
Standby-system reliability.
What does the DRP process develop and maintain?
Recovery plans for data-processing continuity during disasters.
How does a hot site differ from a cold site?
A hot site is fully configured and immediately available; a cold site provides only space and utilities without hardware.
What are examples of alternate processing services besides hot, warm, and cold sites?
Mutual aid agreements, multiple centers, service bureaus, and other data-center backup alternatives.
What distinguishes electronic vaulting from remote journaling and database shadowing?
Electronic vaulting transfers backup data off-site.
What is a mutual aid agreement in disaster recovery?
An arrangement where companies with similar computing needs support each other during disruptions.
What service does a service bureau provide in disaster recovery?
Contracted alternate backup processing services with quick response and possible testing.
What is the purpose of DRP maintenance?
To keep the recovery plan current and regularly report its status through maintenance and audits.
What are the five types of DRP tests ordered from review to full disaster replication?
Checklist, structured walk-through, simulation, parallel, and full-interruption testing.
Test your knowledge with 32 questions on Information Security and Continuity Planning.
1. What is the primary purpose of information security within an organization?
2. Which set correctly identifies the three basic requirements of information security?
Review the complete course in the study sheet for Information Security and Continuity Planning.
See study sheet →Import your course and AI generates flashcards in 30 seconds.
Flashcard generator