Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 22 pages
Exam (elaborations)

INMT 441 Exam 2Questions and Answers

Document preview thumbnail
Preview 3 out of 22 pages

INMT 441 Exam 2Questions and Answers

Content preview

INMT 441 Exam 2Questions and
Answers




Policy - Answer-an organization's statement of intent



IT policy - Answer-an organization's policy regarding IT investment, management, and use



Information Security Policy (ISP) - Answer-a subset of IT policy that specifies the requirements regarding
information security or cybersecurity



Other Concepts Related to ISP - Answer--procedures

-rules

-standards

-guidelines



Procedures - Answer-specific actions taken to address a situation



Rules - Answer-specific statements of what are allowed and/or disallowed



Standards - Answer-specific performance expectations

,Guidelines - Answer-nonmandatory recommendations the employee may use as a reference in
complying with a policy



Major Elements of an ISP - Answer--IT assets to protect and why: purpose and scope

-protection roles and responsibility

-administration and interpretations of the policy

-amendements/

-termination (if any)

-references to applicable policies (if applicable)

-key definitions (if necessary)



Major Types of ISPs in Organizations - Answer-a complete system of ISPs contain the following three
types of policies:

-enterprise information security policy

-systems specific policies

-issue specific security policies



Enterprise Information Security Policy (EISP) - Answer-a high-level information security policy that sets
the strategic direction, scope, and tone for all of an organization's security efforts



-usually drafted/led by the CISO

-typically 2-10 pages

-governs the development of other system-specific and issue-specific ISPs



EISP Elements - Answer--an overview of the corporate philosophy on security

, an overview of the structure of the information security organization and individuals who fulfill the
information security role

-fully articulated responsibilities for security that are shared by all members of the organization
(employees, contractors, consultants, partners, and visitors)

-fully articulated responsibilities for security that are unique to each role within the organization



System Specific Information Security Policy - Answer--an organizational policy that functions as
standards or procedures to be used when configuring or maintaining a specific information system

-created by the management to guide the implementation and configuration of technology, as well as to
address the behavior of people in the organization in ways that support the security of information

-can be combined or separated



Issue Specific Security Policy (ISSP) - Answer--an organizational policy that provides detailed, targeted
guidance to instruct all members of the organization in the use of a resource

-in some organizations, ISSPs are referred to as fair and responsible use policies, describing the intent of
the policy to regulate appropriate use

-should assure members of the organization that its purpose is not to establish a foundation for
administrative enforcement or legal prosecution but rather to provide a common understanding of the
purposes for which an employee can and cannot use the resource



Examples of ISSP - Answer--confidential information policy

-use policy

-backup policy

-account management policy

-incident handling procedures

-disaster recovery plan



Establishing an ISP - Answer-steps to create and ISP:

-determine which assets to protect from which threats

Document information

Uploaded on
December 7, 2024
Number of pages
22
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$17.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Zanaya
4.5
(12)
Sold
78
Followers
29
Items
10176
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions