Shared Flashcard Set

Details

IT223
Lecture 8
23
Computer Science
Undergraduate 2
05/06/2011

Additional Computer Science Flashcards

 


 

Cards

Term
plan
Definition
methof of achieving an end
Term
policy
Definition
management or procedure based on primarily on material interest
Term
standard
Definition
something established by authority, custom, or general consent as a model or example
Term
practice
Definition
the usual way for doing something
Term
procedure
Definition
a particular way of accomplishing something or of acting
Term
guideline
Definition
an indication or outline of policy or conduct
Term
what do policies drive?
Definition
standards
Term
what do standards drive?
Definition
practices, procedures, and guidelines
Term
"information security is primarily a ____ problem, not a technical one"
Definition
management
Term
de facto vs de jure
Definition
de facto- not formally issued but adopted by practice
de jure - secturidy standards should be de jure
Term
what does de jure mean?
Definition
-issued by recognized authority
- should be formal(published writing)
- should include measures to determine compliance and enforcement measures
Term
what is NIST?
Definition
National Institute of Standards and Technology
Term
NIST SP800-14 defines computer security policy as what?
Definition
policy is senior management's directives to cteate a computer security program, establish its goals, and assign responsibilities.
Term
NIST SP-800-14 describes 3 types of policy of IS
Definition
Program
Issue-Specific
System-Specific

for each type, the policy should be: supplemented, visible, supported by management, and consistent
Term
what is System-specific policy
Definition
describes users' access rights for objects
Term
how to represent system-specific policy
Definition
access matrix - model includes
-subjects - entities which could access objects
-objects - entities which could be accessed by subjects
-rights - type of access(read write execute0
Term
a policy is a ____
Definition
living document - whcih means it is changed from time to time - not static or frozen
Term
cyclic model of frame works and blueprints are -
Definition
a continual process of refinement ex is NIST SP 800-26
Term
3 types of contingency plans
Definition
- incident response
- disaster recovery
- business continuity
Term
incident response plan (IRP)
Definition
first level response, to events that are anticipated to occur accasionally
Term
disaster recovery plan (DRP)
Definition
if event is more serious than IRP then DRP is used
Term
business continuity plan (BCP)
Definition
if disaster recovery is not immediate BCP is used.
Term
Business impact analysis (BIA)
Definition
first set of activities in contingency planning
Supporting users have an ad free experience!