Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

Self-Exercises Information Security Strategy 1. An information security strategic plan can position an organization to mitigate, transfer accept or avoid information risk related to people,

image text in transcribed
Self-Exercises Information Security Strategy 1. An information security strategic plan can position an organization to mitigate, transfer accept or avoid information risk related to people, processes and technologies. Describe what should be included in an Information Security Strategic Plan. 2. Describe the steps in developing an information security strategy 3. For a security strategy to be effective it should meet certain conditions, i.e. how the strategy should be. Discuss these conditions. 4. Strategy and planning requires a thorough understanding of many issues. Discuss five (S) of these issues that need to be considered when developing an information security strategy 5. Risk management is an important process in security planning. Explain the steps to manage risks, as part of a security plan [NIST SP 800-53]. Information Security Management System (ISMS) 1. An Information Security Management System (ISMS) is a set of policies concerned with information security management or IT related risks. The goveming principle behind an ISMS is that an organization should design, implement and maintain a coherent set of policies, processes and systems to manage risks to its information assets, thus ensuring acceptable levels of information security risk. Describe the "Plan-Do-Check-Act" (PDCA), or Deming cycle approach in ISMS 2. Discuss the critical success factors for an ISMS to be effective. 3. Discuss three main problems which lead to uncertainty in information security management systems (ISMS). 4. Discuss the 11 domains of the information security management systems (ISMS). Information Security Culture 1. Information security culture refers to ideas, customs and social behaviors of a group of people, that impacts their security. It describes the kind of behaviors organizations would like to see in their employees, in areas like cybersecurity, physical security and personnel security. Discuss three tips on how to create a cyber security culture at work

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Relational Database Design With Microcomputer Applications

Authors: Glenn A. Jackson

1st Edition

0137718411, 978-0137718412

More Books

Students also viewed these Databases questions

Question

Explain the factors influencing consumer behaviour.

Answered: 1 week ago