Chapter 13 – Security Policy Design and Implementation
TRUE/FALSE
1. Once written, a security policy should not be altered so that you can maintain consistency.
2. The first phase of the system development life cycle is needs assessment.
3. The first step in SNA is the survivability analysis.
4. The people that manage security for the organization should not be same people that conduct risk
analysis.
5. An extranet is a backup network that you can use if the main network fails.
MULTIPLE CHOICE
1. Which of the following is NOT a phase in the system development life cycle?
a.
needs assessment
c.
system implementation
b.
security audit
d.
performance monitoring
2. Which of the following is considered an asset?
a.
hacker
c.
disgruntled employee
b.
unpatched Web server
d.
intellectual property
3. What is considered the first step in formulating a security policy?
a.
risk analysis
c.
risk reduction
b.
elimination of threats
d.
system monitoring
4. Which of the following is NOT among the six factors needed to create a risk analysis?
a.
threats
c.
personnel profiles
b.
consequences
d.
probabilities
5. Which of the following would be considered a vulnerability?
a.
installation of a firewall
c.
Internet-connected computer
b.
antivirus software
d.
spyware
6. Which best defines residual risk?
a.
risk that occurs as a result of new
vulnerabilities
c.
a vulnerability for which the risk has been
reduced to zero
b.
the amount of risk remaining after
countermeasures are implemented
d.
the cost of implementing solutions to an
assessed risk
7. Which of the following is a network’s ability to detect attacks when they occur and to evaluate the
extent of damage and compromise?
a.
resistance
c.
recognition
b.
recovery
d.
reliability
8. Which is best defined as the ability of a system to continue operations despite a failure?
a.
fault tolerance
c.
reliability audit
b.
survivability analysis
d.
adaptation and evolution
9. Which of the following is NOT a step in threat and risk assessment?
a.
Asset definition
c.
Resolution
b.
Recommendation
d.
Threat assessment
10. Which of the following best describes a Monte Carlo simulation?
a.
a technique for simulating an attack on a
system
c.
a procedural system that simulates a
catastrophe
b.
a formula that estimates the cost of
countermeasures
d.
an analytical method that simulates a real-
life system for risk analysis
11. Which of the following shows how devices are connected and includes an IP allocation register?
a.
hardware inventory
c.
asset table
b.
topology map
d.
security policy
12. Which of the following defines how employees should use the organization’s computing resources?
a.
Network and Internet Policy
c.
Computing and Resource Policy
b.
Email and Spam Policy
d.
Acceptable Use Policy
13. Which of the following requires you to assist police by appearing in court or producing evidence?
a.
subpoena
c.
the 4th amendment
b.
search warrant
d.
de facto agent
14. Which of the following best describes ROI?
a.
the chance that a threat will result in lost
money
c.
the cost of mitigating a threat
b.
how long before an investment will pay
for itself
d.
the benefits of setting security priorities
15. The process of reviewing records of network computer activity is called which of the following?
a.
monitoring
c.
auditing
b.
archiving
d.
recording
COMPLETION
1. The __________________ phase of the system development life cycle can lead you to the needs
assessment phase where the cycle begins again.
2. The process called _____________ analysis determines the threats an organization faces.
3. Your exposure to risk increases if your organization has one or more factors that increase
_____________ probabilities.
4. ____________________ risk is the amount of risk left over after countermeasures are implemented.
5. SNA starts with the assumption that a system or network will be ________________.
6. By providing _________________ through backup systems, you ensure information remains
accessible if primary systems go offline.
7. ________________ clauses exist in acceptable use policies so that companies can discipline
employees whose computer activities interfere with productivity.
8. Search warrants and subpoenas were developed in response to the _____________ Amendment which
protects U.S. residents against illegal search and seizure.
9. VPNs create a _____________ to transport information through public communications media.
10. The portion of a security policy that describes who responds when there has been a security breach is
called the ______________ response section.
MATCHING
a.
extranet
f.
search warrant
b.
network assets
g.
subpoena
c.
privileged access policy
h.
tunneling protocols
d.
risk management
i.
two-factor authentication
e.
role-based authentication
j.
vulnerabilities
1. a process of analyzing the threats an organization faces
2. a legal document that requires a person to appear in court, provide testimony,
or cooperate with law enforcement
3. situations or conditions that increase threats, which in turn increase risk
4. a method of authentication that grants users limited system
access based on their assigned role in the company
5. authentication that requires more than one form of verification
for a user to be granted access
6. routers, cables, bastion hosts, servers, and firewall components that enable
employees to communicate with one another
7. a legal document issued by a court that allows authorities to search a
particular place for specific evidence
8. a private network that a company sets up as an extension of its corporate
intranet
9. network protocols that encapsulate (wrap) one protocol or session
inside another
10. a document that details additional access options and responsibilities
of users with privileged access to resources
SHORT ANSWER
1. What are the four steps of Threat and Risk Assessment?
2. What are three areas in which the use of encryption should be considered to maintain confidentiality?
3. What are three questions you should ask in deciding how your organization should perform risk
analysis?
4. What should you do if a security policy violation involves a criminal offense? Include the Fourth
Amendment in your discussion.
5. What is the purpose of a privileged access policy?
6. What points should a third-party access policy include? List at least three.
7. Describe a remote access and wireless connection policy and the use of role-based authentication.
Include two-factor authentication in your discussion.
8. What is a server security policy? List at least three areas the policy should address.
9. What are the three levels of escalation of threat or security incidents? Describe them.
10. When should you update the security policy?