Chapter 04 – Information Security Policy
TRUE/FALSE
1. Policies must specify penalties for unacceptable behavior and define an appeals process.
2. One of the goals of an issue-specific security policy is to indemnify the organization against liability
for an employee’s inappropriate or illegal use of the system.
3. Users have the right to use an organization’s information systems to browse the Web, even if this right
is not specified in the ISSP.
4. Rule-based policies are less specific to the operation of a system than access control lists.
5. Since most policies are drafted by a single person and then reviewed by a higher-level manager,
employee input should not be considered since it makes the process too complex.
MULTIPLE CHOICE
1. Which of the following is NOT one of the basic rules that must be followed when shaping a policy?
a.
policy should never conflict with law
c.
policy should be agreed upon by all
employees and management
b.
policy must be able to stand up in court if
challenged
d.
policy must be properly supported and
administered
2. Which of the following is a policy implementation model that addresses issues by moving from the
general to the specific and is a proven mechanism for prioritizing complex changes?
a.
On-target model
c.
Bull’s-eye model
b.
Wood’s model
d.
Bergeron and Berube model
3. Which of the following is NOT among the three types of InfoSec policies based on NIST’s Special
Publication 800-14?
a.
Enterprise information security policy
b.
User-specific security policies
c.
Issue-specific security policies
d.
System-specific security policies
4. In addition to specifying the penalties for unacceptable behavior, what else must a policy specify?
a.
appeals process
c.
what must be done to comply
b.
legal recourse
d.
the proper operation of equipment
5. Which policy is the highest level of policy and is usually created first?
a.
SysSP
c.
ISSP
b.
USSP
d.
EISP
6. Which type of document is a more detailed statement of what must be done to comply with a policy?
a.
procedure
c.
guideline
b.
standard
d.
practice
7. Which of the following is an element of the enterprise information security policy?
a.
statement of purpose
b.
information on the structure of the InfoSec organization
c.
articulates the organization’s expectations
d.
indemnifies the organization against liability
8. Which type of security policy is intended to provide a common understanding of the purposes for
which an employee can and cannot use a resource?
a.
issue-specific
c.
system-specific
b.
enterprise information
d.
user-specific
9. Which section of an ISSP should outline a specific methodology for the review and modification of the
ISSP?
a.
Policy Review and Modification
b.
Limitations of Liability
c.
Systems Management
d.
Statement of Purpose
10. Which of the following sections of the ISSP should provide instructions on how to report observed or
suspected policy infractions?
a.
Violations of Policy
b.
Systems Management
c.
Prohibited Usage of Equipment
d.
Authorized Access and Usage of Equipment
11. Which of the following is a disadvantage of the individual policy organization approach?
a.
can suffer from poor policy enforcement
b.
may skip vulnerabilities
c.
may be more expensive
d.
implementation can be difficult to manage
12. Which of the following are the two general groups into which SysSPs can be separated?
a.
technical specifications and managerial
guidance
c.
user specifications and managerial
guidance
b.
business guidance and network guidance
d.
technical specifications and business
guidance
13. What are the two general methods for implementing technical controls?
a.
profile lists and configuration filters
b.
firewall rules and access filters
c.
user profiles and filters
d.
access control lists and configuration rules
14. Which of the following is NOT an aspect of access regulated by ACLs?
a.
what authorized users can access
c.
how authorized users can access the
system
b.
why authorized users need access to the
system
d.
when authorized users can access the
system
15. Which of the following are instructional codes that guide the execution of the system when
information is passing through it?
a.
access control lists
c.
configuration rules
b.
user profiles
d.
capability tables
16. A detailed outline of the scope of the policy development project is created during which phase of the
SecSDLC?
a.
design
c.
implementation
b.
analysis
d.
investigation
17. In which phase of the SecSDLC must the team create a plan to distribute and verify the distribution of
the policies?
a.
design
c.
investigation
b.
implementation
d.
analysis
18. A risk assessment is performed during which phase of the SecSDLC?
a.
implementation
c.
design
b.
analysis
d.
investigation
19. Which individual is responsible for the creation, revision, distribution, and storage of the policy?
a.
policy developer
c.
policy enforcer
b.
policy reviewer
d.
policy administrator
20. When an organization demonstrates that it is continuously attempting to meet the requirements of the
market in which it operates, what is it ensuring?
a.
policy administration
c.
adequate security measures
b.
due diligence
d.
certification and accreditation
COMPLETION
1. In the bull’s-eye model, the ____________________ layer is the place where threats from public
networks meet the organization’s networking infrastructure.
2. The three types of information security policies include the enterprise information security policy, the
issue-specific security policy, and the ____________________ security policy.
3. The responsibilities of both the users and the systems administrators with regard to specific technology
rules should be specified in the ____________________ section of the ISSP.
4. ____________________ include the user access lists, matrices, and capability tables that govern the
rights and privileges of users.
5. A(n) ____________________, which is usually presented on a screen to the user during software
installation, spells out fair and responsible use of the software being installed.
6. The champion and manager of the information security policy is called the ____________________.
MATCHING
a.
capability table
f.
InfoSec policy
b.
statement of purpose
g.
standard
c.
Bull’s eye model
h.
EISP
d.
SysSP
i.
Systems Management
e.
procedures
j.
ISSP
1. methods or processes, usually detailed, put in place by an organization in order to accomplish its
objectives
2. a detailed statement of what employees of an organization must do to comply with a policy
3. information security issues are addressed from the general to the specific
4. a program that addresses specific areas of technology and contains a statement on the organization’s
position on each
5. the set of organizational guidelines that describe acceptable and unacceptable behaviors of employees
in the workplace
6. a policy document that establishes the strategic direction, scope, and tone for all of an organization’s
security efforts
7. answers the question “who is responsible and accountable for policy implementation?”
8. should specify users’ and systems administrators’ responsibilities
9. specifies which subjects and objects that users or groups can access
10. could include a statement of managerial intent and an access control
list
SHORT ANSWER
1. List the significant guidelines used in the formulation of effective information security policy.
2. List the advantages and disadvantages of using a modular approach for creating and managing the
ISSP.
3. List the major components of the ISSP.
4. How should a policy administrator facilitate policy reviews?
5. What is the final component of the design and implementation of effective policies? Describe this
component.
6. In which phase of the development of an InfoSec policy must a plan to distribute the policies be
developed? Why is this important?
7. What are configuration rules? Provide examples.
8. What is a SysSP and what is one likely to include?
9. What should an effective ISSP accomplish?
10. What are the four elements that an EISP document should include?