Management of Information Security, Fourth Edition 2-8
11. Discuss the risk assessment, or risk analysis, step in the analysis phase. Students should
understand that both are part of risk management, which identifies potential
vulnerabilities.
12. Define risk assessment as involving the association of a risk rating or score to an
15. Describe how an information security policy outlines how information should and will
be protected within an organization.
16. Explain the three different types of security policies that must be defined, according to
the National Institute for Standards and Technology (NIST):
a. General or enterprise InfoSec policy
17. Re-iterate the importance of a SETA program in preventing human error and human
failure related breaches to security.
18. Define the controls and safeguards terms as methods for protecting information against
attacks, and note the three different categories of controls:
a. Managerial controls, which are executed by the security administration of an
organization.
20. Stress the importance of addressing physical security needs, and discuss what can be
considered a physical resource.
21. The implementation phase should be explained as involving the acquisition of security
solutions and products, as well as the implementation and testing of products.
22. Outline the three steps that occur during the execution of the project plan:
23. List some of the different skill sets that might be involved in a development team:
a. Champion
24. Provide a list of the various roles involved in information security: