MoIS4 CH04 Solutions
1. What is information security policy? Why it is critical to the success of the InfoSec program?
The Information Security Policy sets the strategic direction, scope, and tone for all of an
2. Of the controls or countermeasures used to control InfoSec risk, which is viewed as the least
expensive? What are the primary costs of this type of control?
Information Security Policies are the least costly to execute. The primary cost is management’s
3. List and describe the three challenges in shaping policy.
An organizations policy should never conflict with the law, it must stand up in court when it is
4. List and describe the three guidelines for sound policy, as stated by Bergeron and
Bérubé.
All policies must contribute to the success of an organization means that a policy should be
5. Describe the bull’s-eye model. What does it say about policy in the InfoSec program?
In the bull’seye model policies are on the outside, because policies should deal with every
6. In what way are policies different from standards?
A standard is a more detailed statement of what must be done in order to be measured as in
7. In what way are policies different from procedures?
Procedures explain how the employee might act to comply with the policy and to be successfully
8. For a policy to have any effect, what must happen after it is approved by management? What
are some ways to accomplish this?
9. Is policy considered static or dynamic? Which factors might determine this status?
A policy could be considered either static or dynamic depending on the context of the policy. A
10. List and describe the three types of InfoSec policy as described by NIST SP 800-14.
The first type of information security policy described by NIST SP 800-14 is enterprise
information security program (EISP). EISP is used to determine the scope, tone and strategic
11. What is the purpose of an EISP?
An Enterprise Information Security Policy is designed to outline the strategic direction and scope
12. What is the purpose of an ISSP?
An Issue Specific Security Policy is designed to provide a detailed and targeted guidelines and
13. What is the purpose of a SysSP?
A System Specific Security Program Policy is designed to specify and detail standards or
14. To what degree should the organization’s values, mission, and objectives be integrated into
the policy documents?
Organizational values, mission, and objectives should be a central part of any policy document.
15. List and describe four elements that should be present in the EISP.
The four elements that should be present in the EISP are:
An overview of the corporate philosophy on security
16. List and describe three functions that the ISSP serves in the organization.
It explains how the organization expects the technology in question is to be used, it documents
17. What should be the first component of an ISSP when it is presented? Why? What should be
the second major component? Why?
The ISSP should begin with a Statement of Purpose which outlines its objectives, who is
18. List and describe three common ways in which ISSP documents are created and/or managed.
Policies can be created to manage a specific issue, such as internet use at work. Policies can be
19. List and describe the two general groups of material included in most SysSP documents.
The two types of materials included in the SystemsSpecific Policy are (1) Management
20. List and describe the three approaches to policy development presented in this chapter. In
your opinion, which is best suited for use by a smaller organization and why? If the target
organization were very much larger, which approach would be more suitable and why?
Three approaches to policy are the Enterprise Information Security Policy, Issue Specific