Strategic Planning
Governance
Policy
100

The process of defining and specifying long term directions to be taken by an organization.

What is strategic planning?

100

The three components of information security.

What is governance, risk management, and compliance?

100

An employee responsible for the creation, revision, distribution, and storage of a policy in an Organization  

What is a Policy Administrator

200

A plan for the organization's intended strategic efforts over the next several years.

What is a strategic plan?

200

The 3 core principles of this term are confidentiality, integrity, and availability.

What is governance?

200

what is Written instructions provided by that inform employees and others in the workplace about proper behavior regarding the use of information and information assets.

What is information security policy?

300

A plan for the organization’s intended tactical efforts over the next few years.

What is a tactical plan?

300

Executive management’s responsibility to provide strategic direction, ensure the accomplishment of objectives, oversee that risks are appropriately managed, and validate responsible resource use.

What is corporate governance?

300

what is The high-level information security policy that sets the strategic direction, scope, and tone for all of an organization’s security efforts; also known as a security program policy, general security policy, IT security policy, high level InfoSec policy, or simply an InfoSec policy.

 What is enterprise information security policy (EISP)?

400

A plan for the organizations intended operational efforts on a day to day basis for the next several months.

What are operational plans?

400

The application of principles and practices of corporate governance to the information security function.

What is information security governance?

400

An organizational policy that provides detailed, targeted guidance to instruct all members of the organization in the use of a resource, such as one of its processes or technologies.

What is an issue specific security policy?

500

A term often used synonymously with goals, the intermediate states obtained to achieve progress toward a goal or goals.

What is an objective?

500

The leadership, policies, and processes that directs an organization’s security activities to meet business goals, manage risks, and ensure regulatory compliance.

What is strategic framework of information security governance?

500

Organizational policies that often function as standards or procedures to be used when configuring or maintaining systems. Can be separated into two groups, managerial guidance and technical specifications.

What are systems-specific security policies?

M
e
n
u