Cyberstudy
PDF p.370 In progress Not in the PDF's table of contents

Common Organizational Policies

Open PDF at p.370 4 flashcards

Summary

PDF p.370

Common organizational policies include Acceptable Use Policy (AUP), Information Security Policies, Business Continuity & Continuity of Operations Plans (COOP), Disaster Recovery, Incident Response, Software Development Life Cycle (SDLC), and Change Management. These policies ensure the organization operates efficiently and securely.

In plain words

Supplementary — not from your PDF

Common policies include the Acceptable Use Policy (AUP), information security policies, business continuity and COOP, disaster recovery, incident response, the software development lifecycle (SDLC), and change management. Each governs a specific area of secure, efficient operation.

Detailed explanation

PDF p.370
  • Acceptable Use Policy (AUP)
    • Purpose: Define acceptable behavior for network and computer system use.
    • Details: Browsing behavior, appropriate content, software downloads, handling sensitive information, and consequences for noncompliance.
  • Information Security Policies
    • Purpose: Ensure compliance with rules and guidelines related to information security.
    • Details: Security of information within the organization's environment.
  • Business Continuity & COOP
    • Purpose: Focus on critical processes during and after substantial disruptions.
    • Details: Natural disasters, cyber-attacks, and maintaining operational continuity.
  • Disaster Recovery
    • Purpose: Recover from catastrophic events.
    • Details: Steps to restore operations quickly and efficiently.
  • Incident Response
    • Purpose: Outline processes after a security breach or cyberattack.
    • Details: Identifying, investigating, controlling, and mitigating incidents, and communication procedures.
  • Software Development Life Cycle (SDLC)
    • Purpose: Govern software development within the organization.
    • Details: Structured plan from requirement analysis to maintenance, ensuring efficiency, reliability, and security.
  • Change Management
    • Purpose: Outline how changes to IT systems and software are managed.
    • Details: Request, review, approval, implementation, and documentation requirements.

Important terms

taken from the text above
AUP Acceptable Use Policy COOP Continuity of Operations Plans SDLC Software Development Life Cycle

Examples & real-world scenarios

Supplementary — not from your PDF
  • An AUP telling staff what they may and may not do on company systems.
  • An incident response policy defining who does what after a breach.
  • A change management policy requiring approval before system changes.

Scenario

An employee uses a work laptop to download pirated software and infects it. A signed AUP with clear consequences gives HR the basis to act and reminds staff of the rules.

Common mistakes

Supplementary — not from your PDF
  • Not having an AUP, so there's no agreed standard of acceptable behaviour.
  • Mixing up business continuity (keep running) and disaster recovery (restore after).

Practical skills

Supplementary — not from your PDF
  • Match a scenario to the policy that governs it.

What I should remember

Key Points PDF p.370
  • Acceptable Use Policy (AUP)
    • Purpose: Define acceptable behavior.
    • Details: Browsing, content, downloads, sensitive information, and consequences.
  • Information Security Policies
    • Purpose: Ensure information security compliance.
    • Details: Security within the organization's environment.
  • Business Continuity & COOP
    • Purpose: Maintain critical processes during disruptions.
    • Details: Natural disasters, cyber-attacks.
  • Disaster Recovery
    • Purpose: Recover from catastrophic events.
    • Details: Restore operations quickly.
  • Incident Response
    • Purpose: Processes after security breaches.
    • Details: Identify, investigate, control, mitigate, and communicate.
  • Software Development Life Cycle (SDLC)
    • Purpose: Govern software development.
    • Details: Structured plan from analysis to maintenance.
  • Change Management
    • Purpose: Manage changes to IT systems.
    • Details: Request, review, approval, implementation, documentation.