1
00:00:06,600 --> 00:00:09,840
- Welcome to Lesson 23: Deep Dive Quiz.

2
00:00:09,840 --> 00:00:11,610
Lesson 23 was about summarizing

3
00:00:11,610 --> 00:00:13,350
effective security governance.

4
00:00:13,350 --> 00:00:16,320
And in 23.1 we talked
about governance structures

5
00:00:16,320 --> 00:00:19,950
and in 23.2 we talked
about governance documents.

6
00:00:19,950 --> 00:00:22,110
So are you ready for a five question quiz?

7
00:00:22,110 --> 00:00:24,930
Pen, paper, pencil, whatever you're using,

8
00:00:24,930 --> 00:00:26,400
be sure you have it handy.

9
00:00:26,400 --> 00:00:29,370
And really, put me on pause
as often as you need to

10
00:00:29,370 --> 00:00:32,073
so that you take the time
to answer these questions.

11
00:00:33,930 --> 00:00:35,403
All right, let's get started.

12
00:00:36,930 --> 00:00:38,850
An action that a prudent person

13
00:00:38,850 --> 00:00:41,130
would have exercised under the same

14
00:00:41,130 --> 00:00:43,170
or similar conditions.

15
00:00:43,170 --> 00:00:44,760
Is this stewardship?

16
00:00:44,760 --> 00:00:46,170
Due diligence?

17
00:00:46,170 --> 00:00:47,430
Fiduciary?

18
00:00:47,430 --> 00:00:49,200
Or due care?

19
00:00:49,200 --> 00:00:51,000
Said that this was a legal construct.

20
00:00:51,000 --> 00:00:53,310
The actions that a prudent person

21
00:00:53,310 --> 00:00:55,050
would have exercised under the same

22
00:00:55,050 --> 00:00:56,970
or similar conditions.

23
00:00:56,970 --> 00:01:01,443
Stewardship, due diligence,
a fiduciary, or due care.

24
00:01:02,850 --> 00:01:03,683
What do you like?

25
00:01:03,683 --> 00:01:06,600
You can put me on pause if
you wanna think about it.

26
00:01:06,600 --> 00:01:07,710
Well, let's go through these.

27
00:01:07,710 --> 00:01:09,810
A stewardship is really the care,

28
00:01:09,810 --> 00:01:12,900
taking care of something
that's been entrusted to you.

29
00:01:12,900 --> 00:01:16,380
Due diligence is the act
of doing an investigation.

30
00:01:16,380 --> 00:01:17,640
We've talked about due diligence

31
00:01:17,640 --> 00:01:19,680
at the beginning of a relationship,

32
00:01:19,680 --> 00:01:21,570
during the lifetime of a relationship,

33
00:01:21,570 --> 00:01:24,483
and definitely if whenever a
contract has to be resigned.

34
00:01:25,800 --> 00:01:29,190
A fiduciary is a legal
responsibility, right?

35
00:01:29,190 --> 00:01:33,240
For whatever you have been entrusted with.

36
00:01:33,240 --> 00:01:37,650
But due care is really the legal standard

37
00:01:37,650 --> 00:01:40,440
that a prudent person would have exercised

38
00:01:40,440 --> 00:01:43,440
under the same or similar condition.

39
00:01:43,440 --> 00:01:44,460
So I'm going with due care.

40
00:01:44,460 --> 00:01:45,690
Do you like it?

41
00:01:45,690 --> 00:01:46,563
Let's check.

42
00:01:47,670 --> 00:01:48,783
And that is correct.

43
00:01:50,550 --> 00:01:54,540
Match the organizational
role and the description.

44
00:01:54,540 --> 00:01:57,360
And we have four roles
down the left-hand side,

45
00:01:57,360 --> 00:02:00,270
a compliance officer, internal audit,

46
00:02:00,270 --> 00:02:02,610
the chief information security officer,

47
00:02:02,610 --> 00:02:04,740
or executive management.

48
00:02:04,740 --> 00:02:06,360
On the right-hand side we have:

49
00:02:06,360 --> 00:02:09,090
independently assesses
the control environment;

50
00:02:09,090 --> 00:02:11,430
identifies applicable
statutory, regulatory,

51
00:02:11,430 --> 00:02:13,800
and contractual requirements;

52
00:02:13,800 --> 00:02:15,960
that the responsibilities
include budgeting,

53
00:02:15,960 --> 00:02:18,870
value delivery, and resource optimization;

54
00:02:18,870 --> 00:02:22,350
or manages the information
security program.

55
00:02:22,350 --> 00:02:24,510
Let's start with that one 'cause
that's the easy one, right?

56
00:02:24,510 --> 00:02:27,120
Manages the information security program.

57
00:02:27,120 --> 00:02:28,860
Is that compliance, internal audit,

58
00:02:28,860 --> 00:02:31,743
a chief security officer,
or executive management?

59
00:02:33,240 --> 00:02:34,980
Yeah, for sure.

60
00:02:34,980 --> 00:02:37,113
Chief information security officer.

61
00:02:39,390 --> 00:02:42,240
if you wanna put me on
pause, don't forget to do so.

62
00:02:42,240 --> 00:02:43,200
All right, let's go.

63
00:02:43,200 --> 00:02:44,190
What do we have next?

64
00:02:44,190 --> 00:02:46,590
Independently assesses
the control environment.

65
00:02:46,590 --> 00:02:48,870
Well, who do we know has to be independent

66
00:02:48,870 --> 00:02:51,030
in our organization?

67
00:02:51,030 --> 00:02:51,863
Audit.

68
00:02:51,863 --> 00:02:53,490
Audit will always be independent.

69
00:02:53,490 --> 00:02:55,080
Even if they're internal audit,

70
00:02:55,080 --> 00:02:57,540
they will still be independent.

71
00:02:57,540 --> 00:03:00,780
They have to follow
specific audit standards.

72
00:03:00,780 --> 00:03:02,910
All right, well now we
have two choices here.

73
00:03:02,910 --> 00:03:05,250
Identifies applicable
statutory, regulatory,

74
00:03:05,250 --> 00:03:08,010
and contractual compliant requirements,

75
00:03:08,010 --> 00:03:11,040
or responsible for
budgeting, value delivery,

76
00:03:11,040 --> 00:03:13,080
and resource optimization.

77
00:03:13,080 --> 00:03:15,720
Well, I think they're
already in the right place.

78
00:03:15,720 --> 00:03:19,140
The compliance officer
identifies applicable statutory,

79
00:03:19,140 --> 00:03:21,510
regulatory, and contractual requirements.

80
00:03:21,510 --> 00:03:23,490
An executive management,
among other things,

81
00:03:23,490 --> 00:03:26,520
is responsible for
budgeting, value delivery,

82
00:03:26,520 --> 00:03:28,293
and resource optimization.

83
00:03:29,190 --> 00:03:30,060
So going through these,

84
00:03:30,060 --> 00:03:32,550
a compliance officer identifies
applicable statutory,

85
00:03:32,550 --> 00:03:34,590
regulatory, and contractual requirements.

86
00:03:34,590 --> 00:03:36,660
Internal audit independently assesses

87
00:03:36,660 --> 00:03:37,920
the control environment.

88
00:03:37,920 --> 00:03:40,020
The chief information security officer

89
00:03:40,020 --> 00:03:42,360
manages the information security program.

90
00:03:42,360 --> 00:03:45,390
And executive management is responsible,

91
00:03:45,390 --> 00:03:48,810
among other things, for
budgeting, value delivery,

92
00:03:48,810 --> 00:03:51,270
and resource optimization.

93
00:03:51,270 --> 00:03:52,110
You agree?

94
00:03:52,110 --> 00:03:53,880
Let's try it.

95
00:03:53,880 --> 00:03:54,933
And that's correct.

96
00:03:55,830 --> 00:03:57,960
All right, question three.

97
00:03:57,960 --> 00:03:59,790
In which type of governance document

98
00:03:59,790 --> 00:04:02,017
would you most likely find a statement,

99
00:04:02,017 --> 00:04:04,530
"password complexity
must include uppercase,

100
00:04:04,530 --> 00:04:07,047
lowercase, and at least one symbol"?

101
00:04:08,040 --> 00:04:09,810
Is that gonna be in a standard,

102
00:04:09,810 --> 00:04:12,480
a guideline, a procedure,

103
00:04:12,480 --> 00:04:13,983
or a baseline?

104
00:04:16,020 --> 00:04:17,970
Password complexity
must include uppercase,

105
00:04:17,970 --> 00:04:19,830
lowercase, and one symbol.

106
00:04:19,830 --> 00:04:22,383
Standard, guideline,
procedure, or baseline?

107
00:04:24,360 --> 00:04:25,680
Well, that sounds a lot to me

108
00:04:25,680 --> 00:04:28,830
like mandatory implementation details.

109
00:04:28,830 --> 00:04:31,410
So I'm gonna choose, it's a standard.

110
00:04:31,410 --> 00:04:35,070
A guideline helps me
either implement a policy

111
00:04:35,070 --> 00:04:37,470
or implement a standard,

112
00:04:37,470 --> 00:04:39,570
but a guideline is not mandatory.

113
00:04:39,570 --> 00:04:41,310
A guideline is really optional.

114
00:04:41,310 --> 00:04:44,640
It's guidance, that's where
the word guideline comes from.

115
00:04:44,640 --> 00:04:47,100
A procedure would be step-by-step.

116
00:04:47,100 --> 00:04:50,010
So if the document told me how to create

117
00:04:50,010 --> 00:04:51,570
that password step-by-step,

118
00:04:51,570 --> 00:04:53,130
I could think of it as a procedure.

119
00:04:53,130 --> 00:04:56,340
And a baseline is when we combine

120
00:04:56,340 --> 00:05:00,930
a number of different standards
for a particular grouping.

121
00:05:00,930 --> 00:05:02,880
And that grouping could be a platform,

122
00:05:02,880 --> 00:05:06,030
it could be a location, it
could be a type of device.

123
00:05:06,030 --> 00:05:07,410
So, I really like standard.

124
00:05:07,410 --> 00:05:08,430
How about you?

125
00:05:08,430 --> 00:05:09,423
Let's check.

126
00:05:10,290 --> 00:05:11,463
And that is correct.

127
00:05:12,330 --> 00:05:14,010
All right, question four.

128
00:05:14,010 --> 00:05:17,220
This agreement should clearly
state handling standards,

129
00:05:17,220 --> 00:05:21,123
explanation of monitoring,
and limitation of privacy.

130
00:05:21,990 --> 00:05:24,060
Is this the acceptable
use policy agreement,

131
00:05:24,060 --> 00:05:27,360
the nondisclosure agreement,
a service level agreement,

132
00:05:27,360 --> 00:05:29,283
or a remote access agreement?

133
00:05:31,410 --> 00:05:32,370
Now, this is the one that I said

134
00:05:32,370 --> 00:05:35,280
I wish didn't have the
word policy in it, right?

135
00:05:35,280 --> 00:05:37,410
But it's going to clearly state

136
00:05:37,410 --> 00:05:40,590
the handling standards,
how we handle information

137
00:05:40,590 --> 00:05:42,810
at different classification levels,

138
00:05:42,810 --> 00:05:45,060
the explanation of how
we might be monitored,

139
00:05:45,060 --> 00:05:46,833
and the limitation of our privacy.

140
00:05:49,680 --> 00:05:50,730
Well, let's start at the bottom.

141
00:05:50,730 --> 00:05:52,410
A remote access agreement, right,

142
00:05:52,410 --> 00:05:55,500
is only going to be
applicable to remote access

143
00:05:55,500 --> 00:05:57,870
and it will go to anyone
who's using remote access,

144
00:05:57,870 --> 00:06:00,150
but it's very specific.

145
00:06:00,150 --> 00:06:01,950
An SLA, a service level agreement,

146
00:06:01,950 --> 00:06:03,750
is an agreement we have with our vendors

147
00:06:03,750 --> 00:06:05,310
about a level of service.

148
00:06:05,310 --> 00:06:06,993
So the expectation of service.

149
00:06:07,860 --> 00:06:10,200
A nondisclosure agreement, that's an NDA,

150
00:06:10,200 --> 00:06:12,390
also called a confidentiality agreement.

151
00:06:12,390 --> 00:06:14,853
We use that to protect data.

152
00:06:15,750 --> 00:06:17,250
The one that we like here,

153
00:06:17,250 --> 00:06:19,740
acceptable use policy agreement, right?

154
00:06:19,740 --> 00:06:22,710
Because the document is called
the acceptable use policy

155
00:06:22,710 --> 00:06:24,090
and the corresponding agreement would be

156
00:06:24,090 --> 00:06:27,150
the acceptable use policy agreement.

157
00:06:27,150 --> 00:06:28,530
Did you get that one?

158
00:06:28,530 --> 00:06:30,090
All right, let's check.

159
00:06:30,090 --> 00:06:31,173
And that's correct.

160
00:06:34,170 --> 00:06:36,540
All right, you wanna
read this one carefully.

161
00:06:36,540 --> 00:06:38,730
The information security strategy

162
00:06:38,730 --> 00:06:41,490
should be endorsed by the:

163
00:06:41,490 --> 00:06:42,810
CEO,

164
00:06:42,810 --> 00:06:44,400
CISO,

165
00:06:44,400 --> 00:06:45,930
Board of Directors,

166
00:06:45,930 --> 00:06:48,963
the Information Security Steering
Committee, or equivalent?

167
00:06:49,920 --> 00:06:52,080
The word endorsed here is important.

168
00:06:52,080 --> 00:06:55,560
There's a difference between
endorsed and authorized.

169
00:06:55,560 --> 00:06:58,290
And you wanna be looking
for these kind of keywords

170
00:06:58,290 --> 00:07:00,480
in your questions in the exam.

171
00:07:00,480 --> 00:07:01,920
So who should endorse it?

172
00:07:01,920 --> 00:07:03,000
The CEO,

173
00:07:03,000 --> 00:07:03,963
the CISO,

174
00:07:04,890 --> 00:07:06,150
the Board of Directors,

175
00:07:06,150 --> 00:07:09,540
or the Information Security
Steering Committee?

176
00:07:09,540 --> 00:07:11,290
Hmm, think about that for a moment.

177
00:07:15,360 --> 00:07:18,180
Well ultimately, it's going
to need to be approved

178
00:07:18,180 --> 00:07:20,010
by the board of directors

179
00:07:20,010 --> 00:07:22,920
and we definitely hope the CISO likes it.

180
00:07:22,920 --> 00:07:25,320
But the endorsement should really come

181
00:07:25,320 --> 00:07:27,870
from the Information
Security Steering Committee.

182
00:07:27,870 --> 00:07:32,870
Why? Because that's going
to be business managers

183
00:07:32,970 --> 00:07:34,920
from across the spectrum.

184
00:07:34,920 --> 00:07:36,870
And once you get their endorsement,

185
00:07:36,870 --> 00:07:38,460
now you've got their buy-in,

186
00:07:38,460 --> 00:07:40,680
now it's gonna go up to
the board of directors

187
00:07:40,680 --> 00:07:42,120
or board of trustees or equivalent

188
00:07:42,120 --> 00:07:44,190
and get authorized.

189
00:07:44,190 --> 00:07:47,010
But it will come to the
table with their endorsement

190
00:07:47,010 --> 00:07:48,030
and their support.

191
00:07:48,030 --> 00:07:50,100
So Information Security
Steering Committee.

192
00:07:50,100 --> 00:07:53,580
And again, the key here
was the word endorsed

193
00:07:53,580 --> 00:07:56,250
versus the word authorized.

194
00:07:56,250 --> 00:07:57,083
You agree?

195
00:07:57,083 --> 00:07:58,470
Let's check.

196
00:07:58,470 --> 00:08:00,180
And we are correct.

197
00:08:00,180 --> 00:08:01,530
Great job.

198
00:08:01,530 --> 00:08:04,350
All right, we're gonna
keep moving on lesson 24.

199
00:08:04,350 --> 00:08:05,520
We're gonna explain the elements

200
00:08:05,520 --> 00:08:07,320
of the risk management process.

201
00:08:07,320 --> 00:08:08,153
See you there.
