Security Policies, Standards, and Frameworks
Organizations rely on policies and standards to guide security practices. Examples include ISO/IEC 27001 (an international information security management standard) and the NIST Cybersecurity Framework. A security policy defines roles and responsibilities (for example, an Acceptable Use Policy or Incident Response Policy). Auditors check that organizations follow these standards. For instance, a Philippine company might align with ISO 27001 and the National Privacy Commission's policies to ensure comprehensive coverage of security and privacy requirements.
Risk Management and Assessment
Risk management involves identifying, analyzing, and mitigating risks. Techniques include qualitative analysis (using risk matrices to rate impact and likelihood) and quantitative analysis (calculating expected losses). A key formula is Single Loss Expectancy (SLE) = Asset Value × Exposure Factor and Annual Loss Expectancy (ALE) = SLE × Annualized Rate of Occurrence (ARO). Controls (like firewalls or encryption) reduce risk by lowering either the likelihood or the impact. A key step is performing risk assessments: listing assets, threats, vulnerabilities, and determining the level of risk. Exams often ask you to perform or interpret simple risk calculations using these formulas.
Legal and Regulatory Compliance
ProReviewer — locked
Drills, code labs, and full solutions.
Asset Classification and Data Protection
ProReviewer — locked
Drills, code labs, and full solutions.
Practice & Exam Drills — Lesson 7
ProReviewer — locked
Drills, code labs, and full solutions.