Chapter 3

Security Policies and Standards

CERTIFICATION OBJECTIVES

3.01     Implementing Data Privacy

3.02     Understanding Data Types and Data Governance

3.03     Managing Risk

3.04     Designing Security Policies

QUESTIONS

Security policies provide the framework from which all types of users can learn the proper procedures in using computing devices and accessing data. Policies are often influenced by laws, regulations, and security standards. Management support is crucial to ensure that the security policies are understood and enforced to mitigate risk. User awareness and training provide users with this knowledge, and metrics, such as thorough testing, must be gathered to determine training effectiveness.

1.   Your online retail business ...

Get CompTIA Security+ Certification Practice Exams, Fourth Edition (Exam SY0-601), 4th Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.