click below
click below
Normal Size Small Size show me how
review questions
| Question | Answer |
|---|---|
| Why choose ASD Essential Eight? | Simple, practical, protects against common attacks |
| How does ASD work with NIST/ISO? | They both cover technical security/management |
| What does the Privacy Act 1988 require? | Protect sensitive data and report breaches |
| Name 3 security controls | MFA, patching, backups |
| What is a policy? | What must be done |
| What is a standard? | Strict rule |
| What is a procedure? | Steps to follow |
| What is a guideline? | Recommended advice |
| Example of access control policy? | Users only access what they need + MFA |
| 3 IoT security rules | Change passwords, update, isolate network |
| Why is infrastructure planning important? | Improves communication and organisation |
| Incident response steps? | Prep (have plans) Detection (identify incident using logs/alerts) Analysis (understand what happened) Containment (stop it spreading) Eradication (remove threat) Recovery (restore systems/data) Review (learn/improve) |
| What to do in ransomware? | Isolate, disconnect, restore backup |
| Response to phishing | Report, reset passwords, scan system, warn other staff |
| Response to a DDos attack (too much traffic crashing system) | Block IPs, enable filtering |
| Who do you report incidents to? (Jurisdictional arrangements) | ACSC, OAIC, police |
| What does the IT Security Policy do? | Protects data, controls access, handles incidents |
| How do you implement a policy in a company? | Train staff, apply controls, monitor |
| How do you make sure staff follows the policy | Monitoring and enforcing rules |
| How do you keep policy updated? | Review regularly, update for new threats |
| How does a policy minimise damage? | By using MFA, backups, fast recovery |