- [Instructor] In addition to conducting regular…security audits and assessments,…organizations should perform routine management…of their own controls.…Every security program should include…control testing procedures,…a process for managing exceptions to controls,…the building of control remediation plans,…and the use of compensating controls.…Control testing should take place on a regular basis.…While periodic audits and assessments do evaluate…the effectiveness of security controls,…these usually occur infrequently.…
Organizations should supplement these more formal tests…with routine and automated monitoring of security controls.…For example, an automated review process might routinely…check to see if new ports are opened…on a firewall in an unexpected manner.…You'll also find that there is an exception…to every rule in the world of security.…You should have a defined process in place…to help team members understand how they may request…and exception to a security control…and who has the authority to approve such a request.…
Want more CySA+ test prep tips? Visit certmike.com to join Mike's free study group.
We are a CompTIA Content Publishing Partner. As such, we are able to offer CompTIA exam vouchers at a 10% discount. For more information on how to obtain this discount, please download these PDF instructions.
- Security governance
- Security roles and responsibilities
- Security policies
- Complying with laws and regulations
- Auditing and assessing security
- Personnel security
- Security training
- Vendor management
Skill Level Intermediate
Insights from a Cybersecurity Professionalwith Mike Chapple32m 15s Intermediate
Implementing an Information Security Programwith Kip Boyle2h 33m Intermediate
1. Security Governance
2. Security Policy
3. Regulatory Compliance
4. Assessing Security Processes
5. Personnel Security
6. Awareness and Training
7. Vendor Management
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.Cancel
Take notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.