Description should include measures such as, but not limited to,
- employee policies (e.g., acceptable use policies [AUPs])
- physical security controls
- legal/oversight requirements
- incident (i.e., breach) response procedures.
Description should also include the concept that prevention and protections against cyberattacks change as the targets, vulnerabilities, and threats change.
Process/Skill Questions:
- What is an example of a cybersecurity breach?
- How do employee policies relate to the prevention of cybersecurity breaches?