Font size
WorksheetsCyber Policy Quiz 2
Total questions: 20
Worksheet time: 14mins
Rosaline is implementing a solution in Faculty of Engineering which is a 30 million dollar project. She is performing a high level business case and wants to incorporate cyber security principles in the planning. Which 2 principles should she focus on? (select two correct options)
UNSW Information Resources must be designed, deployed, maintained, and decommissioned according to their cyber security risk and any associated control requirements
All access to UNSW Information Resources must be authorised, restricted based on need, and periodical review is not required
Cyber security incidents must be identified, reported, contained, eradicated, and recovered from, in a timely manner
Business continuity and disaster recovery plans must be developed, documented, and enacted when required and may allow acceptable increase in cyber security risk
How many levels of Cyber Security Risk Rating exists for UNSW Information Resources, derived from inherent risk as per the UNSW Cyber Security Risk Framework?
3
4
2
5
Which of the following UNSW Information Resource types delivered by a vendor are covered by the Cyber Security Risk Management Standard?
Endpoints (workstations, laptops, mobiles, IoT and VDI)
Data Services and Storage Services (including PaaS).
Networks and Network Devices (including SDN and Cloud).
Research journals
Classroom whiteboard
Who has UNSW-wide authority to establish mandatory Cyber Security Standards and Guidelines and determine the consultation process (in accordance with the UNSW Policy Framework Policy),
Chief Information Officer
Chief Information Security Officer
Vice- Chancellor
VP, Operations
The Chief Information Security Officer has UNSW-wide accountability and authority for:
assign UNSW-wide management responsibilities for cyber security
the design, implementation, and oversight of UNSW cyber security strategy, plans, programs, capabilities, and controls
supporting UNSW management in identification, assessment, treatment, and reporting of cyber security risks.
ensuring the Cyber Security Policy, Cyber Security Standards and Cyber Security Guidelines conform with the requirements of any relevant International Standard and its defined scope within UNSW.
As per the Cyber Security Policy Deputy Vice-Chancellors, Vice-Presidents, Deans, and the Rector UNSW Canberra are accountable for the:
identification and management of cyber security risk within their area of accountability, including where necessary obtaining guidance and support from the Chief Information Security Officer.
assignment of Business Owners for all UNSW Information Resources within their area of accountability.
annual attestation of compliance to the Cyber Security Risk Management Framework, for High Cyber Security Risk Rated UNSW Information Resources within their area of accountability, in accordance with the Cyber Security Standard – Risk Management, and where necessary obtaining guidance and support from the Chief Information Security Officer.
All of the above
John is a business owner trying to implement an AI tool in the Finance division. What is John responsible for? (multiple correct answers)
ensuring all UNSW Information Resources within their area of responsibility have Cyber Security Risk determined
no need for reporting and escalating identified cyber security risks in accordance with the Cyber Security Standard – Risk Management.
overseeing all access to UNSW Information Resources within their area of responsibility in accordance with the Cyber Security Standard – Identity and Access Management.
ensuring UNSW Information Resources within their area of responsibility are compliant with all applicable cyber security laws and regulations, including those relating to critical infrastructure
Any non-compliance with the Cyber Security Risk Management Framework must be approved in accordance with the Cyber Security Standard – Framework Exemption, including a mandatory (a) and agreed compensating controls
Maria is installing a software which is not compatible with UNSW's vulnerability security scanning tools. The software is critical to maintain business for her division but since it's not compatible, an exemption cannot be granted
True
False
Ashok is the business owner completing the Cyber Security Exemption Form for one his projects. Which of the below sections must be filled mandatory by him?
the Policy or Standard, and clause to which the exemption applies.
business and technical justification for the non-compliance
The place and time of non compliance
data classification, and maximum acceptable outage (for the system, network, or data).
List of team members impacted by the exemption
Cindy has advised that her exemption may take unknown amount of time to be remediated. What is your advise to her?
Unknown time limit is acceptable on case to case basis.
Unknown time limit is acceptable on case to case basis only when she can specify exact actions for the remediations
Advice her that exemption is time limited
Charlie is a system owner for a teaching application in faculty of law. She noticed some of the legal documents have been stolen and published on a publicly available website. She must contact the below teams (select all applicable)
Call the police
UNSW IT Service Centre
UNSW IT Cyber Security Team
UNSW Paralegal team
Who has UNSW wide accountability and authority for the design, implementation, and oversight of UNSW cyber security strategy, plans, programs, capabilities, and controls.
Chief information officer
VP, Operations
Vice-Chancellor
Chief Information Security Officer
Identifying and managing cyber security risks associated with UNSW Information Resources and third-party service providers within their area is a responsibility of
Business Owner
System Owner
Technical Owner
Project Manager
Users of UNSW Information Resources must comply with
a) UNSW policies and procedures.
b) UNSW Cyber Security Standards
Users must not use UNSW Information Resources to
collect, use, or disclose personal information except in accordance with the UNSW Privacy
Policy
Users must take all reasonable steps to protect
UNSW Information Resources from physical or digital theft, damage, or unauthorised use.
Users must not
attempt to gain unauthorised access to UNSW Information Resources
Users must not access, display, store, copy, or transmit prohibited or restricted material on or using UNSW Information Resources EXCEPT for which two conditions?
For research or teaching purposes
Where written approval of a relevant Deputy Vice-Chancellor (for prohibited material) or a Head of School or equivalent (for restricted material) is not required
For the purpose or intention of investigation of a potential breach of a code of conduct, policy, procedure by the Conduct and Integrity Office or Human Resources
Where there is no conflict of interest
Users are permitted limited and incidental personal use of UNSW Information Resources. This use must not unreasonably deny any other user access to any UNSW (a) .
To protect the security of UNSW Digital Information, staff performing University duties using personal devices must ensure that these devices are, (select all that applies)
Are password protected
Are patched or updated at least once in a year
Have malware protection enabled
Devices are encrypted
UNSW at all times reserves the right to monitor, access, examine, take custody of, and retain any UNSW Information Resource.
True
False
Approvals are required for access by a person other than the owner or custodian, to UNSW storage services and storage devices such as mailboxes, Microsoft O365 services, hard drives, and file shares that may also contain personal information.
In a circumstance related to above, when UNSW reasonably suspects that an individual(s) is not complying with legislation or UNSW codes, policies or procedures. Who should be the approver?
Chief Information Officer, or their nominee; AND the relevant responsible officer for the policy.
Chief Human Resources Officer, or their nominee.
Deputy Vice-Chancellor Academic Quality, or their nominee.
