TechKnowSurge
ISC2 CC 1.3 NIST CSF GV.PO-01 NIST CSF GV.OC-03 CompTIA Security+ 5.1 ISC2 CC 2.3 CompTIA Security+ 5.4 NIST 800-53 PM-1 NIST CSF PR.AT-01
InteractiveSecurityFree

Audit the Security Program

Audit TechKnowDJ's draft security program and flag what should not pass.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Administrative controls are the paper side of security: the documentation, policies, standards, procedures and guidelines that say what the organization does; the framework it builds them from; the policies and agreements that bind employees, customers, vendors and partners; the awareness program that makes people know and follow them; and the laws and regulations the whole program has to meet. This audit draws on the whole module. A process that lives in one person's head. A procedure that is not a set of steps, and a requirement filed as a guideline. A framework used word for word. A payment standard treated as optional because it is not a law. Policies missing for the people who need them. A rule posted but never announced. Training completion mistaken for awareness. A sector-specific law ignored. Some lines look odd and are exactly right: a guideline that leaves a judgment call to the team, an MSA signed years ago and still in force, an MOU signed before the contract, phishing tests that pretend to come from HR, and GDPR applying to a U.S. company with customers in Europe.

What you'll learn

Aligned to

ISC2 CC
1.3 Understand governance concepts
2.3 Understand security awareness
NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.
CompTIA Security+
5.1 Summarize elements of effective security governance.
5.4 Summarize elements of effective security compliance.
NIST 800-53
PM-1 Information Security Program Plan

Key terms

Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Standard
A mandatory, specific requirement derived from a policy that defines how the policy is to be implemented.
Procedure
A detailed, step-by-step set of instructions for carrying out a specific task in alignment with policies and standards.
Guideline
A recommended, non-mandatory suggestion that provides flexible guidance for implementing policies and standards.
Acceptable Use Policy
AUP
A documented policy that defines the rules and expectations for how employees and internal users may use organizational systems and resources. An AUP establishes the grounds for disciplinary or legal action if violated.
Privacy Policy
A document that discloses how an organization collects, uses, and manages the data of visitors, customers, and other external parties.
Security Awareness
The ongoing effort to ensure employees understand security policies, recognize threats, and apply safe behaviors through multiple communication methods beyond formal training alone.
Payment Card Industry Data Security Standard
PCI DSS
A set of security requirements mandated by major credit card brands that organizations must follow to process, store, or transmit cardholder data. PCI DSS covers controls such as encryption, access restriction, and regular security testing.
Compliance
The act of adhering to the laws, regulations, standards, and internal policies that govern how an organization handles data and security. Compliance programs use audits and controls to demonstrate that requirements are being met.

Topics

Security Policy Standard Procedure Guideline Acceptable Use Policy Security Awareness Compliance Interactive Spot The Error

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →