2.3 - Relate how national bodies such as NCSC, GCHQ, NIST and FIPS provide guidance and information to public and private sector organisations Flashcards

1
Q

What is Federal Information Processing Standard 140-2?

A

It is the benchmark for validating the effectiveness of cryptographic hardware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who issued FIPS 140-2?

A

National Institute of Standards and Technology (NIST)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How many FIPS security levels are there?

A

4

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is FIPS Level 1?

A

Level 1: Provides the lowest level of security. Basic security requirements are at least one Approved algorithm or Approved security function and production-grade component are required.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is FIPS Level 2?

A

Level 2: Adds requirements for physical tamper-evidence and role-based authentication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is FIPS Level 3?

A

Level 3: Adds requirements for physical tamper-resistance and identity-based authentication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is FIPS Level 4?

A

Level 4: Makes the physical security requirements more stringent, requiring the ability to be tamper-active.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a security policy?

A

A security policy is a formal statement of the rules by which employees who use technology within the company.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is NIST SP 500?

A

Computer Systems Technology - includes conference and meeting proceedings; best practice recommendations; and reports on test methods, specifications, and data formats from the Information Technology Laboratory (ITL)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is NIST SP 800?

A

Computer Security Series - Publications in the SP800 series present information of interest to the computer security community

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is NIST SP 1800?

A

NIST Cybersecurity Practice Guides - target specific cybersecurity challenges in the public and private sectors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is NIAP?

A

National Information Assurance Partnership - US CC Certifies protection profiles, approves test labs, evaluate security targets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are Certificate consuming members?

A

They recognise CC certifications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the CCRA

A

Common Criteria Recognition Arrangement - Defines the list of members that test CC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is FIPs used?

A

In computer systems by non-military American government agencies and government contractors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is FIPS 197?

A

Standard for ADVANCED ENCRYPTION STANDARD (AES)

17
Q

What is FIPS 46-3?

A

Data Encryption Standard (DES)

18
Q

What is FIPS 140?

A

Security requirements for cryptography modules

19
Q

What is FIPS 137?

A

Federal Standard for Linear Predictive Coding

20
Q

What is FIPS 199?

A

Standards for Security Categorization of Federal Information and Information Systems

21
Q

What is FIPS FIPS 201?

A

Personal Identity Verification for Federal Employees and Contractors

22
Q

What is FISMA?

A

Federal Information Security Modernization Act of 2014

23
Q

What does Federal Information Security Modernization Act of 2014 emphasize?

A

risk-based policy for cost-effective security.

24
Q

What does FISMA require executive agencies within the federal government to do?

A
  • Plan for security
  • Ensure that appropriate officials are assigned security responsibility
  • Periodically review the security controls in their systems
  • Authorize system processing prior to operations and, periodically, thereafter