5. Program Management Flashcards

1
Q

5.1 AUP

A

Acceptable Use Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

5.1 SDLC

A

Software Development Lifecycle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

5.1 Data Owner

A

responsible for classification, protection, and quality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

5.1 Data Steward

A

Subject matter expert for data, including its meaning and correct usage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

5.1 Data Custodian

A

responsible for the technical environment, including database structure. Implement security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

5.1 Data Subject

A

Person whose data is being processed or stored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

5.2 Risk Assessment Types

A

Ad hoc (RA completed for a specific situation or application)

Recurring

One-Time

Continuous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

5.2 SLE

A

Single Loss Expectancy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

5.2 ALE

A

Annualized Loss Expectancy (How much will a threat cost you over a year?)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

5.2 ARO

A

Annualized Rate of Occurrence (projected number of times an incident will happen in a year)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

5.2 Risk Register

A

Document used to identify and track risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

5.2 Risk Register Components

A

Risk Indicators: measureable variables that determine likelihood of a risk

Risk Owners: Person responsible for mitigating a certain risk

Risk Threshold: area determined by which risks are acceptable and which are addressed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

5.2 Risk Appetite (and kinds of appetite)

A

How much risk is an organization willing to accept to achieve its goals.

Expansion: Organization wants to expand, thus increasing the attack surface area

Conservative: Organization is focused on mitigating all risks and conserving capital rather than taking business risks

Neutral: Balanced approach. Organization only accepts risks that are essential to a predetermined strategic goal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

5.2 Components of Business Impact Analysis

A

RTO
RPO
MTTR
MTBF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

5.2 RTO

A

Recovery Time Objective

acceptable amount of time for a service to be unavailable before too much damage is done

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

5.2 RPO

A

Recovery Point Objective

maximum amount of data loss that an organization can tolerate

17
Q

5.2 MTTR and MTBF

A

Mean Time to Repair

Mean Time Between Failures

18
Q

5.3 SLA

A

Service Level Agreemenet

Defines what services to be provided and expected performance

19
Q

5.3 MOA

A

Memorandum of Agreement

outlines terms and details of an agreement between parties

20
Q

5.3 MOU

A

Memorandum of Understanding

Less formal version of MOA that may not have legal implications. Used to express mutual agreement between parties.

21
Q

5.3 MSA

A

Master Service Agreement

determines terms and conditions that govern future transactions and agreements. Framework for the entire relationship, long-term document

22
Q

5.3 SOW or WO

A

Statement of Work Order. Outlines work to be performed for a specific project.

23
Q

5.3 BPA

A

Business Process Agreement, focuses on overall client experience and satisfaction

24
Q

5.3 Security Attestation

A

Document that declares the existence of something, such as compliance or proof of secure status

25
Q

5.4 Consequences of non-compliance

A

fines
sanctions
reputation damage
loss of license
contractual impacts

26
Q
A