Acronyms Flashcards

1
Q

ASLR

A

Address Space Layout Randomization
Memory protection for operating systems
Guards against buffer overflow attacks
Randomized place system executables are loaded into memory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ARO

A

Annualized Rate of Occurrence

How likely a particular issue/disaster is to happen

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SLE

A

Single Loss Expectancy

Cost for one single event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ALE

A

Annual Loss Expectancy
How much it will cost in a year
Calculated by multiplying ARO and SLE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ATT&CK

A

Adversarial Tactics, Techniques, and Common Knowledge
MITRE ATT&CK framework
Information about attacks and how to prevent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

AUP

A

Acceptable Use Policy
Documentation for how all company assets are to be used
Allows for employer to note how things should be used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

BIA

A

Business Impact Analysis

What of the business will be impacted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

RTO

A

Recovery Time Objective
How much time it will take to get back to a certain point
Used in conjunction with RPO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

RPO

A

Recovery point objective
What point is acceptable to recover to
In relation to data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

MTTR

A

Mean time to repair

How log is it going to take to fix an issue

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

MTBF

A

Mean time between failures

Predict time between outages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

DRP

A

Disaster Recovery Plan

Detailed plan for resuming operations after an incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

EDM

A

Exact data match

Used to match format of data (I.E. matching format of ssns)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Cain and Abel

A

Password cracking tool, includes network packet sniffing, brute force cracking, dictionary attacks, cryptoanalysis, and Cisco VPN Client Password Decoding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SLA

A

service level agreement- detailes terms under which the service is provided

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

NAC

A

Network access control- endpoint security technology (anti-virus, HIPS, vulnerability assessments, user/system authentication, network security enforcement). Segments new remote workstations and scans them for malware and vulnerabilities then allows them to connect if it passes

17
Q

CCM

A

Cloud Control Matrix
From CSA
Applies to security controls in the cloud

18
Q

SPF

A

EMail authentication to detect forging sender addresses during email delivery

19
Q

DSUA

A

Specifies data can only be collected for a specific reason

20
Q

ISA

A

Used by Federal agencies interconnecting IT systems to 3rd party
Used to govern the relationlship

21
Q

27001

A

Standards for information security

22
Q

27002

A

Steps for implementation of information security controls

Code of practice

23
Q

27701

A

Privacy management

PIMS

24
Q

31000

A

Standards for risk management

25
Q

SOC Type I/II

A

Auditing of security controls
I - point in time
II - over at least 6 months

26
Q

Data owner

A

Responsible for the data

27
Q

Data controller

A

Manages purpose and means that the data is used

28
Q

Data processor

A

Processes data on behalf of controller

Typically 3rd party

29
Q

Data custodian/steward

A

Implements security controls
Tags data
Ensures compliance with laws

30
Q

Data protection officer (DPO)

A

Responsible for orgs data privacy

Sets policies, implements