Acronyms Flashcards

1
Q

CCE

A

Common Configuration Enumeration - Standard for discussing system configuration issues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CVE

A

Common Vulnerabilities and Exposures - Standard for describing security-related software flaws

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CPE

A

Common Platform Enumeration - Standard for describing product names and versions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CVSS

A

Common Vulnerability Scoring System - Standard for measuring and describing the severity of security-related software flaws

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

XCCDF

A

Extensible Configuration Checklist Description Format - Language for specifying checklists and reporting checklist results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

OVAL

A

Open Vulnerability and Assessment Language - Language for specifying low-level testing procedures used by checklist

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SCAP

A

Security Content Automation Protocol - Led by NIST to create a standardized approach for communicating security related content (CVE, CVSS, etc.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

NIST

A

National Institute of Standards and Technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

IDS

A

Intrusion Detection System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

IPS

A

Intrusion Prevention System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

PCI DSS

A

Payment Card Industry Data Security Standard (PCI DSS) - Not a law, maintained by the PCI SSC, funded by the payment card industry to maintain requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

PCI SSC

A

Payment Card Industry Security Standards Council

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ASV

A

Approved Scanning Vendor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

FedRAMP

A

Federal Risk and Authorization Management Program - Fed regulation that establishes a standard approach for assessing, monitoring, and authorizing cloud computing services under the FISMA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

FISMA

A

Federal Information Security Management Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

CIS

A

Center for Internet Security - Publishes security benchmarks that represent the consensus opinions of SME’s. Provides solid foundation for system configuration efforts

16
Q

ISO

A

International Organization for Standardization - Publishes standards related to information security, ISO 27001, ISO 27002 etc.

17
Q

OWASP

A

Open Web Application Security Project - Home to devs and security practitioners, hosts community-developed standards, guides, best practice documents, and industry standard open-source tools

18
Q

ISO 27001

A

Standard for setting up an information security management system

19
Q

ISO 27002

A

More specific than ISO 27001, goes into detail on specific information security controls

20
Q

ITSM

A

IT service management - tool that can be used for tracking vulnerabilities

21
Q

SLA

A

Service-level Agreement - Business agreement that outlines which services and support will be provided to a client

22
Q

MOU

A

Memorandum of Understanding - Agreement between two or more parties that is outlined in formal document, which is not legally binding

23
Q

GLBA

A

Gramm-Leach-Bliley Act - Act that governs how financial institutions handle customer financial records

24
SOX
Sarbanes-Oxley Act - Dictates requirements for storing and retaining documents relating to an organization's financial and business operations
25
FERPA
Family Educational Rights and Privacy Act - Requires that educational institutions implement security and privacy controls for student educational records
26
EIGRP
27
BGP
Border Gateway Protocol