Acronyms Flashcards
AICPA
American Institute of Certified Public Accountants
COBIT
Control Objectives for Information and Related Technologies
A control framework for governance best practices in an organization
ISO
International Organization for Standardization
SOC
System and Organization Controls
SSAE
Statement on Standards for Attestation Engagements
CVE
Common Vulnerabilities and Exposures
A naming system for describing security vulnerabilities
A Component of SCAP
CVSS
Common Vulnerability Scoring System
Standardized scoring system for describing vulnerabilities
A Component of SCAP
CCE
Common Configuration Enumeration
Naming system for system configuration issues
A Component of SCAP
CPE
Common Platform Enumeration
A naming system for operating systems, applications, and devices
A component of SCAP
SCAP
Security Content Automation Protocol
Components include CVE, CVSS, CCE, CPE, XCCDF, OVAL
CISSP
Certified Information Systems Security Professional
ISMS
Information Security Management System
XCCDF
Extensible Configuration Checklist Format
Provides a language for specifying security checklists
OVAL
Open Vulnerability and Assessment Language
Provides a language for describing security testing procedures
port 20/21
FTP
Port 22
ssh
Port 23
telnet
port 25
SMTP
port 53
DNS