Chap 1 Flashcards

1
Q

NIST 5 Functions

A

National Institute of Standards and Technology-
Identify, Protect, Detect, Respond, and Recover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Gap Analysis

A

a process that identifies how an organization’s security systems deviate from those required or recommended by a framework.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

IAM

A

Identity and Access Management- Controls who has access to resources and what they can do with them. IAM includes Identification, Authentication, Authorization, and Accounting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Accounting

A

the system must record the actions a customer takes (to ensure that they cannot deny placing an order, for instance).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Managerial Control

A

provide oversight and management of the information system. Examples include:

Risk identification
Tools for evaluating and selecting other security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Operational Control

A

carried out by people. Examples include:

Security guards
Training programs for employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Technical Control

A

These are implemented using technology such as hardware, software, or firmware. Examples include:

Firewalls
Antivirus software
Operating system access control models

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Physical Control

A

These deter and detect unauthorized physical access. Examples include:

Security cameras
Alarms
Locks
Lighting
Security guards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

ISSO

A

Information Systems Security Officer-
Organizational role with technical responsibilities for implementation of security policies, frameworks, and controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

SOC

A

Security Operations Center-
The location where security professionals monitor and protect critical information assets in an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

DevOps

A

Development and Operations-
a set of practices that combines software development (Dev) and IT operations (Ops) to shorten the development lifecycle and deliver high-quality software continuously

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

DevSecOps

A

security expertise must be embedded into any development project regarding software development and operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

CIRT

A

Computer Incident Response Team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CSIRT

A

Computer Security Incident Response Team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

CERT

A

computer emergency response team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly