Chapter 11 – Legal and Compliance Part II Flashcards
What are KRIs (Key Risk Indicators)?
Metrics used by an organization to inform management of impending negative impacts to operations; involves algorithms and rating systems ascribed to factors selected by analysts and management for an early-warning system.
What are KPIs (Key Performance Indicators)?
Backward-looking metrics to gauge business critical initiatives, objectives, or goals; measurable benchmarks against defined goals.
What is Risk Appetite/Tolerance?
How the organization views risks; senior management dictates the amount of risk an organization is willing to take.
What are Risk Profiles?
Comprehensive analysis of the possible risks to the organization; includes a survey of various operations the organization is engaged in, public perception, pending legislation, and stability of countries where the organization operates.
What are Physical Controls?
Physical access to assets that reduces the impact of a physical event; examples include locks, fire suppression, fences, and guards.
What are Technical Controls?
Also known as logical controls; controls that enhance the CIA triad; examples include encryption, ACLs, audit trails, and logs.
What are Administrative Controls?
Processes and activities that provide aspects of security; examples include background checks, scheduled log reviews, mandatory vacations, and robust security policies.
What is the Risk Management Framework (RMF)?
A structured approach to managing risk, including standards like ISO 31000:2018 and NIST SP 800-37.
What is ISO 31000:2018?
An international standard focusing on designing, implementing, and reviewing risk management processes and practices.
What is NIST SP 800-37?
A methodology for handling all organizational risk in a holistic, comprehensive, and continual manner; relies on automated solutions.
What is ENISA?
The EU Agency for Network and Information Security; responsible for producing guidelines on cloud computing security risks.
What is COBIT?
A framework for developing, implementing, monitoring, and improving IT governance and management practices.
What is ISO/IEC 31010:2009?
A standard for risk management techniques.
What are Risk Management Metrics?
A scale used to evaluate risk levels: 5 – Critical; 4 – High; 3 – Moderate; 2 – Low; 1 – Minimal.
What is ISO/IEC 15408-1:2009?
Common Criteria Assurance Framework providing assurances for security claims by vendors.
What is ISO 28000:2007?
A standard that applies to security controls in supply chains.
What is CSA STAR?
A framework for evaluating cloud providers; registry of security controls designed for vendor management.
What is CCM (Cloud Controls Matrix)?
A list of security controls and principles appropriate for cloud environments, cross-referenced to other control frameworks.
What is CAIQ (Consensus Assessments Initiative Questionnaire)?
A self-assessment by cloud providers detailing evaluation of practice areas and control groups.
What are the levels of the CSA STAR Program?
Level One: Self-Assessment; Level Two: CSA STAR Attestation; Level Three: CSA STAR Continuous Monitoring.
What is PKI?
A framework of programs, procedures, communication protocols, and public key cryptography that enables secure communication.
What is OWASP?
An international nonprofit that focuses on identifying software vulnerabilities and educating developers in secure coding practices.
What are some common software vulnerabilities identified by OWASP?
Broken Access Control; Cryptographic Failures; Injection; Insecure Design; Security Misconfiguration; Vulnerable and Outdated Components; Identification and Authentication Failures; Software and Data Integrity Failures; Security Logging and Monitoring Failures; Server-Side Request Forgery (SSRF).