Chapter 11 - Security Administration Flashcards

1
Q

What is a SLA?

A

page 398
Service Level Agreement
Defines the level of service to be provided.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is BPO?

A

page 398
Blanket Purchase Order
An Agreement between a government agency and a private company for ongoing purchases of goods or services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is MOU?

A

page 398
Memorandum of Understanding
Brief summary of which party is responsibility for what portion of the work.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is ISA?

A

page 398

Interconnection Security Agreement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What kind of training involves everyone understanding policies, procedures and resources available to deal with security problems?

A

page 399

Organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Ideally what security awareness should Organization training cover?

A

page 400

  • Importance of security
  • Responsibilities of people in the organization
  • Policies and procedures
  • Usage policies
  • Account and password-selection criteria
  • Social engineering prevention
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who receives additional training or exposure that explains the issues, threats and methods of dealing with threats and will want want to know the hows and whys of security training?

A

page 400

Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Who receives special knowledge training about methods. implementation and capabilities of the systems used to manage security?

A

page 400

Technical Staff

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are some of the topics relate to the safety of the data or physical environment?

A

page 401

  • Fencing - CCTV
  • Lighting - Escape Plans
  • Locks - Drills
  • Escape Routes - Testing Controls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why is it important to have a clean desk policy?

A

page 402

Information on the desk can easily be seen by prying eyes and taken by thieving hands.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is P2P?

A

page404

Peer-to-peer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is PII?

A

page 404
Personally Identifiable Information
Is a catchall for any data that can be used to uniquely identify an individual.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How does NIST define PII?

A

page 404
Any information about an individual maintained by an agency, including
1. Any information that can be used to distinguish or trace an individual’s identity, such as name, social security number, date and place of birth, mother’s maiden name or biometrics records.
2. Any other information that is linked to an individual, such as medical, education, financial and employment information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is piggybacking?

A

page 405

Where the individual knowingly allows another person to tailgate behind hime.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are one safe internet habit?

A

page 406

Never download or install from unknown sites.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is one smart computing habit?

A

page 406

read the EULA

17
Q

What is zero day?

A

page 407

The very day that the attack was discovered.

18
Q

Why is a strong password valuable?

A

page 407

The stronger the password the harder it is to be compromised

19
Q

How do you dispose of Old Media?

A

page 408

Hammer, drill, fire

20
Q

What is the definition of hoax?

A

page 408

A deliberately fabricated falsehood.

21
Q

What are the three classifications of information?

A

page 409
Public use
Internal use
Restricted use.

22
Q

What is public information?

A

page 410

Is primarily that which is made available either to the larger public or to specific individuals who need it.

23
Q

What is Limited distribution?

A

page 410

Information isn’t intended for release to the public.

24
Q

What are the bare minimum security measures be in place for mobile devices?

A

page 418
Screen Lock Voice Encryption
Strong Password GPS Tracking
Device Encryption Application Control
Remote Wipe/Sanitation Storage Segmentation
Asset Tracking Device Access Control

25
Q

What is BYOD

A

page 419

Bring you own Device