Chapter 14 Flashcards

1
Q

DoD Directive 8570.01

A

“Information Assurance Training, Certification and Workforce Management”

Affects any DoD facility or contractor organization

Ensures that all personnel who are directly involved with information security possess security certifications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

DoD Directive 8140

A

A new, operationally focused cybersecurity training framework

Will replace the 8570.01 directive

Developed by the Defense Information Systems Agency (DISA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Roles identified by the 8140 directive include:

A
Security provision
Operate and maintain
Protect and defend
Analyze
Operate and collect
Oversight and development
Investigate
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

U.S. DoD/NSA Training Standards

A

Are actually training requirements for specific job responsibilities

Developed by the CNSS and NSTISS committees

Provide guidance for course and professional certification vendors to develop curriculum and materials that meet DoD/NSA requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

NSTISS-4011

A

National Training Standard for Information Systems Security (InfoSec) Professionals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CNSS-4012

A

National Information Assurance Training Standard for Senior System Managers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

CNSS-4013

A

National Information Assurance Training Standard for System Administrators (SA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CNSS-4014

A

Information Assurance Officer (IAO) Training NSTISSC-4015 National Training Standard for System Certifiers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

CNSS-4016

A

National Information Assurance Training Standard for Risk Analysts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Vendor-Neutral Professional Certifications

A

A certification is an official statement that validates the fact that a person has satisfied specific job requirements, including:

Possessing a certain level of experience
Completing a course of study
Passing an examination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Seven Main (ISC)^2 Certifications

A

Systems Security Certified Practitioner (SSCP)

Certified Information Systems Security Professional (CISSP)

Certified Authorization Professional (CAP)

Certified Secure Software Lifecycle Professional (CSSLP)

Certified Cyber Forensics Professional (CCFP)

HealthCare Certified Information Security Privacy Practitioner (HCISPP)

Certified Cloud Security Professional (CCSP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SSCP

A

Covers the seven domains of best practices for information security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

CISSP

A

Demonstrates competence in the eight domains of the (ISC)2 CISSP Common Body of Knowledge (CBK)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CAP

A

Provides a method to measure the knowledge and skills of professionals involved in authorizing and maintaining information systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

CSSLP

A

Evaluates professionals for the knowledge and skills necessary to develop and deploy secure applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

CCFP

A

Tests and evaluates professionals for the knowledge and skills necessary to perform and conduct a digital forensics investigation

17
Q

HCISPP

A

Tests and evaluates professionals for the knowledge and skills necessary to perform and conduct security and privacy work for health care organizations

18
Q

CCSP

A

Tests and evaluates professionals for the knowledge and skills necessary to secure and manage cloud computing environments

19
Q

(Additional (ISC)^2 Professional Certifications)

Architecture (CISSP-ISSAP)

A

Two years of professional experience in the area of architecture; appropriate for chief security architects and analysts

20
Q

(Additional (ISC)^2 Professional Certifications)

Engineering (CISSP-ISSEP)

A

Road map for incorporating security into projects, applications, business processes, and all information systems

21
Q

(Additional (ISC)^2 Professional Certifications)

Management (CISSP-ISSMP)

A

Two years enterprise-wide security operations and management; contains deeper managerial elements

22
Q

Certified Internet Webmaster (CIW)

A

Credentials focus on both general and web-related security

Credentials that satisfy CIW requirements include:

(ISC)^2 SCCP or CISSP
Various GIAC credentials
CompTIA Security+
Several vendor-specific credentials

23
Q

CompTIA

A

Security+

  • Globally recognized
  • Entry-level information security certification of choice for IT professionals
  • Meets the ISO 17024 standard and is approved by the DoD 8570.01-M requirements
  • Is industry supported

CompTIA Advanced Security Practitioner (CASP)

24
Q

ISACA

A

Is a nonprofit global organization that promotes “the development, adoption, and use of globally accepted, industry leading knowledge and practices for information systems”

Provides security training at conferences and training events

Offers four certifications for IT security professionals: CISM, CISA, CGEIT, and CRISC

25
Vendor-Specific Professional Certifications
Certifications offered by vendors of hardware and software products Holding a certification for a specific vendor implies competence If an applicant meets requirements for a certification, applicant has a certain level of knowledge and skills
26
Cisco Systems
One of the largest manufacturers of network security devices and software Offers a range of certifications for its networking products Offers several different certification levels along different tracks that enable security professionals to focus efforts on specific knowledge and skills they need to get the most out of Cisco equipment
27
Juniper Networks
Manufactures a variety of network security hardware and software Offers a varied range of certifications for its networking product line Four levels from 11 different tracks Does not offer certifications at all levels for every track
28
RSA
Global provider of security, risk, and compliance solutions for enterprise environments Provides specific training and certifications to help security professionals use RSA products effectively Offers certifications for RSA Archer and RSA SecurID
29
Symantec
Provides a wide range of security software products Offers certifications for its product lines, including: Administration of Symantec NetBackup for UNIX Administration of Symantec Enterprise Vault for Exchange Administration of Symantec Endpoint Protection Administration of Symantec NetBackup for Windows
30
Check Point
Global manufacturer of network and security devices and software Provides training and certification paths for security professionals to encourage highest level of knowledge and skills in the use of Check Point products Requires that applicants pass an exam that involves 80 percent study materials and 20 percent hands-on experience