Chapter 14 Flashcards

1
Q

DoD Directive 8570.01

A

“Information Assurance Training, Certification and Workforce Management”

Affects any DoD facility or contractor organization

Ensures that all personnel who are directly involved with information security possess security certifications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

DoD Directive 8140

A

A new, operationally focused cybersecurity training framework

Will replace the 8570.01 directive

Developed by the Defense Information Systems Agency (DISA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Roles identified by the 8140 directive include:

A
Security provision
Operate and maintain
Protect and defend
Analyze
Operate and collect
Oversight and development
Investigate
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

U.S. DoD/NSA Training Standards

A

Are actually training requirements for specific job responsibilities

Developed by the CNSS and NSTISS committees

Provide guidance for course and professional certification vendors to develop curriculum and materials that meet DoD/NSA requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

NSTISS-4011

A

National Training Standard for Information Systems Security (InfoSec) Professionals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CNSS-4012

A

National Information Assurance Training Standard for Senior System Managers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

CNSS-4013

A

National Information Assurance Training Standard for System Administrators (SA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CNSS-4014

A

Information Assurance Officer (IAO) Training NSTISSC-4015 National Training Standard for System Certifiers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

CNSS-4016

A

National Information Assurance Training Standard for Risk Analysts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Vendor-Neutral Professional Certifications

A

A certification is an official statement that validates the fact that a person has satisfied specific job requirements, including:

Possessing a certain level of experience
Completing a course of study
Passing an examination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Seven Main (ISC)^2 Certifications

A

Systems Security Certified Practitioner (SSCP)

Certified Information Systems Security Professional (CISSP)

Certified Authorization Professional (CAP)

Certified Secure Software Lifecycle Professional (CSSLP)

Certified Cyber Forensics Professional (CCFP)

HealthCare Certified Information Security Privacy Practitioner (HCISPP)

Certified Cloud Security Professional (CCSP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SSCP

A

Covers the seven domains of best practices for information security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

CISSP

A

Demonstrates competence in the eight domains of the (ISC)2 CISSP Common Body of Knowledge (CBK)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

CAP

A

Provides a method to measure the knowledge and skills of professionals involved in authorizing and maintaining information systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

CSSLP

A

Evaluates professionals for the knowledge and skills necessary to develop and deploy secure applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

CCFP

A

Tests and evaluates professionals for the knowledge and skills necessary to perform and conduct a digital forensics investigation

17
Q

HCISPP

A

Tests and evaluates professionals for the knowledge and skills necessary to perform and conduct security and privacy work for health care organizations

18
Q

CCSP

A

Tests and evaluates professionals for the knowledge and skills necessary to secure and manage cloud computing environments

19
Q

(Additional (ISC)^2 Professional Certifications)

Architecture (CISSP-ISSAP)

A

Two years of professional experience in the area of architecture; appropriate for chief security architects and analysts

20
Q

(Additional (ISC)^2 Professional Certifications)

Engineering (CISSP-ISSEP)

A

Road map for incorporating security into projects, applications, business processes, and all information systems

21
Q

(Additional (ISC)^2 Professional Certifications)

Management (CISSP-ISSMP)

A

Two years enterprise-wide security operations and management; contains deeper managerial elements

22
Q

Certified Internet Webmaster (CIW)

A

Credentials focus on both general and web-related security

Credentials that satisfy CIW requirements include:

(ISC)^2 SCCP or CISSP
Various GIAC credentials
CompTIA Security+
Several vendor-specific credentials

23
Q

CompTIA

A

Security+

  • Globally recognized
  • Entry-level information security certification of choice for IT professionals
  • Meets the ISO 17024 standard and is approved by the DoD 8570.01-M requirements
  • Is industry supported

CompTIA Advanced Security Practitioner (CASP)

24
Q

ISACA

A

Is a nonprofit global organization that promotes “the development, adoption, and use of globally accepted, industry leading knowledge and practices for information systems”

Provides security training at conferences and training events

Offers four certifications for IT security professionals: CISM, CISA, CGEIT, and CRISC

25
Q

Vendor-Specific Professional Certifications

A

Certifications offered by vendors of hardware and software products

Holding a certification for a specific vendor implies competence

If an applicant meets requirements for a certification, applicant has a certain level of knowledge and skills

26
Q

Cisco Systems

A

One of the largest manufacturers of network security devices and software

Offers a range of certifications for its networking products

Offers several different certification levels along different tracks that enable security professionals to focus efforts on specific knowledge and skills they need to get the most out of Cisco equipment

27
Q

Juniper Networks

A

Manufactures a variety of network security hardware and software

Offers a varied range of certifications for its networking product line

Four levels from 11 different tracks

Does not offer certifications at all levels for every track

28
Q

RSA

A

Global provider of security, risk, and compliance solutions for enterprise environments

Provides specific training and certifications to help security professionals use RSA products effectively

Offers certifications for RSA Archer and RSA SecurID

29
Q

Symantec

A

Provides a wide range of security software products

Offers certifications for its product lines, including:

Administration of Symantec NetBackup for UNIX
Administration of Symantec Enterprise Vault for Exchange
Administration of Symantec Endpoint Protection
Administration of Symantec NetBackup for Windows

30
Q

Check Point

A

Global manufacturer of network and security devices and software

Provides training and certification paths for security professionals to encourage highest level of knowledge and skills in the use of Check Point products

Requires that applicants pass an exam that involves 80 percent study materials and 20 percent hands-on experience