Chapter 15 - Risk Mitigation Flashcards

1
Q

Threat assessment

A

Determining what threats an enterprise may be facing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Supply chain assessment

A

Determining the risk to a supply chain network that moves a product from the supplier to the customer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security control

A

Any device or process that is used to reduce risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Deterrent control

A

A control that attempts to discourage security violations before they occur.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Preventive control

A

A control that attempts to prevent the threat from coming in and reaching contact with the vulnerability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Physical control

A

A control that implements security in a defined structure and location.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Detective control

A

A control that is designed to identify any threat that has reached the system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Compensating control

A

A control that provides an alternative to normal controls that for some reason cannot be used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Corrective control

A

Controls that are intended to mitigate or lessen the damage caused by an incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Security policy

A

A written document that states how an organization plans to protect the company’s information technology assets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Acceptable use policy (AUP)

A

A policy that defines the actions users may perform while accessing systems and networking equipment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Personal email policy

A

A policy that covers using company email to send personal email messages, acceding personal email at a place of employment, and forwarding company emails to a personal email account.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Social media policy

A

A policy that outlines acceptable employee use of social media.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Service level agreement (SLA)

A

A contract between a vendor and a client that specifies what services will be provided, the responsibilities of each party, and any guarantees of service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Blanket purchase agreement (BPA)

A

A prearranged purchase or sale agreement between a government agency and a business.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Memorandum of understanding (MOU)

A

An agreement between two or more parties to enable them to work together that is not legally enforceable but is more formal than an unwritten agreement.

17
Q

Interconnection security agreement (ISA)

A

An agreement between parties intended to minimize security risks for data transmitted across a network.

18
Q

Non-disclosure agreement (NDA)

A

A legal contract between parties that specifies how confidential material will be shared between the parties but restricted to others.

19
Q

Background check

A

Authenticating the information supplied to a potential employer by a job applicant in the applicants resume, application, and interviews.

20
Q

Exit interview

A

A “wrap-up” meeting between management representatives and the person leaving an organization.