Chapter 8 - Sustain - Training And Awareness Flashcards

1
Q

What is the average cost of a data breach as of 2020

A

3.86 million dollars

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the top three industries in terms of financial impact of a data breach

A

1 healthcare (7 million)
2. Energy (6 million)
3. Financial services (5 million)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What can be done to reduce the cost of a data breach

A

Have an information security and incident response team in place (can reduce costs by 2 million)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the difference between training and awareness?

A

Training strives to produce relevant and
needed skills and competencies. Awareness focuses on a specific topic, such as security. Awareness is intended to allow individuals to recognize specific concerns, such as technology, and respond accordingly.6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is NIST SP 800-50

A

NIST SP 800-50, “Building an Information Technology Security Awareness and Training Program,”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 4 steps in the NIST 800-50 awareness and training life cycle

A
  1. Awareness and training program design
  2. Awareness and training material development
  3. Program implantation
  4. Post implementation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly