Chapter 8: Using Risk Management Tools Flashcards
1
Q
Nmap
A
Network scanner that can detect protocols and services running on a server
2
Q
Passive Reconnaissance
A
Uses open source intelligence instead of active tools
3
Q
SOC 2 Type I
A
Describes organizations’ systems and design effectiveness on security controls on a specific date
How well controls address the risks
4
Q
SOC 2 Type II
A
Over a range of dates
How well controls mitigated the risks
5
Q
PCI DSS
A
Payment Card Industry Data Security Standard
6
Q
ISO 27001
A
Information security management system requirements
7
Q
ISO 27002
A
A compliment to ISO 27001, provides best practices guidance
8
Q
ISO 27701
A
PII
9
Q
ISO 31000
A
Risk management standards