CISSP General Flashcards
1
Q
Change Management Process
A
- Request the Change
- Review the change
- approve or reject
- test the change
- schedule and implement
- document the change
2
Q
Info lifecycle
A
- Creation
- classification
- Storage
- usage (data in transit/use)
- archive
- destruction
3
Q
SCAP
A
Security Content Automation Protocol
framework for discussing and facilitate automation of process between applications
4
Q
CVE
A
Common Vulnerability and Assessment
- naming system to describe security vulnerabilities
- Part of SCAP
5
Q
CVSS
A
Common Vulnerability Scoring System
- standardized scoring system to describe severity of vulnerabilities
- Part of SCAP
6
Q
CCE
A
Common Configuration Enumeration
- naming system for system configuration issues
- Part of SCAP
7
Q
XCCDF
A
Extensible Configuration Checklist Description Format
- language for specifying computer checklists
- Part of SCAP
8
Q
OVAL
A
Open Vulnerability Assessment Language
- language for describing security testing procedures
- Part of SCAP
9
Q
Change Management Process
A
- Request the change
- Review the change
- Approve/reject
- test
- schedule and implement
- document