COMPARING SECURITY ROLES AND SECURITY CONTROLS Flashcards

1
Q

What is a security Control?

A

Something designed to give a system or data asset the properties of Confidentiality, Integrity, Availability, and Non-repudiation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a technical Control?

A

Control, implemented as a system (hardware,software,firmware)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is an Operational Control?

A

Implemented by people rather than systems (security Guards, training)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Managerial Control?

A

Gives oversight of information System (risk ID tool)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security Control Categories?

A

Technical, Managerial, Operational

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Security Control Function Types?

A

Preventative, Detective, Corrective, Physical, Deterrent, Compensating

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Preventative Control Function?

A

Acts to eliminate or reduce likelihood of attack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Detective Control Function

A

Does not prevent or Deter, but will ID/record any attempt intrustion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Corrective Control Function

A

Acts to eliminate or reduce the impact of an intrusion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Physical Control Function

A

Deter/Detect Physical access (Alarms/locks cameras)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Deterrent Control Function

A

May not prevent access, but discourages it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Compensating Control Function

A

Substitute for principal control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is A Cybersecurity Framework?

A

A list of activities and objectives undertaken to mitigate risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is NIST (CSF)?

A

National Institute of Standards and Technology : Focuses solely on IT security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What Does ISO 27k Focus on?

A

Personal Data and Privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does ISO 31k Focus on?

A

Overall framework for enterprise risk management (ERM)

17
Q

What Is the Cloud Security Alliance? (CSA)

A

Organization that produces various resources to assist cloud service providers (CSP) in setting up and delivering secure cloud platforms.

18
Q

What is the statements on Standards for Attestation Engagements (SSAE) Service organization Control (SOC)

A

SSAE is audit specifications developed by the American Institute of certified Public Accountants

19
Q

SSAE SOC2 vs SOC3

A

SOC2 is detailed;DnD
SOC3 is Unclassified

20
Q

What is the Center for internet Security (CIS)

A

the 20 CIS
Controls.” The CIS-RAM (Risk Assessment Method) can be used to perform an overall
evaluation of security posture

21
Q

Open Web Application Security Project (OWASP)

A

community that publishes several secure application development resources,

22
Q

Sarbanes-Oxley Act (SOX)

A

mandates the implementation of risk assessments, internal controls, and
audit procedures.

23
Q

he Computer Security Act (1987)

A

equires federal agencies to
develop security policies for computer systems that process confidential information

24
Q

General Data Protection
Regulation (GDPR)

A

personal data cannot be collected, processed, or
retained without the individual’s informed consent

25
Payment Card Industry Data Security Standard (PCI DSS
defines the safe handling and storage of financial information
26