COMPARING SECURITY ROLES AND SECURITY CONTROLS Flashcards

1
Q

What is a security Control?

A

Something designed to give a system or data asset the properties of Confidentiality, Integrity, Availability, and Non-repudiation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is a technical Control?

A

Control, implemented as a system (hardware,software,firmware)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is an Operational Control?

A

Implemented by people rather than systems (security Guards, training)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Managerial Control?

A

Gives oversight of information System (risk ID tool)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security Control Categories?

A

Technical, Managerial, Operational

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Security Control Function Types?

A

Preventative, Detective, Corrective, Physical, Deterrent, Compensating

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Preventative Control Function?

A

Acts to eliminate or reduce likelihood of attack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Detective Control Function

A

Does not prevent or Deter, but will ID/record any attempt intrustion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Corrective Control Function

A

Acts to eliminate or reduce the impact of an intrusion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Physical Control Function

A

Deter/Detect Physical access (Alarms/locks cameras)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Deterrent Control Function

A

May not prevent access, but discourages it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Compensating Control Function

A

Substitute for principal control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is A Cybersecurity Framework?

A

A list of activities and objectives undertaken to mitigate risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is NIST (CSF)?

A

National Institute of Standards and Technology : Focuses solely on IT security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What Does ISO 27k Focus on?

A

Personal Data and Privacy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does ISO 31k Focus on?

A

Overall framework for enterprise risk management (ERM)

17
Q

What Is the Cloud Security Alliance? (CSA)

A

Organization that produces various resources to assist cloud service providers (CSP) in setting up and delivering secure cloud platforms.

18
Q

What is the statements on Standards for Attestation Engagements (SSAE) Service organization Control (SOC)

A

SSAE is audit specifications developed by the American Institute of certified Public Accountants

19
Q

SSAE SOC2 vs SOC3

A

SOC2 is detailed;DnD
SOC3 is Unclassified

20
Q

What is the Center for internet Security (CIS)

A

the 20 CIS
Controls.” The CIS-RAM (Risk Assessment Method) can be used to perform an overall
evaluation of security posture

21
Q

Open Web Application Security Project (OWASP)

A

community that publishes several secure application development resources,

22
Q

Sarbanes-Oxley Act (SOX)

A

mandates the implementation of risk assessments, internal controls, and
audit procedures.

23
Q

he Computer Security Act (1987)

A

equires federal agencies to
develop security policies for computer systems that process confidential information

24
Q

General Data Protection
Regulation (GDPR)

A

personal data cannot be collected, processed, or
retained without the individual’s informed consent

25
Q

Payment Card Industry Data Security Standard (PCI DSS

A

defines the safe handling
and storage of financial information

26
Q
A