Continuous Monitoring 2 Flashcards

1
Q

DoD Policy

A
  1. 16 insider threat program
  2. 06 CI awareness and reporting
  3. 01 cybersecurity
  4. 01 Risk management framework (consistent with principles established in NIST

CNSSI 1253 security categorization and control/selection for national security systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NIST

A

National institute of standards and technology

NIST SP
800-37 guide for applying RMF to federal info systems
800-137 ISCM for fed info systems and orgs
800-128 Guide for security focused configuration management of info systems
800-53 security and privacy controls for fed info systems and orgs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

NISPOM

A

Detailed industrial security policy for contracts

DoD 5220.22

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

RMF overview

A

Risk: Possibility that threat will adversely impact info systems exploiting vulnerability

Risk assessment: analyzing threats, defining impact, ID countermeasures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Strategic risk tiers

A

Communication loop

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ISCM

A

Maintaining ongoing awareness of IS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Tiers 1/2 develop policies and procedures

ISCM strategy developed tiers 1/2

System specific policy and procedure of implementation tier 3. Strategy based on government guidance

A

Na

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SecCM Controlling Configuration Changes

A

Access restrictions for change employed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly