Control, Monitoring, and Audit Flashcards

1
Q

What is control?

A
  1. Minimise deviation from standards and foreseeing action
  2. Control = Monitor + Action
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the component of PDCA?

A

Plan, Do , Check, and Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is risk management about?

A
  1. Effective and efficient controls
  2. Obtaining further information
  3. Learn lessons from incidents
  4. Detecting changes
  5. Identify emerging risks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the key issues in monitoring /controlling?

A
  1. Learning process
  2. Specific experts
  3. Cost-benefit
  4. Frameworks, KPIs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the best practices in security training?

A
  1. Someone directly responsible
  2. Testing
  3. Every 4-6 months
  4. Open communication policy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which types of control exist?

A
  1. Before an event (feedforward)
  2. During an event (concurrent)
  3. After an event (feedback)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which cybersecurity frameworks exist?

A
  1. NIST
  2. ISO 27001 and ISO 27002
  3. SOC2
  4. NERC CIP
  5. HIPAA
  6. GDPR
  7. FISMA
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the NIST about?

A

Guidance to help organisation focus on the most critical security considerations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is ISO27001 and ISO27002 about?

A

Information security controls that organisations might choose to implement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is SOC2?

A

Auditing procedure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is NERC CIP?

A

Set of standards in North America

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is HIPAA?

A

Cybersecurity framework for Health

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the GDPR about?

A

Privacy and security law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is FISMA about?

A

Government information protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the upper left area in the VUCA graph?

A

Complexity - multiple key decision factors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the upper right area in the VUCA graph?

A

Volatility - rapid and unexpected challenges

17
Q

What is the bottom left area in the VUCA graph?

A

Ambiguity - Too many “unknown unknowns”

18
Q

What is the bottom right area in the VUCA graph?

A

Uncertainty - pending change: known unknowns

19
Q

What is continuous assurance?

A

Continuous control monitoring + continuous auditing