Controls, frameworks, and compliance Flashcards

1
Q

What is the CIA model?

A

The confidentiality, integrity, and availability (CIA) triad is a model that helps inform how organizations consider risk when setting up systems and security policies. CIA are the three foundational principles used by cybersecurity professionals to establish appropriate controls that mitigate threats, risks, and vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what are the four main components of security frameworks?

A

Identifying and documenting security goals

Setting guidelines to achieve security goals

Implementing strong security processes

Monitoring and communicating results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what is compliance?

A

Compliance is the process of adhering to internal standards and external regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Give some examples of frameworks?

A

The NIST Cybersecurity Framework (CSF) and the NIST risk management Framework (RMF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the NIST

A

The National Institute of Standards and Technology (NIST) is a U.S.-based agency that develops multiple voluntary compliance frameworks that organizations worldwide can use to help manage risk. The more aligned an organization is with compliance, the lower the risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does FERC-NERC stand for?

A

The Federal Energy Regulatory Commission - North American Electric Reliability Corporation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the FERC-NERC regulation?

A

FERC-NERC is a regulation that applies to organizations that work with electricity or that are involved with the U.S. and North American power grid. These types of organizations have an obligation to prepare for, mitigate, and report any potential security incident that can negatively affect the power grid. They are also legally required to adhere to the Critical Infrastructure Protection (CIP) Reliability Standards defined by the FERC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is CIP?

A

Critical Infrastructure Protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does FedRAMP stand for?

A

The Federal Risk and Authorization Management Program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the FedRAMP

A

FedRAMP is a U.S. federal government program that standardizes security assessment, authorization, monitoring, and handling of cloud services and product offerings. Its purpose is to provide consistency across the government sector and third-party cloud providers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does CIS stand for?

A

Centre for Internet Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is CIS?

A

CIS is a nonprofit with multiple areas of emphasis. It provides a set of controls that can be used to safeguard systems and networks against attacks. Its purpose is to help organizations establish a better plan of defense. CIS also provides actionable controls that security professionals may follow if a security incident occurs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does GDPR stand for?

A

General Data Protection Regulation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is GDPR?

A

GDPR is a European Union (E.U.) general data regulation that protects the processing of E.U. residents’ data and their right to privacy in and out of E.U. territory. For example, if an organization is not being transparent about the data they are holding about an E.U. citizen and why they are holding that data, this is an infringement that can result in a fine to the organization. Additionally, if a breach occurs and an E.U. citizen’s data is compromised, they must be informed. The affected organization has 72 hours to notify the E.U. citizen about the breach.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does PCI DSS stand for?

A

PCI DSS is an international security standard meant to ensure that organizations storing, accepting, processing, and transmitting credit card information do so in a secure environment. The objective of this compliance standard is to reduce credit card fraud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does HIPAA stand for?

A

The Health Insurance Portability and Accountability Act

17
Q

What is HIPPA?

A

HIPAA is a U.S. federal law established in 1996 to protect patients’ health information. This law prohibits patient information from being shared without their consent.

18
Q

What 3 rules is HIPAA governed by?

A

Privacy

Security

Breach notification

19
Q

what does PHI stand for?

A

Protected Health Information

20
Q

What does ISO stand for?

A

International Organization for Standardization

21
Q

What is ISO?

A

ISO was created to establish international standards related to technology, manufacturing, and management across borders. It helps organizations improve their processes and procedures for staff retention, planning, waste, and services.

22
Q

What does SOC type 1 and Soc type 2 stand for?

A

System and Organizations Controls

23
Q

What does AICPA stand for?

A

The American Institute of Certified Public Accountants

24
Q
A