Documentation and Reporting Flashcards

1
Q

Documents to Maintain Includes:

A
  • Gap Assessment Report
  • Vulnerability Assessment Report
  • Risk Assessment Report
  • Zone & Conduit diagrams
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Vulnerability Assessment Report

A
  • Scope of the assessment
  • “As found” System Architecture
  • Assessment details
  • Prioritized summary of findings
  • Detailed findings
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Vulnerability Assessment Report

A
  • Scope of the assessment
  • “As found” System Architecture
  • Assessment details
  • Prioritized summary of findings
  • Detailed findings
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Cybersecurity Risk Assessment Report

A
  • Risk profile
  • Scope of the risk assessment
  • Assessment details
  • Detailed findings
  • Prioritezed recomendations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Cybersecurity Requirements Specifications

A

A Cybersecurity Requirements Specification (CRS) documents general security requirements based upon company policy and standards, relevant regulations and the outcome of the high-level risk assessment as well as any mandatory security functions of the SuC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Definition of zones and conduits, access control requirements, and security level targets should all be included in which document?

A

Cybersecurity Requirements Specification (CRS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In a CRS, which requirements can be grouped?

A

Access control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The desired level of security for a particular system is known as a Target Security Level (SL-T). Which document includes SL-Ts?

A

CRS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True of False?

A CRS is a living document that may change over time

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

True of False?

Without documentation, there is nothing to verify, audit or prove.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly