Domain 1 Flashcards

1
Q

process of how an org is managed. Includes all aspects of how decisions are made for that org and can include policy, roles, and procedures the org uses to make those decisions.

A

governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

the entirety of the polices, roles, and processes the org uses to make security decisions, Specific to its purpose and objectives

A

security governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Makes strategic decisions and which policies are required for all corp

A

legislation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Might impose corp mandate for part types of decisions

A

Board of directors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Might dictate who within the corp participate and finalizes part decisions

A

Local and federal regulators

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Typically responsible for mandating policy , determining strategic goals for the org, and making final determination according to the org governance for both security and non-security.

A

Senior management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Responsible for advising senior management on security matters, may assist in drafting policies , manages day-to-day security operations represents the org security needs in groups and meetings, selects and contracts for security products , and may manage the incident and disasters response.

A

Security manage, director, or officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Tasked with performing the security processes and activities with the org.

A

Security personnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Recognized globally, know as ISMS, comprehensive holistic view of security governance within an org. Mostly focused on policy.

A

ISO 27001

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

comprehensive list of security controls

A

ISO 27002

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Created and maintained by ISACA, Designed in a way to manage and document enterprise IT and Security functions for an org. Attending to address IT performance, security ops, risk management, and regulatory compliance

A

COBIT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

IT service delivery set of best practices. Concentrates on how an org it env should enhance and benefit its business goals.

A

ITIL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Legal concept pertaining to the duty owed by a provider to a customer.

A

Due care

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

An activity used to demonstrate or provide due care.

A

Due diligence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

publishing a policy is an insufficient form of due diligence. What must you have?

A

To meet the legal duty, an org must also have a documented monitoring and enforcement capability in place and active to ensure the org is adhering to the policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

possibility of damage and harm and the likelihood that damage or harm will be relegalized.

A

Risk

17
Q

Creates a risk and enhances a risk or possibility of being realized.

A

Threat and vulnerability

18
Q

Subjective risk analysis -choose when no budget, no time, or training

A

Qualitive

19
Q

Objective risk analysis - choose when you have budget, time, and training

A

Quantitative

20
Q

Plan and process for determining the proper function and management of controls necessary and should be customized to the needs of the org.

A

Security Control Assessment

21
Q

Adherence to a mandate

A

compliance

22
Q

Compliance reviews

A

audit

23
Q

comes in form of contracts, government imposition, governments creating regulations, or traditional or cultural.

A

mandate

24
Q

Legal standards are set by

A

courts

25
Q

Actions, process, and tools for ensuring an org can continue critical operations during a contingency.

A

Bc

26
Q

Efforts are those task and activities required to bring an org back from contingency operations and reinstate regular operations.

A

DR

27
Q

measure of how long and org can survive an interruption of critical factors if exceeded the org will no longer be viable

A

MAD or MTD

28
Q

target time for recovering from interruption. must be less than MAD. Goal for recovering availability of the critical path. Stage until return to regular status.

A

RTO

29
Q

Measure of how much data the org can lose before the org is no longer viable. Measured in time.

A

RPO