Domain 1, Information Security Governance Flashcards
PCI-DSS
Payment Card Industry Data Security Standard
OCTAVE
Operationally Critical Threat, Asset, and Vulnerability Evaluation.
• Self Directed Risk Management.
COBIT
Control Objectives for Information and related Technology.
• Goals for IT – Stakeholder needs are mapped down to IT related goals.
COSO
Committee Of Sponsoring Organizations.
• Goals for the entire organization.
ITIL
Information Technology Infrastructure Library.
• IT Service Management (ITSM).
FRAP
Facilitated Risk Analysis Process.
• Analyses one business unit, application or system at a time in a roundtable brainstorm with internal employees. Impact analyzed, threats and risks prioritized.
SWOT
Strengths, Weaknesses, Opportunities, and Threats
Gap analysis:
Identify the existing process:
• What are we doing?
Identify the existing outcome:
• How well do we do it?
Identify the desired outcome:
• How well do we want to do?
Identify and document the gap:
• What is the difference between now and desired result?
Identify the process to achieve the desired outcome:
• How can we possibly get to the desired result?
Develop the means to fill the gap:
• Build the tool or processes to get the result.
Develop and prioritize Requirements to bridge the gap.
OPEX
(Operating Expense) is the ongoing cost for running a product, business, or system.
CAPEX
(Capital Expenditure) is the money a company spends to buy, maintain, or improve its fixed assets, such as buildings, vehicles, equipment, or land.
KGI (Key Goal Indicator):
Define measures that tell management, after the fact—whether an IT process has achieved its business requirements.
KPI (Key Performance Indicators):
Define measures that determine how well the IT process is performing in enabling the goal to be reached.
KRI (Key Risk Indicators):
Metrics that demonstrate the risks that an organization is facing or how risky an activity is.
The CIA Triad (AIC)
Confidentiality
Integrity
Availability
Data at Rest
(Stored data): This is data on disks, tapes, CDs/DVDs, USB sticks