Domain 1: Security and Risk Management Flashcards
Code Ethics- tenants and order?
Protect society, behave honorably, do a good job, advance the profession
Confidentiality definition and associated risk?
Only authorized people can access the information and the risk is unauthorized disclosure
Integrity definition and risk?
Integrity is ensuring information is accurate and complete, and only authorized users can alter/change information. The risk is unauthorized alteration.
Availability definition and risk?
Information availability, risk is unauthorized destruction
Security governance
The responsibilities and procedures governing security in org
Who is ultimately responsible for information security?
Board of directors/CEO - whomever is the head of the head
Sec gov principle - aligning?
understand the business and act accordingly.
governance committee
governance committee is a group of diverse executives to keep tabs on what’s going on and provide oversight on the security of an org
Sec gov principle - involve information security
governance committees and be part of tech acquisitions and such
Org roles - common roles - CISO
CISO A senior level exec responsible for overall management and supervision of the info sec program
Org roles - common roles - User
Users are everyone - they must agree to security policies and generally follow them within their job role
iso 27001
what you should be doing
security control framework
iso 27002
How you should be doing it
security control framework
NIST 800-53
security control framework
NIST sec control framework 5 core functions
Identify, Protect, Detect, Respond, and Recover