Domain 1: Security and Risk Management Flashcards

1
Q

Code Ethics- tenants and order?

A

Protect society, behave honorably, do a good job, advance the profession

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Confidentiality definition and associated risk?

A

Only authorized people can access the information and the risk is unauthorized disclosure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Integrity definition and risk?

A

Integrity is ensuring information is accurate and complete, and only authorized users can alter/change information. The risk is unauthorized alteration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Availability definition and risk?

A

Information availability, risk is unauthorized destruction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security governance

A

The responsibilities and procedures governing security in org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who is ultimately responsible for information security?

A

Board of directors/CEO - whomever is the head of the head

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Sec gov principle - aligning?

A

understand the business and act accordingly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

governance committee

A

governance committee is a group of diverse executives to keep tabs on what’s going on and provide oversight on the security of an org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Sec gov principle - involve information security

A

governance committees and be part of tech acquisitions and such

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Org roles - common roles - CISO

A

CISO A senior level exec responsible for overall management and supervision of the info sec program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Org roles - common roles - User

A

Users are everyone - they must agree to security policies and generally follow them within their job role

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

iso 27001

A

what you should be doing
security control framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

iso 27002

A

How you should be doing it
security control framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

NIST 800-53

A

security control framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

NIST sec control framework 5 core functions

A

Identify, Protect, Detect, Respond, and Recover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly