Domain 1 - Security and Risk Management - Control Frameworks Flashcards

1
Q

Provide “Control Frameworks” highlight points

A
Consistent – approach & application 
Measurable – way to determine progress 
Standardized – all the same 
Comprehension – examine everything 
Modular – to help in review and adaptive. Layered, abstraction
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Describe “Due Care”

A

Which means when a company did all that it could have reasonably done to try and prevent security breach / compromise / disaster, and took the necessary steps required as countermeasures / controls (safeguards). The benefit of “due care” can be seen as the difference between the damage with or without “due care” safeguards in place. AKA doing something about the threats, Failing to perform periodic security audits can result in the perception that due care is not being maintained.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Describe “Due Diligence”

A

means that the company properly investigated all of its possibly weaknesses and vulnerabilities AKA understanding the threats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly