Domain 1 - Security and Risk Management - Control Frameworks Flashcards
Provide “Control Frameworks” highlight points
Consistent – approach & application Measurable – way to determine progress Standardized – all the same Comprehension – examine everything Modular – to help in review and adaptive. Layered, abstraction
Describe “Due Care”
Which means when a company did all that it could have reasonably done to try and prevent security breach / compromise / disaster, and took the necessary steps required as countermeasures / controls (safeguards). The benefit of “due care” can be seen as the difference between the damage with or without “due care” safeguards in place. AKA doing something about the threats, Failing to perform periodic security audits can result in the perception that due care is not being maintained.
Describe “Due Diligence”
means that the company properly investigated all of its possibly weaknesses and vulnerabilities AKA understanding the threats