Domain 1 - Security and Risk Management - Corporate Officer Liability (SOX) Flashcards
Executives are not held liable if the organization they represent is not compliant with the law.
…True or False
False; Executives are now held liable if the organization they represent is not compliant with the law.
Which of the following best describes negligence if there is a failure to implement recommended precautions.
if there is no contingency/disaster recovery plan
failure to conduct appropriate background checks
failure to institute appropriate information security measures
failure to follow policy or local laws and regulations
All of the above
All of the above
What is TCSEC?
Trusted Computer System Evaluation Criteria
What is ITSEC?
Information Technology Security Evaluation Criteria
Define TCSEC?
- issued in 1983 by National Computer Security Center
- frequently referred to as the Orange Book
- centerpiece of the DoD Rainbow Series publications
- set requirements for built-in security controls on systems that would be processing classified infor
- TCSEC was replaced by Common Criteria standard in 2005
Define ITSEC?
- issued May 1990, France, Germany, Netherlands, UK
- Referred as the European version of TCSEC
- ITSEC was replaced by Common Criteria standard in 2005
TCSEC and ITSEC came together in Common Criteria. What are considered overlap from the original framework of the two? Part 1
A. level of confidentiality and privacy protections
B. strong in anti-spam and legitimate marketing
C. user claims identity, used for user access control
D. determine actions to an individual person
E. User may refuse cookies to be stored and user must be provided with information
TCSEC and ITSEC came together in Common Criteria. What are considered overlap from the original framework of the two? Part 2
A. level of confidentiality and privacy protections
B. Takes an OPT-IN approach to unsolicited commercial electronic communications
C. Member states in the EU can make own laws e.g.
retention of data
D. Directs public directories to be subjected to tight controls
E. rights and permissions granted
What is COSO?
Committee of Sponsoring Organizations of the Treadway Commission
Define COSO?
Framework to work with Sarbanes-Oxley 404 compliance