Domain 1 - Security P&P Flashcards
What is PODSCORB
Fayol’s Management Principles: Planning, Organizing, Deciding, Staffing, Directing, Coordinating, Reporting, and Budgeting
ESRM is a ___ not a ___
ESRM is an approach/methodology, not a program
what is observability?
the ability of an adversary to see and identify a vulnerability (or for security to be aware of incoming natural threat)
what is exploitability?
the ability of the adversary to take advantage of the vulnerability (or natural threat’s ability to damage the facility)
What is one mathematical way of calculating risk?
Risk = (threat * vulnerability * impact)^(1/3)
what are requirements for copyrights to be protected
Under international law, copyrights do not have to be registered to be protected
What is the best way to protect a trademark internationally?
Registration of trademarks before the product enters the stream of commerce in any country is the primary means of ensuring that the mark is eligible for protection under that country’s law
How long do patents last?
20 years
What are the criminal laws surrounging trade secrets and patend infringements
Stealing a trade secret may violate criminal laws, but there are no criminal laws regarding patent infringement (US)
What are 10 types of insurance?
commerical general liability
workers compensation
commercial auto
commercial property
excess and umbrella liability - extends limits of primary policies
fidelity coverage - for losses caused by employee’s fraudulent or dishonest actions
Business Interruption Insurance
Directors and Officers insurance - protects individuals from personal losses if sued as a result of these jobs
Cyber Insurance - covers financial loses from data breaches and other cyber events
employment practices liability insurance
what is a captive carrier
writes insurance for the owning company, easier to insure risks not acceptable to conventional carriers (expensive/large firms only)
What is admitted vs non-admitted insurer
For a policy to be admitted, it must be filed and approved with state’s insurance department to ensure the policy meets the rquirements of that state (backed by state’s guaranty fund in event of carrier insolvency.
Non-admitted is for risks not covered by typical policies
What are the three management styles
authoritatian, deomcratic, and laissez-faire
Cost of Loss Formula
K=Cp+Ct+Cr+Ci-I
K=cost of loss; Cp=cost of permanent replacement; Ct=cost of temporary substitute; Cr=total related costs (remove old asset, install new, etc); Ci=lost income cost; I=available insurance or indemnity