Domain #2: Asset Security Flashcards

1
Q

What is an “Asset”?

A

An asset is, anything of worth to an organization. This includes people,
partners, equipment, facilities, reputation, and information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Information Life Cycle

A

*Acquisition
*Store
*Use
*Share
*Archival
*Disposal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Commercial/Private Information
Classification:

A

*Confidential
*Private
*Sensitive
*Public

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Military Information Classification

A

*Top Secret
*Secret
*Confidential
*Sensitive but unclassified
*Unclassified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Data Classification Procedure/Steps

A
  1. Define classification levels
  2. Criteria for how data is classified
  3. Data owner should classify under their responsibility
  4. Identify data custodian who will maintain data and security
  5. Indicate security controls or protection for each classification
  6. Document any exceptions
  7. Indicate process for transferring ownership to different custodian
  8. Define procedure for declassifying data
  9. Integrate in security awareness training program
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the responsibilities of the CEO?

A

*CEO – Chief Executive Officer
*Day-to-day management of entire organization
*Often Chairperson of the Board of Directors and is highest
ranking officer in company
*Oversees companies finances, budget, strategic vision, business
plan
*Decides on partnerships with other vendors
*Decides how company will differentiate itself from its competitors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the responsibilities of CFO?

A

*CFO – Chief Financial Officer
*Day-to-day account and financial activities
*Responsible for overall financial structure
*Determines companies current and future financial needs
*Maintains company capital structure
*Equity, Cash, Credit, Debt
*Oversees budget and financial performance metrics
*Responsible for filing financial statements to regulatory bodies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the responsibilities of CPO?

A

*CPO – Chief Privacy Officer
*Reports to Chief Security Officer
*Newer position
*Oversee appropriate handling and usage of data
*Familiar with outside regulations
and market specific legal requirements
*Usually an attorney by training

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the responsibilities of CSO?

A

CSO – Chief Security Officer
*Responsible for understanding company specific risks and processes used to mitigate these risks
*Must understand business drivers
*Responsible for maintaining company Security Program
*Responsible for compliance with applicable regulations and laws
*Ensures Business is NOT interrupted in any way

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the responsibilities of CISO?

A

*Chief Information Security Officer
*Must have a strong understanding of business processes and objectives
*Ability to communicate effectively with upper management
*Understand legal regulations and security frameworks
*Develop and maintain security awareness programs
*Develop security budget and report to Board of Directors or upper management
*Respond to security incident or breach

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Internal and external labeling of each piece of media in the library should include

A

*Date created
*Retention period
*Classification level
*Who created it
*Date to be destroyed
*Name and version

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What aimed at preventing the loss of sensitive information?

A

Data leak prevention (DLP) aimed at preventing the loss of sensitive information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly