Domain 2: Security Ops and Administration Flashcards

1
Q

ISO 27001:2013

A

Spec for evaluating the performance of an Information Security Management System. Uses Deming Cycle (PDCA), Six Sigma (Define, measure, analyze, improve, control)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO 27002:3013

A

Provides organizational InfoSec standards and management practices which takes into consideration the orgs information risk appetite. Popular

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security Development Lifecycle (SDL)

A

SW dev process proposed by MS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Automated Configuration Management

A

Centralized method to make changes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Configuration Identification

A

Baselines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Functional Policies

A

Address specific issues or concerns of the org. BYOD, AV use, remote wipe, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Organizational Policies

A

Wide scope policy written by someone very high up. Should have specifics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Operational Policies

A

aka System Specific Policy. Clear direction on operational topics.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

QAT

A

Quality Acceptance Testing. Performed by IT Quality team.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

UAT

A

User team tests SW against specific scenarios or business cases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Release coordinator

A

Communicates issues, problems, and concerns and coordinates the services of the help desk group to facilitate SW deployment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Waterfall dev process

A

One step leads to the next until project is completed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Agile dev

A

Items are developed quickly, tested, and made available. Increases releases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

BRD

A

Business Requirements Document. Specific design parameters.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Intangible assets

A

Data, information, and IP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Level I Disaster

A

Local, affects only small part of the operation. 6-12 hour downtime with 48-72 hour recovery.

17
Q

Level II Disaster

A

Affects a significant amount of the organization. 1 week+ affect. Physical location of some departments might be damaged. Data storage facilities may have serious damage and needs to be replaced.

18
Q

Level III Disaster

A

Very serious. Requiring relocation of IT operations to off-prem. Significant damage to facility. Repair may be measured in weeks or months.