Frameworks, Policies, and Procedures Flashcards
Framework-based governance seeks to mitigate the risks that are associated with IT
service delivery
Enterprise Security Architecture
A framework that stipulates control selection and deployment
Prescriptive Frameworks
A component of an ESA framework that is used to assess the formality and
optimization of security control selection and usage and address any gaps
Maturity Model
Prescriptive frameworks can make it difficult for the framework to keep pace with
a continually evolving threat landscape
Risk-based Frameworks
A framework that uses risk assessment to prioritize security control selection and
investment
Risk-based Framework
A risk-based framework that is focused on IT security over IT service provision
NIST Cybersecurity Framework
Identifies five cybersecurity functions (Identify, Protect, Detect,
Respond, and Recover) and each function can be divided into categories
and subcategories
Framework Core
Assesses how closely core functions are integrated with the
organization’s overall risk management process and each tier is classed
as Partial, Risk Informed, Repeatable, and Adaptive
Implementation Tiers
Used to supply statements of current cybersecurity outcomes and
target cybersecurity outcomes to identify investments that will be most
productive in closing the gap in cybersecurity capabilities shown by
comparison of the current and target profiles
Framework Profiles
The process of determining whether a system is free from defects or deficiencie
Quality Control (QC)
Processes that analyze what constitutes quality and how it can be measured and
checked
Quality Assurance (QA)
A compliance-testing process to ensure that the security system meets
the requirements of a framework or regulatory environment, or that a
product or system meets its design goals
Verification
The process of determining whether the security system is fit for
purpose
Validation
The process of testing the subject against a checklist of requirements in a highly
structured way for measurement against an absolute standard
Assessment
A less methodical process of testing that is aimed at examining outcomes or
proving usefulness
Evaluation