Frameworks, Standards, and Models Flashcards

1
Q

ISO 27005

A

Risk Management Framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO 15288

A

Systems engineering standard covering processes and life cycle stages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ISO 15408

A

Common Criteria

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO 27002

A

Framework for security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ISO 27001

A

Standard for ISMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

COBIT

A

IT Security Best Practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Fraud Prevention Framework

A

COSO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

COSO

A

Risk Management controls framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

COBIT 5

A

5 key principles for governance and management of enterprise IT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

ISO 9000 series

A

Quality management techniques

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

SOC 1

A

Internal controls over financial reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SOC 2

A

Technical assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SOC 2 evaluates

A

CIA
Privacy
Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which SOC report is public?

A

SOC 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SOC 2 Type 1

A

Evaluates design of security controls at a point in time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SOC 2 Type 2

A

Assesses control effectiveness over a period of time (3-6 months)

17
Q

TSP/TSC

A

SOC 2

18
Q

SOC X Type 1

A

Design

19
Q

SOC X Type 2

A

Testing of controls

20
Q

SOC evaluates

A

Trusted Service Principles

21
Q

TCSEC only recognized in…

A

the US

22
Q

ITSEC is recognized in…

A

Europe only

23
Q

Regionalized product evaluation models (2)

A

ITSEC
TCSEC

24
Q

Zachman framework

A

Give holistic view of the enterprise.

Understand complex architecture

25
Q

SABSA

A

Risk driven security architecture

26
Q

CMMI

A

Process

27
Q

ISO 21827

A

CMMI

28
Q

CMMI 1-2

A

Reactive

29
Q

CMMI 2-3

A

Biggest jump

30
Q

CMMI 3-5

A

Proactive

31
Q

Service mark

A

Type of trademark

32
Q

Key word for CMMI

A

Appraisal (not certification)