Governance Flashcards
What is defense in depth?
Layering of security measures to provide “overlapped” security.
What is the difference in series and parallel when layering?
Parallel leaves gaps that can be exploited.
What is abstraction when securing data?
Grouping things together for efficiency.
What is used when hiding data?
Preventing discovery by unauthorized subjects. Can be done by positioning data in containers not accessible by certain subjects.
What is the definition of encryption?
Art or Science of hiding the meaning or intent of an Object from unintended Subjects.
Name some elements of Privacy.
Prevention of unauthorized access to information that is PII.
Freedom from unauthorized access to information deemed personal or confidential.
Freedom from being observed, monitored, or examined without consent/ knowledge.
What does COBIT stand for?
Control Objectives for
Information and Related Technology
What are the 5 elements of COBIT?
- Meet stakeholder needs
- Covering Enterprise E2E
- Apply single, integrated framework
- Enable holistic approach & principle.
- Separate governance from management.
What is Due Care?
Use of reasonable care to protect interests.
What is Due Diligence?
The practices required to maintain Due Care.
What is the CIA Triad?
Confidentiality
Integrity
Accountability
What does Confidentiality mean?
High level of assurance that objects and/ or resources are restricted from unauthorized Subjects.
What can cause a loss of confidentiality?
Failure to encrypt transmissions
Failure to properly authenticate Subjects.
Failure of an end user or administrator.
What is Integrity?
The ability to ensure that only authorized Subjects can intentionally modify and Object
What can be done to ensure integrity?
Logging & Monitoring