IA (mand) Flashcards

1
Q

Define CERTIFICATION.

A

eval of the technical and non tech security features of an information system, meets a set of security requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define ACCREDITATION.

A

formal declaration by the DESIGNATED APPROVING AUTHORITY (DAA) that the information system is APPROVED TO OPERATE.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is ATO?

A

AUTHORITY TO OPERATE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

IATO.

A

temporary authorization granted by the DESIGNATED APPROVING AUTHORITY

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

RISK MANAGEMENT.

A

balances the operational and economic cost for protective measures and gains of mission capability protecting the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

5 attributes of IA.

A

CAAIN

  1. confidentiality
  2. integrity
  3. availability
  4. non re repudiation
  5. authentication
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Categories of CPU incidents.

A
9 total/ IM RRUUDE N! 
INVESTIGATION 
MALICIOUS 
ROOT LEVEL
RECON
USER LEVEL
UNSUCCESSFUL 
DENIAL OF SERVICES 
EXPLAINED ANOMALY 
NON COMPLIANCE
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

IAVA.

A

Information Assurance Vulnerability Alert: addresses severe network vulnerabilities and potentially severe threats, CORRECTIVE ACTION OF THE HIGHEST PRIORITY

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

IAVB.

A

Information Assurance Vulnerability Bulletin: addresses new vulnerabilities and do not pose immediate risk but non compliance could escalate the risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

IAVT.

A

Information Assurance Vulnerability Technical Advisory: new risks but classified as low risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

CTO.

A

Communications Tasking Order- urgent request coming for the Naval Network Warfare Command CDR (NETWARCOM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define Service Pack.

A

single install package for fixing software problems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Difference between Vulnerability and Threat.

A

Threat is an actual event that can mess up operations and an vulnerability is a weakness in a info system ( but can be fixed)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

IAM.

A

Information Assurance Manager, responsible for the IA program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly