IS3110 CHAP 10 Flashcards
Critical business function (CBF)
Any function considered vital to an organization. If it fails, the organization will lose the ability to perform a critical operation necessary for the businesses mission.
Critical success factor (CSF)
An element necessary for the success of an organization. This often contributes to CBFs.
Defense in depth
A security principle used to provide multiple layers of controls. Even though one control may provide protection, additional controls are added to provide stronger protection. It is a strategy that ensures a risk is mitigated even if one control fails.
E-Rate funding
A program in place that provides discounts to schools and libraries for Internet access. Any school or library that requests discounts under the program must comply with CIPA rules. CIPA mandates the filtering of Internet content for children under 17 years of age.
Maximum acceptable outage (MAO)
The maximum amount of time a system or service can be down before affecting the mission. This directly affects the required recovery time. In other words, a system must be recoverable before this time is reached.
Proxy server
A server used to accept requests from clients for Internet access, retrieve the Web pages, and serves them back to the client. It can filter requests so that clients cannot access Web pages. It can be used as a technology protection measures for CIPA.
Return on investment (ROI)
A value that determines the monetary benefits of purchasing or improving a system. If the cost of a control is close to the annual projected benefits, this can be calculated to determine if the control will be valuable over the lifetime of the control.
Service level agreement (SLA)
A document that identifies an expected level of performance. It can specify the minimum uptime or the maximum downtime. It is often written as a contract between a service provider and a customer. An SLA can identify monetary penalties if the terms aren’t met.
Technology protection measure (TPM)
A requirement of CIPA. It will filter offensive content on school and library computers. This ensures that minors are not exposed to the offensive content. It can be disabled if an adult needs to use the computer.
- A ___ is used to identify the impact on an organization if a risk occurs.
Business impact analysis (BIA)
- MAO is the minimal acceptable outage that a system or service can have before affecting the mission.
TRUE OR FALSE.
TRUE
- Your organization wants to have an agreement with a vendor for an expected level of performance for a service. You want to ensure that monetary penalties are assessed if the minimum uptime requirements are not met. What should you use?
- MAO
- BIA
- SLA
- IDS
SLA
- What can be used to help identify mission-critical systems?
- Critical outage times
- Critical business function
- PCI DSS review
- Disaster recovery plan
Critical business function
- What can be used to remind users of the contents of the AUP?
- Logon banners
- Posters
- Emails
- All the above
Logon banner
Posters
Emails
ALL
- Routers have ___ to control what traffic is allowed through them.
Access control lists (ACLs)