IS3110 CHAP 10 Flashcards

1
Q

Critical business function (CBF)

A

Any function considered vital to an organization. If it fails, the organization will lose the ability to perform a critical operation necessary for the businesses mission.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Critical success factor (CSF)

A

An element necessary for the success of an organization. This often contributes to CBFs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Defense in depth

A

A security principle used to provide multiple layers of controls. Even though one control may provide protection, additional controls are added to provide stronger protection. It is a strategy that ensures a risk is mitigated even if one control fails.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

E-Rate funding

A

A program in place that provides discounts to schools and libraries for Internet access. Any school or library that requests discounts under the program must comply with CIPA rules. CIPA mandates the filtering of Internet content for children under 17 years of age.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Maximum acceptable outage (MAO)

A

The maximum amount of time a system or service can be down before affecting the mission. This directly affects the required recovery time. In other words, a system must be recoverable before this time is reached.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Proxy server

A

A server used to accept requests from clients for Internet access, retrieve the Web pages, and serves them back to the client. It can filter requests so that clients cannot access Web pages. It can be used as a technology protection measures for CIPA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Return on investment (ROI)

A

A value that determines the monetary benefits of purchasing or improving a system. If the cost of a control is close to the annual projected benefits, this can be calculated to determine if the control will be valuable over the lifetime of the control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Service level agreement (SLA)

A

A document that identifies an expected level of performance. It can specify the minimum uptime or the maximum downtime. It is often written as a contract between a service provider and a customer. An SLA can identify monetary penalties if the terms aren’t met.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Technology protection measure (TPM)

A

A requirement of CIPA. It will filter offensive content on school and library computers. This ensures that minors are not exposed to the offensive content. It can be disabled if an adult needs to use the computer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
  1. A ___ is used to identify the impact on an organization if a risk occurs.
A

Business impact analysis (BIA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
  1. MAO is the minimal acceptable outage that a system or service can have before affecting the mission.
    TRUE OR FALSE.
A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
  1. Your organization wants to have an agreement with a vendor for an expected level of performance for a service. You want to ensure that monetary penalties are assessed if the minimum uptime requirements are not met. What should you use?
  2. MAO
  3. BIA
  4. SLA
  5. IDS
A

SLA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  1. What can be used to help identify mission-critical systems?
  2. Critical outage times
  3. Critical business function
  4. PCI DSS review
  5. Disaster recovery plan
A

Critical business function

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
  1. What can be used to remind users of the contents of the AUP?
  2. Logon banners
  3. Posters
  4. Emails
  5. All the above
A

Logon banner
Posters
Emails
ALL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
  1. Routers have ___ to control what traffic is allowed through them.
A

Access control lists (ACLs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q
  1. Which of the strategies below can help to reduce security gaps even if a security control fails?
  2. Access control
  3. Critical business factor analysis
  4. Defense in depth
  5. Business impact analysis
A

Defense in depth

17
Q
  1. How much can an organization be fined in a year for mistakes that result in noncompliance?
  2. $100
  3. $1,000
  4. $25,000
  5. $250,000
A

$25,000

18
Q
  1. What determines if an organization is governed by FISMA?
  2. If it is registered with the Securities and Exchange commission
  3. If employees handle health-related information
  4. If it receives E-Rate funding
  5. If it is a federal agency
A

If it is a federal agency

19
Q
  1. What determines if an organization is governed by HIPAA?
  2. If it is registered with the Securities and Exchange commission
  3. If employees handle health-related information
  4. If it receives E-Rate funding
  5. If it is a federal agency
A

If employees handle health-related information

20
Q
  1. What determines if an organization is governed by SOX?
  2. If it is registered with the Securities and Exchange commission
  3. If employees handle health-related information
  4. If it receives E-Rate funding
  5. If it is a federal agency
A

If it is registered with the Securities and Exchange commission

21
Q
  1. What determines if an organization is governed by CIPA?
  2. If it is registered with the Securities and Exchange commission
  3. If employees handle health-related information
  4. If it receives E-Rate funding
  5. If it is a federal agency
A

If it receives E-Rate funding

22
Q
  1. You’ve performed a CBA on a prospective control. The CBA indicates the cost of the control is about the same as the projected benefits. What should you do?
  2. Identify the ROI
  3. Purchased the control
  4. Cancel the purchase of the control
  5. Redo the CBA
A

Identify the ROI

23
Q
  1. Which of the following is a valid formula used to identify the projected benefits of a control?
  2. Loss after control - loss before control
  3. Loss before control - loss after control
  4. Cost of control + losses
  5. Cost of control /12
A

Loss before control - loss after control

24
Q
  1. A CBA can be used to justify the purchase of a control.

TRUE OR FALSE

A

TRUE