ISC 1 - Regulations, Standards, & Frameworks Flashcards
What is NIST?
National Institute of Standards and Technology
What are the core functions of the NIST Privacy Framework?
Communicate
Govern
Identify
Control
Protect
Detect
Respond
Recover
What is the protect function of NIST composed of?
1-data protection policies, processes, and procedures
2- identity management, authentications, and access control
3 - data security
4 - data maintenance
5 - protective technology
What is the control function of NIST composed of?
1- data processing policies, processes, and procedures
2 - data processing management
3 - disassociated processing
What is the identity function of NIST composed of?
1- inventory and mapping
2 - business environment
3 - risk assessment
4 - data processing ecosystem risk management
What is the govern function of NIST composed of?
1 - governance policies, processes, and procedures
2- risk management strategy
3- awareness and training
4 - monitoring review
What are the four implementation tiers?
Partial
Risk-Informed
Repeatable
Adaptive
What are the two framework profiles?
Current and target
What is the Health Insurance and Portability Act (HIPAA)?
A business that handles protected health information (PHI) via transmission of health information
What is the GDPR?
General Data Protection Regulation; For companies located in the EU, the scope of GDPR applies to data processing organizations.
CIS - What is the Inventory and Control of Enterprise Assets?
Actively manage all enterprise assets connected to the infrastructure to accurately know all assets that need to be monitored and protected
CIS - What is Inventory and Control of Software Assets?
Actively manage (inv, track, and correct) all software on the network so that only authorized software is installed and executed. Unauthorized and unmanaged software is found and prevented from installation and execution
CIS - What is Data Protection?
Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data
CIS - What is Secure Configuration of Enterprise Assets and Software?
Establish and maintain the secure configuration of enterprise assets and software
CIS - What is Account Management?
Assign and manage authorization to credentials for user, admin, and service accounts