ISC Deck 1 - multi-unit Flashcards
Which CIS principle considers the security life cycle of software to prevent, detect and remediate security weaknesses?
Application software security
Which regulatory framework empasizes explicit informed consent from individuals for data processing activities?
GDPR
What does HIPAA’s security rule require of covered entities?
Ensure the confidentiality, integrity and availability of all e-PHI they create, receive, maintain, or transmit.
The 6 COBIT 2019 governance system framework principles
- Meet stakeholder needs
- holistic approach
- dynamic governance system
- distinct governance from mgmt
- tailored to enterprise needs
- end to end governance system
What is Domain integrity?
The integrity constraint that ensures valid entries for a given column through data type restrictions.
What is the purpose of Boyce Codd normal form (BCNF) in the context of database design?
To prevent specific types of anomalies beyond the third normal form (3NF).
As defined in NIST SP 800-53 when should the risk management strategy exist?
It should exist at the organizational level to address concerns about assessments and determination of risk, security, and privacy requirements.
What SQL command is used to delete an existing table and all of its data?
DROP table
According to NIST SP 800-53 which organizational responsibility includes the consideration of requirements for security and privacy in light of organizational risks?
Risk management strategy
What is the purpose of an event in a business process model and notation diagram (BPMN)?
To indicate the flow of the process
Using profiles, the NIST Cybersecurity Framework assists an organization to align and prioritize its cybersecurity activities with each of the following:
1) business/mission requirements
2) risk tolerances
3) resources
NOT capability levels
What does a gateway represent in a business process model and notation diagram?
A decision point
Which of the NIST Privacy Framework functions is considered foundational for effecive use of the framework?
Identify-P
What is the purpose of a feedback loop in data integration process?
It allows for continuous improvement based on user input
Which GDPR principle is associated with controlling data?
Accountability