ISC S1 Flashcards
What is the definition of Control 1: Inventory and Control of Enterprise Assets?
Track and manage all IT assets.
What is the definition of Control 2: Inventory and control of Software assets?
Allow authorized software.
What is the definition of Control 3: Data Protection?
Manage data life cycle.
What is the definition of Control 4: Secure Configuration of Assets and Software?
Secure configuation.
What is the definition of Control 5: Account Management?
Authorization for credentials.
What is the definition of Control 6: Access Control Management?.
Manage access credentials.
What is the definition of Control 7: Continuous Vulnerability Management?
Identify & track vulnerabilities/weak points.
What is the definition of Control 8: Audit Log Management?
Recover from attacks.
What is the definition of Control 9: Email and Web Browser Protection?
Protect & detect from Email and Web.
What is the definition of Control 10: Malware Defense?
Prevent or control bad software.
What is the definition of Control 11: Data Recovery?
Restore data pre-incident.
What is the definition of Control 12: Network Infrastructure Management?
Prevent attacks in vulnerable points.
What is the definition of Control 13: Network Monitoring and Defense?
Establish defense as security measure.
What is the definition of Control 14: Security Awareness and Skill Training?
Security mindset.
What is the definition of Control 15: Service Provider Management?
Competency in service providers.
What is the definition of Control 16: Software Security?
Implement before it’s needed.
What is the definition of Control 17: Incident Response Management?
Detect and response to attacks.
What is the definition of Control 18: Penetration Testing?
Simulate attacker to exploit vulnerabilities.
What are the objectives of the COBIT core model Evaluate, Direct and Monitor (EDM)?
Ensure:
1. Governance framework
2. Benefit delivery
3. Risk optimization
4. Resource optimizations
4. Stakeholder engagement
What are some of the 14 objectives of the COBIT core model Align, Plan, and Organize (APO)
Manage:
1. Strategy
2. Innovation
3. Portfolio
4. Risk
5. Data
What are the objectives of the COBIT core model Build, Acquire, and Implement (BAI)?
What are the objectives of the COBIT core model Deliver, Service, Support (DSS)?
Manage:
1. Operations
2. Service and incidents
3. Problems
4. Continuity
5. Security services
6. Business controls
What are the objectives of the COBIT core model Monitor, Evaluate, and Assess (MEA)?