IT Security Framework Flashcards
What do we use IT Security Frameworks for?
As a basis for out policies, procedures, and standards.
Who makes the consensus-developed secure configuration guidelines for hardening, prescriptive, prioritized, and “simplified” cybersecurity best practices?
Center for Internet Security (CIS)
What framework integrates security and risk management into the development life cycle?
Risk Management Framework (RMF)
Exam Tip: Made by NIST, used by federal government
What set of industry standards and best practices is created by NIST to help manage cybersecurity risks?
Cybersecurity Framework (CSF)
What international standard details requirements for establishing, implementing, and maintaining a continually improving Information Security Management System (ISMS)?
ISO 27001
Note: Information Systems
Note: This is a basic procedure for cyber security and is an international standard
What international standard provides best practice recommendations for controls on Information Security Management Systems?
ISO 27002
Note: Controls to protect Information Systems
What international standard acts as a privacy extension for ISO 27001?
ISO 27701
Note: Privacy for Information Systems
What international standard regards risk management?
ISO 31000
Note: Risk Management
What is the audit performed in conjunction with using controls such as NIST?
System and Organization Controls (SOC)
What standard is based on the following Trust Services Criteria: security, availability, processing integrity, confidentiality, privacy?
SOC 2
Note: Expect to see SOC 2 on exam.
What audit addresses the operational effectiveness of the security controls implemented over a specified amount of time.
SOC 2 Type II
Note: It’s just checking how effective your implementation of the security controls are.
What security framework addresses cloud security for vendors and customers?
Cloud Security Alliance’s Cloud Control Matrix
What methodology and set of tools do we use as a reference for cloud security?
Cloud Security Alliance’s Reference Architecture