Larry Greenblatt Kung Fu Magic Flashcards
What are the new 8 domains in CISSP?
1) Security and Risk Management,
2) Asset Security,
3) Security Engineering,
4) Communications and Network Security,
5) Identity and Access Management,
6) Security Operations,
7) Security Assessment and testing,
8) Software Development Security
What are the 5 CMMI levels?
0) Non-existent,
1) Initial,
2) Repeatable
3) Defined
4) Quantitatively
5) Optimized
What are the SDLCs?
1) Project Initiation
2) Functional Requirements
3) System Design
4) Develop/Acquire
5) Installation/Implement
6) Operation
7) Retirement
Describe the Incident Response Life Cycle phases.
Preparation, Detection and analysis, Containment Eradication and Recovery, and Post-Incident Activity.
How does a gap analysis work?
Figure out where we need to be, figure out where we are, and then close the gap between those two positions.
What is ISO 27001
Requirements for Information Security Management Systems
What is ISO/IEC 15498 ?
The evaluation criteria for IT security. Called the “Common Criteria”
What are the three goals of Info Sec Governance and risk managemetn?
Confidentiality, Integrity, Availability
What are the three processes of Info Sec Governance and Risk management?
prevention, detection, and response.
What does the OECD (Organization for Economic Development)) help standardize?
International information exchange standards.
SO/IEC 27001:2005 covers what?
11 control categories. Controls can be audited against Outlines a management responsibility for security.
The information security officer is the quarterback of an company’s information security team.
They stay on top of security trends, identify weaknesses, communicate threats to higher levels, and coordinate between multiple departments to assess and improve an organizations security posture.
What is the 1st maturity level of CMMI?
Initial
What is the last maturity level of CMMI?
Optimized
What do policies dictate?
Policies dictate the “what”.
What is the most important feature of procedures?
That it works when followed.
What’s a baseline?
a reference point for unacceptable risk.