Lecture 3 Flashcards
What is a policy in the context of vulnerability management?
A high-level statement from top management.
It reflects intent and direction
Examples include Acceptable Use Policy (AUP), Email policies, Internet Usage policies.
What is the purpose of a standard?
An acceptable level of quality
Example: ISO 27001.
Define a procedure.
A series of detailed steps to be followed for accomplishing a particular task
Related to Standard Operating Procedures (SOP).
What does a guideline provide?
Additional recommendations or suggestions for security
What is the significance of ITSG-33?
It’s the Canadian equivalent to NIST 800-53
It is Canada’s Information Technology Security Guidance Publication
What does PCI/DSS apply to?
Any organization that processes payment cards, such as VISA
It focuses on protecting cardholder data.
What is GAP Analysis?
Finding the gap between an organization’s security systems and those recommended by a framework.
List the NIST Framework Core Functions.
- Identify
- Protect
- Detect
- Respond
- Recover
What are the three classes of security controls according to NIST?
- Technical
- Operational/Administrative
- Management
True or False: Guidelines are mandatory to follow.
False
Guidelines provide optional guidance based on best practices.