Lecture 4-2 Flashcards
1
Q
What is the recommended time frame for conducting vulnerability assessments?
A
Critical assets: every 6 months
Non-critical assets: every 1 year
2
Q
A Vulnerability Assessment test plan: Name the first 5 sections.
A
- Overview
- Purpose
- Regulations/Laws/Standards
- Scope
- Type of test
3
Q
A Vulnerability Assessment test plan: Name the second 4 sections.
A
- Timeline and tasks
- Rule of engagement
- Stakeholders list
- Liabilities
4
Q
What is Data Governance (DG)?
A
The process of managing information over its life cycle from creation to destruction
5
Q
List the levels of data classification used in our lab (5).
A
- Public Data
- Private Data
- Restricted Data
- Sensitive Data
- Top Secret Data
6
Q
True or False: Non-critical assets are always ignored in vulnerability assessments.
A
False