MOD 8 - Midterm Flashcards
What do the letters in the CIA triad stand for?
Confidentiality
Integrity
Availability
What is confidentiality?
Concept of measures used to ensure the protection of the secrecy of data, objects or resources
What is integrity?
The concept of protecting the reliability and correctness of data. prevents unauthorized altercations of data.
What is Availability?
Authorized subjects are granted timely and uninterrupted access to objects.
Name the AAA services.
Identification
Authentication
Authorization
Auditing
Accounting(Accountability)
What are the types of security plans in security governance
What is the minimum level of security?
Baseline
Due dilligence
Establishing a plan, policy and process to protect the interest of an organization, knowing what should be done and planning for it.
Due care
practicing the individual activities that maintain the due diligence effort, doing the right action at the right time.
Separation of duties
Making sure duties are split from each other so things get done ; protects from fraud.
Job rotation
Making sure multiple people know how to do the same job and you are forcefully rotated into this position; protects against fraud.
What is SLA?
Service Level Agreement
An agreement established ahead of time that ensures organizations providing services to internal and/or external customers maintain an appropriate level of service agreed on by both the service provider and the vendor.
What is security governance
The collection of practices related to supporting, defining and directing the security efforts of an organization.
What is risk assessment?
A detailed process of identifying factors that could damage or disclose data, evaluating those factors in light of data value and countermeasure cost, and implementing cost-effective solutions for mitigating or reducing risk.
What is vulnerability?
Weakness in asset or the absence or the weakness of a safeguard or countermeasure.
What are the types of risk analysis?
Qualitative - Rank threats on a scale to evaluate their risks, costs and effects
Quantitative - Inventory assets and assign a value (money)
What are the risk responses?
Reduce/Mitigate
Assign/Transfer
Accept
Deter
Avoid
Reject/Ignore
What is exposure?
The amount of damage done to an asset if the risk manifests.
What is asset value?
How much something costs. Dollar amount of the asset.
What is BCP?
Business Continuity Planning
Involves assessing risks to organizational processes and creating policies, plans and procedures to minimize the impact those risks might have on the organization if they were to occur.
What is shoulder surfing?
Looking over someone shoulder to get their information
What are the 4 steps of BCP?
Project planning and scope
Business impact analysis
Continuity planning
Approval and implementation
What are the two types of threats?
Natural
Person made/Man made
Why is BCP used?
To reduce the impact of a realized risk on organization.
What is the main formula for SLE?
SLE (Single loss expectancy) = Asset value * Exposure Factor
What is the formula for ALE?
ALE = SLE * ARO
What is ARO?
Annualized rate of occurrence (number of times per year)
In the scope of BIA, what is MTD?
Maximum tolerable downtime
The amount of time a business can be inoperable.
What is RTO?
Recovery time objective
The amount of time it takes for a business to recover.
What is PHI?
Protected Health Information
Health information that relates to an individual.
What is proprietary data?
It gives competitive advantage
What are the government data classification?
Top secret
Secret
Confidential
Unclassified
For official use only
Sensitive but unclassified