Module 1 Flashcards

1
Q

Risk

A

Anything that can impact the confidentiality, integrity, or availability of an asset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Asset

A

An item perceived as having value to an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat

A

Any circumstance or event that can negatively impact assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Vulnerability

A

A weakness that can be exploited by a threat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Asset Management

A

The process of tracking assets and the risks that affect them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Asset Inventory

A

A catalog of assets that need to be protected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Asset Classification

A

The practice of labeling assets based on sensitivity and importance to an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Levels of Asset Classification

A

Public

Internal-only

Confidential

Restricted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Data

A

Information that is translated, processed, or stored by a computer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

States of Data

A

In use

In transit

At rest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Data in use

A

Data being accessed by one or more users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Data in transit

A

Data traveling from one point to another

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Data at rest

A

Data not currently being accessed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Information Security (InfoSec)

A

The practice of keeping data in all states away from unauthorized users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Types of risk categories

A

Damage

Disclosure

Loss of information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Elements of a security plan

A

Policies

Standards

Procedures

17
Q

Policy

A

A set of rules that reduces risk and protects information

18
Q

Standards

A

References that inform how to set policies

19
Q

Procedures

A

Step-by-step instructions to perform a specific security task

20
Q

Compliance

A

The process of adhering to internal standards and external regulations

21
Q

Regulations

A

Rules set by a government or other authority to control the way something is done

22
Q

NIST Cybersecurity Framework (CSF)

A

A voluntary framework that consists of standards, guidelines, and best practices to manage cybersecurity risk

23
Q

NIST CSF components

A

Core

Tiers

Profiles

24
Q

Five functions of the NIST CSF core

A

Identify

Protect

Detect

Respond

Recover