Module 2 - 02-3 Flashcards

NIST frameworks

1
Q

What does NIST stand for?

A

National Institute of Standards and Technology (NIST)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does CSF stand for?

A

Cybersecurity Framework (CSF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does NIST CSF stand for?

A

National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)

A

A voluntary framework that consists of standards, guidelines, and best practices to manage cybersecurity risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What NIST CSF expands into the protection of the United States federal government?

A

NIST special publication, or S.P. 800-53

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Define NIST S.P. 800-53

A

A unified framework for protecting the security of information systems within the federal government

(including the systems provided by private companies for federal government use)

The security controls provided by this framework are used to maintain the CIA triad for those systems used by the government.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the five core functions of the NIST CSF?

A

1) Identify
2) Protect
3) Detect
4) Respond
5) Recover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do the five core functions of the NIST CSF help organizations?

A

These core functions help organizations manage cybersecurity risks, implement risk management strategies, and learn from previous mistakes.

They are key for making sure an organization is protected against potential threats, risks, and vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the first (1st) core function of the NIST CSF?

A

1) Identify

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Define Identify

A

The management of cybersecurity risk and its effect on an organization’s people and assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the second (2nd) core function of the NIST CSF?

A

2) Protect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define Protect

A

The strategy used to protect an organization through the implementation of policies, procedures, training, and tools that help mitigate cybersecurity threats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the third (3rd) core function of the NIST CSF?

A

3) Detect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Define Detect

A

Identifying potential security incidents and improving monitoring capabilities to increase the speed and efficiency of detections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the fourth (4th) core function of the NIST CSF?

A

4) Respond

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Define Respond

A

Making sure that the proper procedures are used to contain, neutralize, and analyze security incidents, and implement improvements to the security process

17
Q

What is the fifth (5th) core function of the NIST CSF?

A

5) Recover

18
Q

Define Recover

A

The process of returning affected systems back to normal operation

19
Q

What is the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)?

  • A required business framework for ensuring security updates and repairs are successful
  • Standards, guidelines, and best practices that organizations follow voluntarily in order to manage cybersecurity risk
  • A collection of security principles focused on maintaining confidentiality, integrity, and availability
  • A set of security controls that help analysts determine what to do if a data breach occurs
A

Standards, guidelines, and best practices that organizations follow voluntarily in order to manage cybersecurity risk

The NIST CSF is a voluntary framework that consists of standards, guidelines, and best practices to manage cybersecurity risk.

20
Q

The five core functions that make up the CSF are: identify, protect, detect, _____, and recover.

  • regulate
  • reevaluate
  • reflect
  • respond
A

respond

21
Q

The CSF _____ function relates to monitoring systems and devices in an organization’s internal network to help security teams manage potential cybersecurity risks and their effects.

  • respond
  • protect
  • identify
  • recover
A

identify

22
Q

What does a security analyst’s work involve during the CSF recover function?

  • Protect an organization through the implementation of employee training
  • Return affected systems back to normal operation
  • Pinpoint threats and improve monitoring capabilities
  • Contain, neutralize, and analyze security incidents
A

Return affected systems back to normal operation