Module 3 Flashcards
What are Security Frameworks?
Guidelines used for building plans to help mitigate risk and threats to data and privacy
What is the name for guidelines used for building plans to help mitigate risk and threats to data and privacy?
Security Frameworks
What is a Security Life Cycle?
A constantly evolving set of policies and standards that define how an organisation manages risks, follows established guidelines, and meets regulatory compliance or laws.
What is the name for a constantly evolving set of policies and standards that define how an organisation manages risks, follows established guidelines, and meets regulatory compliance or laws.
Security Life Cycle
What are the purposes of Security Frameworks?
- Protecting PII
- Securing financial information
- Identifying security weaknesses
- Managing organisational risks
- Aligning security with business goals
What are the Four Core Components of Frameworks?
- Identifying and documenting security goals
- Setting guidelines to achieve security goals
- Implementing strong security processes
- Monitoring and communicating results
What are Security Controls?
Safeguards designed to reduce specific security risks
What is the CIA Triad?
A foundational model that helps inform how organisations consider risk when setting up systems and security policies
What does the “CIA” in “CIA Triad” stand for?
Confidentiality. Integrity. Availability.
What is meant by Confidentiality?
Only authorised users can access specific assets or data
What is meant by Integrity?
Data is correct, authentic, and reliable
What is meant by Availability?
Data is accessible to those who are authorised to access it
What is an “Asset”?
An item perceived as having value to an organisation
What is the NIST Cybersecurity Framework (CSF)?
A voluntary framework that consists of standards, guidelines, and best practices to manage cybersecurity risk
What does NIST stand for?
National Institute of Standards and Technology
Why are disgruntled employees some of the most dangerous threat actors?
They often have access to sensitive information and know where to find it
What is the NIST?
A U.S-based agency that develops Compliance Frameworks that organisations worldwide can use to help manage risk.
What are two examples of NIST frameworks?
- NIST CSF (Cybersecurity Framework)
- NIST RMF (Risk Management Framework)
What are he Federal Energy Regulatory Commission - North American Electric Reliability Corporation (FERC-NERC)?
A regulation that applies to organisations that work with electricity or that are involved with the North American Power Grid.
What does “CIP” stand for?
Critical Infrastructure Protection
What does FERC stand for?
The Federal Energy Regulatory Commission
What does NERC stand for?
North American Electric Reliability Corporation
What does FedRAMP stand for?
The Federal Risk and Authorization Management Program
What is the Federal Risk and Authorization Management Program (FedRAMP) ?
U.S. government program that standardises security assessment, authorisation, monitoring, and handling of cloud services and product offerings