Module 3 - Information Security Flashcards

1
Q

What are the 3 values of the CIA Triad?

A

Confidentiality, Integrity and Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Confidentiality?

A

Property that information is not made available or disclosed to unauthorised individuals, entities or processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Integrity?

A

Property of accuracy and completeness, hasn’t been tampered with or missing info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Availability?

A

Property of being accessible and usable upon demand by an authorised entity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the difference between Cyber Security and Information Security?

A

Cyber security focuses on protecting digital assets, Information Security aims to protect all information assets include non-digital hard copies etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are Certification Bodies?

A

Bodies that are authorised to certify other orgs ISO accreditation.

Certification Bodies are themselves certified by National Accreditation Bodies to carry out ISO audit/certification etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is required to become ISO 27001 certified?

A

Org must demonstrate conformity to the ISO 27001 Standard by undergoing external auditing from a Certification Body to verify

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the two stages of an ISO 27001 audit?

A

Stage 1 – Intent Audit

Stage 2 – Implementation Audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is reviewed during an Intent Audit?

A

Examines ISMS for compliances with ISO 27001, it looks at:

  • Policy
  • Scope
  • Risk Assessment
  • Risk Management
  • Selection of controls
  • SoA
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is reviewed during an Implementation Audit?

A
  • Examine and close findings from Stage 1
  • Audit sample to verify implementation of ISMS
  • Auditor highlights and major and minor non-conformities
  • Corrective action is required within 3 months
  • Major non-conformities will need to be evidenced as addressed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How long will an org have to correct non-conformities highlighted during a Stage 2 audit?

A

3 months

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How often will surveillance by a Certification Body continue after an org has been certified?

A

Usually annually or 6 months

How well did you know this?
1
Not at all
2
3
4
5
Perfectly