Policies and Procedures Flashcards

1
Q

Agreement between two parties that defines what data is considered confidential and cannot be shared outside of the relationship

A

Non-Disclosure Agreement (NDA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A non-binding agreement between two or more organizations to detail an intended common line of action

A

Memorandum of Understanding (MOU)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

An agreement concerned with the ability to support and respond to problems within a given timeframe and continuing to provide the agreed upon level of service to the user

A

Service-Level Agreement (SLA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Conducted between two business partners that establishes the

conditions of their relationship

A

Business Partnership Agreement (BPA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Consensus-developed secure configuration guidelines for hardening (benchmarks) and prescriptive, prioritized, and simplified sets of cybersecurity best practices (configuration guides)

A

Center for Internet Security (CIS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A process that integrates security and risk management activities into the
system development life cycle through an approach to security control selection and specification that considers effectiveness, efficiency, and constraints due to applicable laws, directives, Executive Orders, policies, standards, or regulations

A

Risk Management Framework (RMF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A set of industry standards and best practices created by NIST to help
organizations manage cybersecurity risks

A

Cybersecurity Framework (CSF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A suite of reports produced during an audit which is used by service
organizations to issue validated reports of internal controls over those information systems to the users of those services

A

System and Organization Controls (SOC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly