Policies and Procedures Flashcards
Agreement between two parties that defines what data is considered confidential and cannot be shared outside of the relationship
Non-Disclosure Agreement (NDA)
A non-binding agreement between two or more organizations to detail an intended common line of action
Memorandum of Understanding (MOU)
An agreement concerned with the ability to support and respond to problems within a given timeframe and continuing to provide the agreed upon level of service to the user
Service-Level Agreement (SLA)
Conducted between two business partners that establishes the
conditions of their relationship
Business Partnership Agreement (BPA)
Consensus-developed secure configuration guidelines for hardening (benchmarks) and prescriptive, prioritized, and simplified sets of cybersecurity best practices (configuration guides)
Center for Internet Security (CIS)
A process that integrates security and risk management activities into the
system development life cycle through an approach to security control selection and specification that considers effectiveness, efficiency, and constraints due to applicable laws, directives, Executive Orders, policies, standards, or regulations
Risk Management Framework (RMF)
A set of industry standards and best practices created by NIST to help
organizations manage cybersecurity risks
Cybersecurity Framework (CSF)
A suite of reports produced during an audit which is used by service
organizations to issue validated reports of internal controls over those information systems to the users of those services
System and Organization Controls (SOC)