Quick Tips 2 Flashcards

1
Q

A BLANK, also called a safeguard or control, mitigates the risk.

A

countermeasure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A BLANK can be administrative, technical, or physical and can provide deterrent, preventive, detective, corrective, or recovery protection.

A

control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A BLANK is an alternate control that is put into place because of financial or business functionality reasons.

A

compensating control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

BLANK is a framework of control objectives and allows for IT governance.

A

CobiT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

BLANK is the standard for the establishment, implementation, control, and improvement of the information security management system.

A

ISO/IEC 27001

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The BLANK series were derived from BS 7799 and are international best practices on how to develop and maintain a security program.

A

ISO/IEC 27000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

BLANK are used to develop architectures for specific stakeholders and present information in views.

A

Enterprise architecture frameworks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An BLANK is a coherent set of policies, processes, and systems to manage risks to information assets as outlined in ISO\IEC 27001.

A

information security management system (ISMS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

BLANK is a subset of business architecture and a way to describe current and future security processes, systems, and subunits to ensure strategic alignment.

A

Enterprise security architecture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

BLANK are functional definitions for the integration of technology into business processes.

A

Blueprints

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

BLANK are used to build individual architectures that best map to individual organizational needs and business drivers.

A

Enterprise architecture frameworks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

BLANK is an enterprise architecture framework, and BLANK is a security enterprise architecture framework.

A

Zachman, SABSA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

BLANK is a governance model used to help prevent fraud within a corporate environment.

A

COSO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

BLANK is a set of best practices for IT service management.

A

ITIL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

BLANK is used to identify defects in processes so that the processes can be improved upon.

A

Six Sigma

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

BLANK is a maturity model that allows for processes to improve in an incremented and standard approach.

A

CMMI

17
Q

BLANK should tie in strategic alignment, business enablement, process enhancement, and security effectiveness.

A

Security enterprise architecture

18
Q

BLANK uses the following control categories: technical, management, and operational.

A

NIST 800-53

19
Q

BLANK is a team-oriented risk management methodology that employs workshops and is commonly used in the commercial sector.

A

OCTAVE

20
Q

Security management should work from the BLANK.

A

top down (from senior management down to the staff)