Quick Tips 4 Flashcards

1
Q

BLANK are documents that outline rules that are compulsory in nature and support the organization’s security policies.

A

Standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A BLANK is a minimum level of security.

A

baseline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

BLANK are recommendations and general approaches that provide advice and flexibility.

A

Guidelines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Job rotation is a BLANK control to detect fraud.

A

detective administrative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

BLANK are a detective administrative control type that can help detect fraudulent activities.

A

Mandatory vacations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

BLANK ensures no single person has total control over a critical activity or task. It is a preventative administrative control.

A

Separation of duties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

BLANK are two aspects of separation of duties.

A

Split knowledge and dual control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

BLANK specify the classification of data, and data custodians implement and maintain controls to enforce the set classification levels.

A

Data owners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Security has BLANK, which define the expected behavior from a product or system, and BLANK, which establish confidence in the implemented products or systems overall.

A

functional requirements, assurance requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

BLANK must define the scope and purpose of security management, provide support, appoint a security team, delegate responsibility, and review the team’s findings.

A

Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The BLANK should include individuals from different departments within the organization, not just technical personnel.

A

risk management team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

BLANK is a nontechnical attack carried out to manipulate a person into providing sensitive data to an unauthorized individual.

A

Social engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

BLANK is a collection of identity-based data that can be used in identity theft and financial fraud, and thus must be highly protected.

A

Personal identification information (PII)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

BLANK is a framework that provides oversight, accountability, and compliance.

A

Security governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

BLANK is an international standard for information security measurement management.

A

ISO/IEC 27004:2009

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

BLANK is a standard for performance measurement for information security.

A

NIST 800-55