Reference Models Flashcards

1
Q

What are the (5) Cloud Reference Model standards?

Reference Models … (5)

A
NIST Cloud Compute Ref
IBM Cloud Ref Architecture
ISO/IEDC 17789:2014 Ref Architecture
Open Group Cloud Eco Sys Ref Model
Microsoft Private Cloud Ref Model
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

InfoSec IS Mgmt includes (5) CIANA

A

Confidentiality – Encrypt/hide info for unauthorized access
Integrity – Protect from modification/deletion
Availability – Accessible to authorized users
Non-Repudiation – Cant deny actions
Authentication – Prove identity to access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security Mgmt means?

___ & ____ for securing Mgmt

A

Policy & Procedures for securing & mgmt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Security Mgmt = (3)
_____ Mgmt
Security _________
_____

A

RISK MGMT
SECURITY Assessmt
Calculated Return on Investmt (ROI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Finish the equation: RISK = (3)

Risk = ____ X ____ X _____

A

RISK = Asset x Threat x Vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an example of Threat? (4)

A

Angry Employee, Hacker, Malware, Rogue Software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an example of Vulnerability? (5)

A

SW bugs, Broken process, Bad Cntl, HW malfunction, Human error

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is example of Risk: (5)

A

Fin loss, privacy loss, reputation damage, legal penalties, Business disruption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When you hear Security Assessment, you should think of this word?

A

AUDIT!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do you address a Security GAP? (3) choices

A
  1. (DENY) Cancel Project
  2. (Allocate) necessary resources to correct sec gaps
  3. (Accept) RISK
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are (6) Data Sec Standards?

A

ISO 27001 – (FISMA) Establish, implement maintain ISMS
ISO 27017 – (Cloud Security) IT Sec/IS Cntl for Cloud
customers and providers
ISO 27018 – (PII) Protection in Cloud –How to protect PII
(PII – Cloud)
ISO 27036 – (Info Risk of Goods/Svcs – Cloud)Supplier
relationships – Overview, Requirements,
ICT Supply chain, Sec, Cloud Svcs
NIST 800-144 (NIST) Guidelines Sec / Privacy in Public
Cloud (NIST Sec/Policy – Cloud)
PCI-DSS – (Payment card Industry) – Data Sec Std- Sec
Assessment Procedure / Cloud Guidelines (Paymt
card Cloud Stds)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
Name the (6) Data Standards:
ISO 27001 
ISO 27017 
ISO 27018
ISO 27036
NIST 800-144
PCI-DSS
A

ISO 27001 FISMA
ISO 27017 IT Sec / IS Control Cloud Customer/providers
ISO 27018 PII - Cloud
ISO 27036 Supplier relationships in Cloud, Svc, Risk
NIST 800-144 NIST Sec / Policy Cloud
PCI-DSS Paymt card Cloud standards and guidelines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the International Data Protections? (3) categories

A
  1. EU – US Privacy Shield – protects Europeans basic
    right when data is transferred to US
  2. USA Patriot ACT – US Law
    FISA Foreign Intel Survellience Act
    ECPA Electronic Communication Privacy Act
    Money Laundering Control Act
    Bank Secrecy Act
    Immigration National Act
  3. PRISM surveillance data mining program used by
    NSA / British Govt
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Is Safe Harbor applicable to cloud svc provider agreements?

A

Yes. Safe Harbor & Commission’s adequacy decision apply to such agreements that involve the transfer of personal data from the EU to org established in US

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is SAFE HARBOR?

EU – US.

A

European Commission Directive on Data Protection. Oct 1998. Prohibits transfer of personal data to non-European Union countries that don’t meet the (EU) European Union adequacy standard for privacy protection. US & EU share goal. Must join program to participate!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly