Regulations, standards, and frameworks Flashcards

1
Q

What is the ISO 27701?

A

Provides specific requirements and guidance for establishing, implementing, maintaining and constantly improving an information system with private data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is ISO 31000

A

A risk management framework that assists an organization in integrating risk management into day to day functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is ISO 27001

A

A standard that sets out the best practice specification for an information system. The guides information security by addressing people and processes as well as technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is ISO 27002?

A

A supplementary standard that focuses on the info security controls that organizations might choose to implement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the Cloud security alliance cloud controls matrix (CSA CCM)?

A

A framework that provides guidance in security domains, including application security, identify and access management, mobile security, encryption and key management, and data center operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What the national institute of standards and technology and technology (NIST) Cyber security framework (CSF)

A

A security policy for how private sector organizations can assess and improve their ability to prevent, detect, and respond to cybersecurity attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The Statements on Standards for Attestation Engagements (SSAE)

A

Is an audit specification guide developed for accountants

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a clean desk policy?

A

AN employers work area should be free from any documents or information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a fair use (acceptable use) policy?

A

Defines what someone is allowed to use a particular service or resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a Standard Operating Procedure (SOP)?

A

Is a documented list of steps or actions used to perform a task to a specified and expected standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a Non-disclosure agreement?

A

A legal basis for protecting info assests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is End of Life (EOL)?

A

When a product will no longer prudced or sold

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is End of service life (EOSL)?

A

Describes when a vendor will no longer support a product. as well as updates and patches will no longer be produced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the annual rate of occurrence (ARO)

A

Indicates how many times a loss will occur within a year

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a legacy system?

A

An outdated computing software OR HARDWARE THAT IS STILL IN USE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a workflow

A

An onboarding process that involves identifying the roles and permissions users need

17
Q

What is Offboarding?

A

Process by which accounts are dleeted or disabled

18
Q

What is User Account control (UAC)?

A

A windows-specific function that prevents users from permission to a resource for the duration of a specific authorization

19
Q

What is privilege bracketing

A

An account management practice that involves giving users permission to a resource for the duration of a specific project or a need-to-know situation

20
Q

What is a Service Level Agreement?

A

A contractual agreement setting out detailed terms for future provided services

21
Q

What is a Business Partners Agreement?

A

A partner agreement type that large IT companies, such as Microsoft and Cisco, set up with resellers and solution providers

22
Q

What is a Interconnection Security Agreement (ISA)?

A

used when any federal agency interconnecting its IT system to a third part

23
Q

What ia User Training

A

Teaches users new functionality, as well as proper policies and procedures for both the company and the software

24
Q

What is Vendor-specific guides

A

Instructions on how to install and securely configure hardware and software, specifically for a certain vendor

25
Q

What is General Purpose gudies

A

Help increase security in hardware and software by providing instructions to configuring a system based on roles and appliances

26
Q

What is Change Management?

A

A process that involves the prevention of unauthorized changes to a system

27
Q

Why is the Sarbanes-Oxley (SOX) act?

A

An act that helps investors from fraudulent financial reporting by large corporations