Regulations Standards Framework Flashcards
What is NIST (National Institute of Standards and Technology)
SP 800-53?
- A standard that focuses on security and privacy.
- All US federal info systems MUST FOLLOW 800-53, EXCEPT FOR MILITARY / INTELLIGENCE.
- It is NOT MANDATORY to follow this standard
- This standard has 20 control families that must be implemented by federal agencies and their contractors
What is CIS?
- Center for Internet Security.
- It has 18 security controls.
- It’s an international organization of volunteers and organizations that share info about attacks and defensive actions.
What is CIA?
- Confidentiality, Integrity, and Availability.
- It is a cybersecurity model that focuses on DATA RECOVERY.
What is COBIT 2019?
- “Control Objectives for Information Technologies.”
- It is an IT governance framework.
- Based on 2 core concepts: Governance SYSTEM principles and governance FRAMEWORK principles.
- Governance SYSTEM principles describe the requirements of a governance system for IT.
- Governance FRAMEWORK principles are used to build a governance system.
COBIT 2019 GOVERNANCE FRAMEWORK principles
- Governance framework should be based on a conceptual model.
- Governance framework should be open and flexible.
- Governance framework should align to standards, framework, and regulations.
Under EU GDPR (General Data Protection Regulation), if there is a data breach, the controller must notify the appropriate SUPERVISORY AUTHORITY within
72 hours of noticing the incident.
EU GDPR 6 Principles
LOVE PUTS DOGS AT SOME INTEREST
1) Lawfulness, Fairness, Transparency
2) Purpose limitation
3) Data Minimization
4) Accuracy
5) Storage limitation
6) Integrity and confidentiality
Under EU GDPR, personal data can be:
Processed without a data subject’s consent when a controller must do so to comply with legal obligations
GDPR is an EU law that:
- Imposes rules on the processing of personal data of EU citizens.
- GDPR respects the rights of individuals to their personal data and ensures the free movement of data between EU member states.
- GDPR can apply to individuals/orgs outside the EU if they monitor the behavior of data subjects who live in the EU.
Applicability of the GDPR is not limited by
- Citizenship, company size, or location.
- The regulation’s protection extends to the personal data and privacy of all individuals residing in the EU.
According to the GDPR’s accuracy principle, what must be accurate?
Personal data. It also must be kept up to date.
What are automated discovery tools?
- They are tools that can find software within a network and determine its version.
What is the NIST (National Institute of Standards and Technology) cybersecurity framework (CSF)?
- It is a risk-based approach to cybersecurity assessment and decision making.
What are the 3 main parts of the NIST (National Institute of Standards and Technology) Cybersecurity Framework?
COME IN PLEASE
1) Core
2) Implementation Tiers (there are 4 tiers)
3) Profiles
What is the primary focus of implementation tiers under NIST (National Institute of Standards and Technology) CSF?
The sophistication of an entity’s cybersecurity risk management program.