regulations, standards or frameworks. Flashcards
The _____ publishes the “20 CIS Controls.” _____ can be used to perform an overall evaluation of security posture.
Center for Internet Security (CIS)
The Risk Assessment Method (CIS-RAM)
Department of Defense Cyber Exchange provides _____ with hardening guidelines for a variety of software and hardware solutions.
Security Technical Implementation Guides (STIGs)
_____, by the National Institute of Standards and Technology (NIST), provides checklists and benchmarks for a variety of operating systems and applications.
National Checklist Program (NCP)
The ______ can be used with automated vulnerability scanners to test compliance against these benchmarks.
Center for Internet Security Configuration Access Tool (CIS-CAT)
The ______ is a set of 12 requirements aimed to ensure companies that process, store, or transmit credit card information maintain a secure environment.
Payment Card Data Security Standard (PC DSS)
The ______ mandates that medical facilities and patient representatives protect private health information of an individual.
Health Insurance Portability and Accountability Act of 1996 (HIPAA)
The ______ provides a security policy for how private sector organizations can assess and improve their ability to prevent, detect, and respond to cybersecurity attacks.
National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)
also maps to Cloud Security Alliance Cloud Controls Matrix (CSA CCM)
_____ frameworks are based on specific laws and regulations and ensure compliance of those standards. These _____ frameworks are highly-controlled and regulated
Regulatory
Medical records are governed by regulatory laws, for example.
The _____ Act mandates the implementation of risk assessments, internal controls, and audit procedures in the United States. It maps to CSA CCM.
Sarbanes-Oxley (SOX)
The _____ is an international standard for information technology security. It maps to CSA CCM.
International Organization for Standardization (ISO)
The _____ is an audit specification guide developed for accountants.
Statements on Standards for Attestation Engagements (SSAE)
The _____ states that personal data cannot be collected, processed, or retained without the individual’s informed consent.
European Union’s General Data Protection Regulation (GDPR)
The _____ is a federal law in the United States and is a vertical law for the financial sector.
Gramm–Leach–Bliley Act (GLBA)
The _____ defines the safe handling and storage of financial information.
Payment Card Industry Data Security Standard (PCI DSS)
A Service Organization Control (SOC) Type _ report addresses internal controls over financial reporting.
1