Risk Management Concepts Flashcards

1
Q

Risk Management Concepts

provide guidance on identifying and managing risk

A

Risk Management Frameworks (RMFs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Risk Management Concepts

Security regulations and standards designed to protect sensitive data

A

GDPR

HIPAA

PCI DSS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Risk Management Concepts

Security policies designed to protect assets

A

Org security policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Risk Management Concepts

-Acceptable use policy (AUP)
- email, social media, web browsing

  • Resource access policies
    • app or file access
  • Account policies
    • hardening

-Data Retention Policies
- often dictated by regs

  • asset management policies
A

Types of security policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk Management Concepts

Data Privacy Regs and Stds

protects EU citizen’s private data

A

General Data Protection Regulation (GDPR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Risk Management Concepts

RMF

cybersecurity best practices

A

Center for Internet Security (CIS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Risk Management Concepts

Data Privacy Regs and Stds

protect American patient medical info

A

Health Insurance Portability and Accountability Act (HIPAA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Risk Management Concepts

RMF

Cybersecurity risk management

A

NIST RMF

Cybersecurity Framework (CSF)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Risk Management Concepts

RMF

IT and info security
- 27001
- 27002
- 27701
- 31000

A

International Organization for Standardization/International Electrotechnical Commission (ISO/IEC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Risk Management Concepts

RMF

  • Financial statements integrity
  • internal controls
  • Type I and Type II
A

Statement on Standards for Attestation Engagements System and Organization Controls (SSAE SOC 2)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Risk Management Concepts

RMF

Guidance for Conducting Risk Assessments

A

https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Risk Management Concepts

Access control vestibules (mantraps)

Server room access

Limit USB bootable devices

A

Physical Risk Vectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk Management Concepts

  • Mission-critical IT systems
  • Payment processing
  • HR
  • Emergency
  • Sensitive data
    • do we know what we have and where it is?
  • Third-party access
A

Risk Vectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly