S1 M1 Flashcards

1
Q

3 components to manage cybersecurity risk

A

Framework core
Implementation tiers
Framework profile

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Purpose of NIST CSF?

A

To identify, assess, and manage cybersecurity risks in a cost effective and repeatable manner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

5 CSF Core components

A

Identify
Protect
Detect
Respond
Recover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CSF Implementation Tiers

A

Tier 1 - partial (not integrated; ad hoc and situational risk management)
Tier 2 - risk informed (some are aware of risks, but not yet integrated; no action taken)
Tier 3 - repeatable (formal, documented policies, cybersecurity is implemented into planning)
Tier 4 - adaptive (Fully integrated and cybersecurity is prioritized)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

CSF Profiles

A

Current profile - current level of risk management
Target profile - Where you would like your risk management to be
Gap analysis - difference between current and target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Privacy framework core

A

Identify
Protect
Detect
Respond
Recover
Control
Communicate
Govern

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Difference between NIST security and privacy controls and NIST CSF and privacy framework

A

CSF and privacy framework are designed to manage cybersecurity risks in a cost effective manner, security and privacy controls are designed to protect against sophisticated threats. Must more detailed and stricter.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Three NIST SP control implementation approaches

A

Common - implementation at the organizational level
System-specific - Implementation at the information system level
Hybrid - combination based on appropriateness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly