Security Frameworks Flashcards

1
Q

CIS

A

Center for Internet Security

To improve cyber defenses and to develop secure configuration postures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NIST RMF

A

National Institute of Standards
and Technology Risk
Management Framework

Mandatory for US Federal agencies and organizations that handle federal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CSF

A

Cybersecurity Framework

A set of guidelines and best practices for managing and reducing cybersecurity risks across all sectors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO 27001

A

International Organization
for Standardization 27001

Focuses on information security management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ISO 27002

A

International Organization
for Standardization 27002

Provides detailed guidance on information security controls for implementing the controls specified in ISO 27001

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ISO 27701

A

International Organization
for Standardization 27701

Focuses on protecting privacy rights and personal data within the context of an ISMS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ISO 31000

A

International Organization
for Standardization 31000

Focuses on risk management in general, not specifically on information security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SSAE SOC 2 Type I

A

Service Organization Controls Type I

A standard for auditing security controls

Evaluates controls’ suitability as of a specific date.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

SSAE SOC 2 Type II

A

Service Organization Controls Type II

A standard for auditing for security controls

Tests controls over a period of time, typically six months or more.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Cloud control matrix

A

Cloud control matrix
Framework developed by the Cloud Security Alliance (CSA)

Focuses on cloud-specific security controls and provides a structured approach to assessing and improving cloud security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

CSA

A

Cloud Security Alliance

A set of guidelines and best practices for managing and reducing cybersecurity risks across all sectors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly