Security Frameworks And Controls Flashcards

1
Q

What is the purpose of security frameworks? List 4

A
  • Protecting PII
  • Securing financial info
  • Identifying security weaknesses
  • Managing organizational risks
  • Alligjing security with business goals
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

List the 4 core components of security frameworks (ISIM)

A
  1. Identify and document security goals
  2. Set guidelines to achive security goals
  3. Implent strong security processes
  4. Monitor and communicate results
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is security lifecycle?

A

A set of constantly evolving policies and standards regarding how an organization manages risks, follows established guidelines, and meets regulatory laws

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is NIST?

A

National Institute of Standards and Technology. It develops multiple voluntary compliance framework that are used worldwide yo help mitigate risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the CIA Triad?

A

A foundational model that helps inform how organizations consider risk when setting up systems and security policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does CIA stand for in this context?

A

Confidentiality, Integrity, Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Confidentiality in the CIA Triad

A

Only authorized users can access specific assets or data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Integrity in the CIA Triad

A

The data is correct, authentic and reliable.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Availability in the CIA Triad

A

Means the data is accessible to those authorized to access it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the NIST CSF?

A

A voluntary framework that consists of standards, guidelines, and best practices to manage Cybersecurity risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are ethics in Cybersecurity?

A

Guidelines put in place to make appropriate decisions as a Cybersecurity professional

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are ethical principles in Cybersecurity?

A
  • Confidentiality
  • Privacy protections
  • Adherance to the laws
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are PIIs?

A

Personally Identifiable Information.
Any information used to infer an individual’s identity like: name, and phone number

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are PIIs?

A

Personally Identifiable Information.
Any information used to infer an individual’s identity like: name, and phone number

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are SPII?

A

Sensitive Personally Identifiable Information.
A specific type of PII under stricter handling guidelines, including; Social security #s & credit card #s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly