Security Frameworks and Controls Flashcards

1
Q

What are security frameworks?

A

Guidelines used for building plans to help mitigate risk and threats to data and privacy. They help organizations adhere to compliance laws and regulations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are security controls?

A

Safeguards designed to reduce specific security risks. They are measures organizations use to lower risk and threats to data and privacy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the Cyber Threat Framework (CTF)?

A

A U.S. government framework that provides a common language for describing and communicating information about cyber threat activity, helping professionals analyze and share information efficiently.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is ISO/IEC 27001?

A

An international framework that enables organizations to manage the security of assets like financial information, intellectual property, employee data, and information entrusted to third parties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are physical controls? Give examples.

A

Security measures you can physically touch:

  • Gates, fences, and locks
  • Security guards
  • CCTV and surveillance cameras
  • Access cards or badges
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are technical controls? Give examples.

A

Technology-based security measures:

  • Firewalls
  • Multi-factor authentication (MFA)
  • Antivirus software
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are administrative controls? Give examples.

A

Procedural security measures:

  • Separation of duties
  • Authorization
  • Asset classification
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do controls relate to security goals?

A

Controls are used alongside frameworks to:

  • Prevent security issues
  • Detect security issues
  • Correct security issues
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is an example of how frameworks and controls work together?

A

In healthcare, organizations use frameworks to comply with HIPAA, while implementing specific controls like MFA to protect patient medical records.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly