Security Principles Flashcards

1
Q

Risk Identification:

A

Involves identifying different possible risks, characterizing them and then estimating their potential for disrupting the organization.  

Takeaways to remember about risk identification:

  • Identify risk to communicate it clearly.
  • Employees at all levels of the organization are responsible for identifying risk.
  • Identify risk to protect against it.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Risk Assessment:

A

The process of identifying and analyzing risks to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals and other organizations.

The analysis
performed as part of risk management which incorporates threat and vulnerability analyses and
considers mitigations provided by security controls planned or in place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Risk Treatment:

A

The determination of the best way to address an identified risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Qualitative Risk Analysis:

A

A method for risk analysis that is based on the assignment of a descriptor such as low, medium or
high

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Quantitative Risk Analysis:

A

A method for risk analysis where numerical values are assigned to both impact and likelihood
based on statistical probabilities and monetarized valuation of loss or gain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The Healthcare Insurance Portability and Accountability Act of 1996 (HIPAA) is…

A

“…a federal law in the United States that requires certain actions be taken to protect health information. Many organizations use published frameworks, or standards, to guide the organizational policies that support the compliance effort. Many departments or workgroups within the organization implement procedures that detail how they complete day-to-day tasks while remaining compliant.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ISC2 Code of Ethics Preamble:

A

The Preamble states the purpose and intent of the ISC2 Code of Ethics.

The safety and welfare of society and the common good, duty to our principals, and to each other, requires that we adhere, and be seen to adhere, to the highest ethical standards of behavior.
Therefore, strict adherence to this Code is a condition of certification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

ISC2 Code of Ethics Cannons:

A

The Canons represent the important beliefs held in common by the members of ISC2. Cybersecurity professionals who are members of ISC2 have a duty to the following four entities in the Canons.

Protect society, the common good, necessary public trust and confidence, and the infrastructure.
Act honorably, honestly, justly, responsibly and legally.
Provide diligent and competent service to principals.
Advance and protect the profession.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly