standards Flashcards
What are the 4 ISS Practitioner frameworks?
1) ISO/IEC 27001:2005 and ISO/IEC 27002:2005 and NIST 800
2) CISSP Body of Knowledge
3) GBDEM Guidance for Boards of Directors and Executive management
4) GAISP Generally Accepted information system security practices
ISO 27001 and 27002 define ISMS. What is ISMS? What are ISMS’s 11 practices?
Information Security Management System.
1) Security policy
2) Organization of information security
3) Asset management
4) Human resources security
5) Physical and environmental security
6) Communications and operations management
7) Access Control
8) Information systems acquisition, development, and maintenance.
9) Information Security Incident Management
10) Business continuity management
11) Compliance
What are the 7 safe harbor principles of the EU General Data Protection Directive (GDPR)? What has the safe harbor replaced by?
1) Notice
2) Choice
3) Onward Transfer
4) Security
5) Data Integrity
6) Access
7) Enforcement
The safe harbor principles were replaced by the EU-US Privacy Shield.
Who uses the NIST 800 series?
The NIST 800 series are used by the US federal government for computer security policy, procedures, and guidelines. They are also widely used within the private security industry.