standards Flashcards

1
Q

What are the 4 ISS Practitioner frameworks?

A

1) ISO/IEC 27001:2005 and ISO/IEC 27002:2005 and NIST 800
2) CISSP Body of Knowledge
3) GBDEM Guidance for Boards of Directors and Executive management
4) GAISP Generally Accepted information system security practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO 27001 and 27002 define ISMS. What is ISMS? What are ISMS’s 11 practices?

A

Information Security Management System.

1) Security policy
2) Organization of information security
3) Asset management
4) Human resources security
5) Physical and environmental security
6) Communications and operations management
7) Access Control
8) Information systems acquisition, development, and maintenance.
9) Information Security Incident Management
10) Business continuity management
11) Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 7 safe harbor principles of the EU General Data Protection Directive (GDPR)? What has the safe harbor replaced by?

A

1) Notice
2) Choice
3) Onward Transfer
4) Security
5) Data Integrity
6) Access
7) Enforcement

The safe harbor principles were replaced by the EU-US Privacy Shield.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who uses the NIST 800 series?

A

The NIST 800 series are used by the US federal government for computer security policy, procedures, and guidelines. They are also widely used within the private security industry.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly