Study 9: Ecommerce, International Shipping, and Cyber Security Flashcards

1
Q

Payment Application Data Security Standard (PA-DSS)

A
  • The global security standard for secure payment application software
  • Requirements put forth by PA-DSS help vendors develop software that does not store prohibited data, such as full magnetic strip data, card verification values, or personal identification number (PIN) data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Cyber Risk

A

Any kind of damage, disruption, or financial loss experienced by a company as a result of a failure in its computer systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

First-party coverage is available for the following costs related to a breach:

A
  • Investigation of the breach
  • Repair of digital records/assets
  • Legal advice on notification and regulatory obligations
  • Lost revenue
  • Extra expenses, such as hiring a PR firm to deal with public backlash over the breach and damage to the company’s reputation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Privacy Breach/Network Security Breach

A

The unauthorized collection, disclosure, use, access, destruction, or modification of personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Third-party coverage is available for the following costs related to a breach:

A
  • Financial damage to third parties (customers)
  • Legal costs to defend against third-party claims
  • Settlements, damages, and judgements
  • Regulatory fines and penalties, including fines issued by payment card companies (Visa or Mastercard)
  • Expenses incurred in responding to regulatory inquiries
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Marine Insurance

A

A form of insurance that covers loss or damage to ships, cargo, and terminals, as well as any goods or cargo in transit, and the liability arising out of the use, ownership, or operation of any of the foregoing.

Includes two general classes of risk: ocean marine and inland marine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Inland Marine Insurance

A

Coverage for moveable property in transit, excluding ocean crossings; includes bridges and tunnels, because they are implements of transportation

Applies to shipments by truck

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Ocean Cargo Insurance (aka Ocean Marine Insurance)

A

Insurance of ships and their cargoes and the various interests connected therewith

Applies to shipments transported by cargo ship

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

3 General Categories of Cyber Risk

A
  1. Deliberate and unauthorized breaches of security to access information systems for the purposes of destruction, espionage, extortion, or embarrassment of an organization, such as ransomware to lock businesses out of their system until they pay a ransom; malware, including viruses, worms, or spyware; and other online phishing scams
  2. Unintentional or accidental security breaches, such as losing a memory stick or a laptop or falling victim to social engineering attacks
  3. Operational IT risks, such as failing to install firewalls, keep security software up to date, or select passwords that are unique and difficult to decode
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Threat actors might target a company for 3 main reasons

A
  1. Corporate espionage (stealing trade secrets, possibly to sell to a competitor)
  2. To steal private data (which could include credit card numbers, personal data on employees or customers)
  3. To steal money (through extortion or directly from the company’s accounts)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Most common cyber risks companies are exposed to

A
  • hacking
  • ransomware
  • malware
  • insider threats
  • DoS attacks
  • phishing
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

First Party Cyber Exposures

A
  • Event expenses
  • Extortion expenses
  • Restoration expenses
  • Regulatory expenses
  • Business interruption
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Third Party Cyber Exposures

A
  • Privacy Breach
  • Internet Media Liability
  • Network Security Liability
  • Technology E&O
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Basics of a Cyber Policy

A
  • They are claims-made policies
  • There is a duty to defend
  • There needs to be a retroactive date
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Retroactive date

A

Refers to the date before which there is no coverage for claims.

A provision in some liability policies written on a claims-made basis that prohibits claims for incidents that happened prior to the stated date

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Full Prior Acts Coverage

A
  • Liability insurance coverage for claims arising from acts that occurred before the beginning of the policy period
  • Most policies for small to medium-sized enterprises are now offering this