Types of Assessments Flashcards
1
Q
Goal-Based Assessments
A
- specific goals are defined before testing starts
* tester may attempt to find many unique methods to achieve the specific goals
2
Q
Objective Based Assessments
A
- seek to ensure information remains secure
* testing occurs using all methods and more accurately simulates a real attack
3
Q
Compliance Based Assessment
A
- type of objective based assessment
- required to ensure policies or regulations are being followed properly
- regulations provide checklists
- focus on password policies, data isolation, limited network/storage access, and key management
4
Q
Premerger Assessment
A
- before two companies merge, identify weaknesses inherited, part of due diligence
5
Q
Supply Chain Assessment
A
- may be required by suppliers to ensure they are meeting cybersecurity requirements
- can be required prior to allowing interconnection between the suppliers systems and organizations systems
6
Q
Red Team Assessment
A
- conducted by internal testers of an organization during security exercise to ensure defenders (blue team) can perform their jobs adequately