Untitled Deck Flashcards

1
Q

CIA - Confidentiality - ISO/IEC 27000

A

Confidentiality: The property that information is not made available or disclosed to unauthorized individuals, entities, or processes (ISO/IEC 27000)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

CIA - Integrity - ISO/IEC 27000

A

Integrity: The property of accuracy and completeness (ISO/IEC 27000)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CIA - Availability - ISO/IEC 27000

A

Availability: The property of being accessible and usable upon demand by an authorized entity (ISO/IEC 27000)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Asset: Anything of Value to an organization - ISO/IEC 13335

3 Types of Assets are?

A
  1. Pure Information (in whatever format)
  2. Physical assets such as buildings or computer systems
  3. Software used to process or otherwise manage information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Threat, Vulnerability, Risk, and Impact -

Threat - ISO/IEC 27000

A

Threat: A potential cause of an unwanted incident, which may result in harm to a system or organization (ISO/IEC 27000)

Example - Storm clouds in sky - threat of rain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Threat, Vulnerability, Risk, and Impact

Vulnerability - ISO/IEC 27000

A

Vulnerability: A weakness of an asset or control that can be exploited by one or more threats (ISO/IEC 27000)

Example - Leave house without a coat or umbrella

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Threat, Vulnerability, Risk, and Impact

Risk - ISO/IEC 27000

A

Risk: The effect of uncertainty on objectives (ISO/IEC 27000)

Example - You could risk getting wet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Threat, Vulnerability, Risk, and Impact

Impact - ISO/IEC 13335

A

Impact: The result of an information security incident, caused by a threat, which affects assets (ISO/IEC 13335)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the purpose of Controls?

A

Controls in the IA sense are those activities that are taken to manage the risks identified: There are 4 main types of STRATEGIC controls (controls high-level made at executive level)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Strategic Controls - Eliminate - Risk Avoidance - ISO Guide 73

A

Eliminate. Risk Avoidance - Informed decision not to be involved in, or to withdraw from, an activity in order not to be exposed to a particular risk (ISO Guide 73)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Strategic Controls - Reduce - Risk Reduction - ISO 22300:2018

A

Reduce. Risk Reduction - Action taken to lesson the probability, negative consequences, or both, associated with a risk (ISO 22300:2018)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Strategic Controls - Transfer - Risk Transfer - ISO Guide 73

A

Transfer. Risk Transfer - A form of risk treatment involving the agreed distribution of risk with other parties (ISO Guide 73)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Strategic Controls - Accept - Risk Acceptance - ISO Guide 73

A

Accept. Risk Acceptance - The decision to accept the risk (ISO Guide 73)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Identity, Authentication, and Authorization

Identity - ISO/IEC 24760-1

A

Identity. Information that unambiguously distinguishes one entity from another one in a given domain (ISO/IEC 24760-1)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Identity, Authentication, and Authorization

Authentication - ISO/IEC 15944-6

A

Authentication. The provision of assurance of the claimed identity of an entity (ISO/IEC 15944-6)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Identity, Authentication, and Authorization

Authorisation - ISO/TR 22100-4

A

Authorisation. The right or permission that is granted to a system entity to access a system resource (ISO/TR 22100-4)

17
Q

Accountability, audit, and compliance

Accountability - ISO/IEC 21827

A

Accountability. The property that ensures that the actions of an entity can be traced uniquely to the entity (ISO/IEC 21827)

18
Q

Accountability, audit, and compliance

Audit - ISO 15638-5

A

Audit. The review of a party’s capacity to meet, or continue to meet, the initial and ongoing approval agreements as a service provider (ISO 15638-5)

19
Q

Accountability, audit, and compliance

Compliance - ISO/TR 19591

A

Compliance. Meeting or exceeding all applicable requirements of a standard or other published set of requirements (ISO/TR 19591)

20
Q

Information Security Management System (ISMS) - ISO 12812-2

A

Information Security Management System (ISMS). Part of the overall management system, based on a business risk approach, used to establish, implement, operate, monitor, review, maintain and improve information security (ISO 12812-2)

21
Q

What is Information Security - ISO 19092

A

Information Security - Preservation of confidentiality, integrity, and availability of information; in addition, other properties such as authenticity, accountability, no-repudiation and reliability can also be involved (ISO 19092)

22
Q

What is Information Assurance

A

Information Assurance (IA) - The confidence that information systems will protect the information they carry and will function as they need to, when they need to, under the control of legitimate users.

23
Q

What is Defense in Breadth

A

Defense in Breadth - All connected systems must now be taken into account when considering how an attack might materialize and the effect it might have.

24
Q

What is Defense in Depth

A

Defense in Depth - Layer of security which may start off as relatively low level, but which increase in complexity, cost and effectiveness as the information and systems being protected get more sensitive and important.