Vocabulary Flashcards

1
Q

NIST

A

National Institute of Standards and Technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

FISMA

A

Federal Information System Modernization Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does NIST provide?

A

Standards of Operations and Guidelines

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does FISMA provide?

A

Policy and Procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ISSO

A

Information System Security Officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SCA

A

Security Control Assessor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Methodology

A

A schedule or time frame

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Vulnerability

A

A weakness or flaw

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Risk

A

A chance or choice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A.O.

A

Authorizing Official

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

ATO

A

Authorization to Operate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Remediate

A

To fix

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SME

A

Subject Matter Expert

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Artifact

A

Proof or source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Threat

A

Anything that tries to exploit a vulnerability or cause harm to a system or organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ST&E

A

System Test and Evaluation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

CIO

A

Chief Information Officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

CISO

A

Chief Information Security Officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Discrepancy

A

Mistake or error

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Scrub

A

To look for

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

PM
(SME)

A

Project Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

High Water Mark

A

The highest or most reoccurring security impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

CAT

A

Control Allocation Table

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

RTM

A

Required Traceable Matrix

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

POA&M

A

Plan of Action and Milestone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

SAP

A

Security Assessment Plan

27
Q

SAR

A

Security Assessment Report

28
Q

RAR

A

Risk Assessment Report

29
Q

SCTM

A

Security Control Traceable Matrix

30
Q

Security Control

A

Something that modifies or reduces one or more security risks

31
Q

System

A

Computer

32
Q

B.O.E.

A

Body of Evidence

33
Q

SSP

A

System Security Plan

34
Q

C.I.A.

A

Confidentiality, Integrity, Availability

35
Q

PII

A

Personally Identifiable Information

36
Q

PKI

A

Public Key Infrastructure

37
Q

ISO

A

International Organization for Standardization

38
Q

IEC

A

International Electrotechnical Commission

39
Q

CDS

A

Cross Domain Solution

40
Q

IC

A

Intelligent Control (Intelligence Community)

41
Q

NIST-800-30

A

Conducting Risk Assessements

42
Q

NIST-800-37

A

RMF 1-7

43
Q

NIST-800-39

A

Managing Risk

44
Q

NIST-800-18

A

How to develop an SSP (Creation of the SSP)

45
Q

GSS

A

General Support System

46
Q

Confidentiality

A

The state of keeping a secret or private

47
Q

Integrity

A

Seeking to prevent the unauthorized modification, use, and destruction of information or data

48
Q

Availability

A

Ensure timely and reliable access and use of information

49
Q

FIPS

A

Federal Information Processing Standards

50
Q

FIPS-199

A

The security categorization of Federal systems and the second step in RMF Categorization.

51
Q

NIST-800-53

A

Information Types

52
Q

NIST-800-53A

A

Data

53
Q

NIST-800-53B

A

Baseline controls for REV5

54
Q

NIST-800-60

A

Mapping

55
Q

NIST Special Publication 200

A

Basic Controls

56
Q

DHS Sensitive System Policy Directive 4300A

A

Directive used if you need overlays, privacy controls, or cross domain solutions

57
Q

ISO/IEC 27001 & 27002

A

Communication

58
Q

CNSS-1253

A

Committee on National Security Systems (Military)

59
Q

PDF

A

Formal Written Direction

60
Q

URL

A

Web site

61
Q

Screen Shot

A

Real time picture with date and time stamp

62
Q

Test the control

A

To observe something is working properly

63
Q

Interview

A

To speak with someone to get an explanation or better understanding of the control function.

64
Q

Examine

A

Physically review the control documentation.