Week 1 Flashcards
What year was the first edition of the CBK created?
jpresuello
1992
When was CISSP certification created?
jpresuello
1994
When was ISC2 established?
jpresuello
1989
What is the meaning of CISSP?
jpresuello
Certified Information Systems Security Professional
What does ISC2 mean?
jpresuello
International Information Systems Security Certification Consortium
Is CISSP a VENDOR NEUTRAL CERTIFICATION?
jpresuello
Yes
How many domains are covered in CISSP?
jpresuello
8 domains
What are the 3 specific functional areas of CISSP?
jpresuello
Architecture, Engineering, Management
What are the 8 knowledge Domains of CISSP
jpresuello
Security and Risk Management, Asset Security, Security Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, Software Development Security
A documented set of your organization’s information security policies, procedures, tools, controls, guidelines, and standards.
jpresuello
Security Program
4 lifecycle of Security Program
jpresuello
- Plan & organize
- Implement
- Operate & Maintain
- Monitor & Evaluate
used to determine whether security is cost effective, relevant, timely and responsive to threats
jpresuello
Risk Analysis
Assign real and meaningful numbers (DOLLARS) to all elements of risk analysis process
jpresuello
Quantitative Risk Analysis
Rank the seriousness of the threats and the validity of the different possible countermeasures based on opinions
jpresuello
Qualitative Risk Analysis
An overall general statement produced by senior management that dictates what role security plays within the organization
jpresuello
Security Policy
Mandatory activities, actions or rules
jpresuello
Standards