/
My Flashcards
Save to my account
Sign up
My Flashcards
Flashcard Deck
Study
1
Question
an organization's most valuable assets:
Answer
information and systems
2
Question
Types of Private Information
Answer
- personally identifiable information - business information
3
Question
examples of personally identifiable information
Answer
- social security - credit card - bank account numbers
4
Question
examples of business information
Answer
- financial data - employee records - trade secrets
5
Question
Security Triad
Answer
- Confidentiality - Integrity - Availability
6
Question
ensures that only authorized individuals have access to information and resources.
Answer
Confidentiality
7
Question
No unauthorized changes are made to the information
Answer
Integrity
8
Question
Ensuring that authorized individuals are able to gain access to information when they need it
Answer
Availability
9
Question
Security Strategies
Answer
People, Process, Technology
10
Question
Security is extremely important, but
Answer
it's not the reason why businesses exists
11
Question
subject matter experts in the organization on issues of confidentiality, integrity and availability
Answer
Security Leaders
12
Question
Security leaders should think of themselves as
Answer
wearing two different hats
13
Question
understands the primary mission of the organization, both its strategic and tactical objectives
Answer
Business Leaders
14
Question
Business = ?
Answer
Security
15
Question
Security Control Considerations
Answer
- Security + Business - Confidentiality + Integrity + Availability
16
Question
Security Professional Management Responsibilities
Answer
- Budget - Performance Reviews - Counseling
17
Question
Information Security must
Answer
align itself with the governance processes of the organization
18
Question
Organizational Processes
Answer
- governance committee - risk management committee - board of directors
19
Question
Purpose of Organizational Processes
Answer
- understand the security risks facing the organization - informed of any security incidents - review the results of audits performed
20
Question
Chief Information Security Officer (CISO)
Answer
- leads a team of information security professionals - enforces guiding principles
21
Question
CISO team of information security professionals
Answer
- security generalists - security specialists
22
Question
CISO guiding principles
Answer
- Due Diligence - Due Care
23
Question
Control Objectives for Information Technology
Answer
1. meeting stakeholder needs 2. covering the enterprise end-to-end 3. applying a single integrated framework 4. enabling a holistic approach 5. separating governance from management
24
Question
International Organization for Standardization (ISO)
Answer
- 27002 - 27701 - 31000
25
Question
Security and Privacy Controls for Federal Information Systems and Organizations.
Answer
National Institute for Standards And Technology (NIST).
26
Question
It's known as NIST
Answer
Special Publication 800-53, or more commonly, NIST 800-53
27
Question
NIST Cybersecurity Framework version 1.1
Answer
- Identify - Protect - Detect - Respond - Recover
28
Question
Security Frameworks provide a common language for
Answer
understanding, managing and describing cybersecurity risks
29
Question
Security Frameworks help organizations identify
Answer
identify and prioritize the actions
30
Question
Security Frameworks help organizations align
Answer
align their security actions