Give three examples of personnel management practices., Least privilege, separation of duties, job rotation and mandatory vacations, clean desk space, onboarding and offboarding, nondisclosure agreements (NDAs), social media, and user training., Name six major information security regulations facing organizations., HIPAA, PCI DSS, GLBA, SOX, GDPR, and FERPA, What do you call a document that provides best practices and recommendations related to a given concept, technology, or task?, A guideline, What term is used for a document that provides a high‐level statement of management intent?, A policy, What do you call a document that provides mandatory requirements describing how an organization will carry out its information security policies?, A standard, What are four types of documents in the information security policy framework?, Policies, standards, procedures, and guidelines, What are playbooks?, Step‐by‐step guides intended to help incident response teams take the right steps in a given scenario., List four standard agreements used in third‐party risk management., Master service agreements (MSA), service level agreements (SLAs), memorandum of understanding (MOU), memorandum of agreement (MOA), and business partners agreements (BPAs)., What are three components in the NIST framework?, The Framework Core, the Framework Implementation, and the Framework Profile, Name the phases of the software development life cycle (SDLC)., Planning, requirements definition, design, coding, testing, training and transition, ongoing operations and maintenance, and end‐of‐life decommissioning, What are four key metrics in the BIA process?, Mean Time Between Failures (MTBF) is the expected amount of time between system failures. Mean Time to Repair (MTTR) is the average amount of time to restore a system to its normal operating state after a failure. Recovery Time Objective (RTO) is the amount of time that the organization can tolerate a system being down before it is repaired. Recovery Point Objective (RPO) is the amount of data that the organization can tolerate losing during an outage., What is risk avoidance?, A risk management strategy where you change your business practices to completely eliminate the potential that a risk will materialize., What is the formula to calculate the severity of a risk?, Risk Severity = Likelihood * Impact, Name all five risk categories., Financial, reputational, strategic, operational, and compliance, What term describes the original level of risk that exists before implementing any controls?, The inherent risk facing an organization is the original level of risk that exists before implementing any controls. Inherent risk takes its name from the fact that it is the level of risk inherent in the organization’s business., What are two important roles served by risk assessment in the risk management process?, The risk analysis provides guidance in prioritizing risks so that the risks with the highest probability and magnitude are addressed first. Quantitative risk analyses help determine whether the potential impact of a risk justifies the costs incurred by adopting a risk management approach., What is risk mitigation?, The process of applying security controls to reduce the probability and/or magnitude of a risk., Why should a company establish key performance indicators (KPIs)?, KPIs quantitatively measure vendors’ performance in order to ensure that vendors are meeting the agreed‐upon standards., What are two types of risk analyses and what are their differences?, Quantitative risk analyses use numeric data, resulting in assessments that allow the very straightforward prioritization of risks. Qualitative risk analysis substitutes subjective judgments and categories for strict numerical analysis, allowing the assessment of risks that are difficult to quantify., What are threats, vulnerabilities, and risks?, Threats are any possible events that might have an adverse impact on the confidentiality, integrity, and/or availability of our information or information systems. Vulnerabilities are weaknesses in our systems or controls that could be exploited by a threat. Risks occur at the intersection of a vulnerability and a threat that might exploit that vulnerability. A threat without a corresponding vulnerability does not pose a risk, nor does a vulnerability without a corresponding threat., What are three key threats to cybersecurity programs?, Disclosure, alteration, and denial, Describe the process of quantitative risk analysis., Determine the asset value (AV) of the asset affected by the risk. Determine the likelihood that the risk will occur. Determine the amount of damage that will occur to the asset if the risk materializes. Calculate the single loss expectancy. Calculate the annualized loss expectancy., What is a right‐to‐audit clause?, Part of the contract between the cloud service and an organization. A right‐to‐audit clause provides either a direct ability to audit the cloud provider or an agreement to use a third‐party audit agency., List at least three key elements of the rules of engagement for a penetration test., The timeline for the engagement and when testing can be conducted; valid targets; data handling requirements; what behaviors to expect from the target; what resources are committed to the test; legal concerns should also be addressed, including a review of the laws that cover the target organization, any remote locations, and any service providers who will be in‐scope, and when and how communications will occur., What is crucial for managing and mitigating third‐party risks?, Effective vendor monitoring is crucial for managing and mitigating third‐party risks., What is a data controller?, The entity who determines the reasons for processing personal information and directs the methods of processing that data., What is a data processor?, A service provider that processes personal information on behalf of a data controller., Define due care., It refers to the ongoing efforts to ensure that the implemented policies and controls are effective and continuously maintained., What are four major categories of penetration testing?, Physical penetration testing, offensive penetration testing, defensive penetration testing, and integrated penetration testing., What are three typical classifications that are used to describe penetration test types?, Known environment, unknown environment, and partially known environment, Identify the four key phases of a penetration test., Initial access, privilege escalation, pivoting (lateral movement), and persistence, What is the difference between an audit and an assessment?, Audits are formal reviews of an organization’s security program or specific compliance issues conducted on behalf of a third party. Assessments are less formal reviews of security controls that are typically requested by the security organization itself in an effort to engage in process improvement., What does the social engineering principle of intimidation rely on?, Intimidation relies on scaring or bullying an individual into taking a desired action., What does the social engineering principle of authority rely on?, Authority relies on the fact that most people will obey someone who appears to be in charge or knowledgeable, regardless of whether or not they actually are.
0%
Domain5
Share
Share
by
Gdps
Edit Content
Print
Embed
More
Assignments
Leaderboard
Show more
Show less
This leaderboard is currently private. Click
Share
to make it public.
This leaderboard has been disabled by the resource owner.
This leaderboard is disabled as your options are different to the resource owner.
Revert Options
Flash cards
is an open-ended template. It does not generate scores for a leaderboard.
Log in required
Visual style
Fonts
Subscription required
Options
Switch template
Show all
Open results
Copy link
QR code
Delete
Continue editing:
?