Lot 3 Flashcards

1
Q
The individual(s) and/or department(s) responsible for the storage and 
safeguarding of computerized data
A

Data custodian -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
The individual(s), normally a manager or director, who has responsibility 
for the integrity, accurate reporting and use of computerized data
A

Data owner -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The practice of layering defenses to provide added protection.
Defense in depth increases security by raising the effort needed in an attack. This
strategy places multiple barriers between an attacker and an organization’s computing
and information resources.

A

Defense in depth -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A set of human, physical, technical, and procedural
resources to recover, within a defined time and cost, an activity interrupted by an
emergency or disaster

A

Disaster recovery plan (DRP) -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A means of restricting access to objects based
on the identity of subjects and/or groups to which they belong. The controls are
discretionary in the sense that a subject with a certain access permission is capable of
passing that permission (perhaps indirectly) on to any other subject.

A

Discretionary access control (DAC) -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A procedure that uses two or more entities (usually persons) operating in
concert to protect a system resource so that no single entity acting alone can access that
resource

A

Dual control -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The level of care expected from a reasonable person of similar competency
under similar conditions

A

Due care -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The performance of those actions that are generally regarded as
prudent, responsible, and necessary to conduct a thorough and objective investigation,
review, and/or analysis

A

Due diligence -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A set of responsibilities and practices exercised by the board
and executive management with the goal of providing strategic direction, ensuring that
objectives are achieved, ascertaining that risks are managed appropriately, and verifying
that the enterprise’s resources are used responsibly

A

Enterprise governance -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The potential loss to an area due to the occurrence of an adverse event

A

Exposure -

How well did you know this?
1
Not at all
2
3
4
5
Perfectly