Governance Standards And Control Frameworks Flashcards

1
Q

PCI-DSS

A

Payment Card Industry Data Security Standard
Standard that is required to handle or issue credit and debit cards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

OCTAVE (Operationally Critical Threat Asset Vulnerability Evaluation)

A

Self directed risk management
Team oriented approach identify assets important to the organization, threats to those assets, and vulnerabilities that may expose those assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

COBIT (Control Objectives for Information and Technology)

A

Control Objectives for Information and Technology
Goals for IT stakeholders needs are mapped down to IT related goals.
Operational level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ITIL

A

Information Technology Infrastructure Library
IT services Management (ITSM)
Set of frameworks and best practices that is used to align IT services with business needs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

COSO

A

Committee of Sponsoring Organizations
Goals for the entire organization
High strategic level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

FRAP

A

Facilitated Risk Analysis Process
Analyzes 1 business unit applications or system at a time in a round table brainstorm with internal employees

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ISO 27001

A

International Organization for Standardization
Focus on creation and maintenance of an information security management system
Can be certified in

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

ISO 27002

A

Provide practical advice on how to implement security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

ISO 27004

A

Provide metrics for measuring the success of your ISMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

ISO 27005

A

Standard based approach to risk management. Gives detail and structure to the information security risks by defining the context for information security risk decision making

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

ISO 27799

A

Directives on how to protect PHI(Protect Health Information)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly