5.0 Security Program Management and Oversight Flashcards
(27 cards)
Q: What is NIST SP 800-61 Rev. 2?
A: A guide for incident response lifecycle: prepare → detect → contain → recover → post-incident.
Q: What is ISO?
A: International Organization for Standardization — sets global standards.
Q: What is NIST?
A: U.S. National Institute of Standards and Technology — provides cybersecurity frameworks.
Q: What is change management?
A: The process for controlling changes in IT, including approval, testing, and backups.
Q: What is ad hoc assessment?
A: A targeted assessment done for a specific issue or threat (“for this”).
Q: What are the four risk management strategies?
Transfer (e.g., insurance)
Accept
Avoid
Mitigate (e.g., firewall)
Q: What is RTO (Recovery Time Objective)?
A: Maximum time allowed to restore a system after disruption.
Q: What is RPO (Recovery Point Objective)?
A: Maximum acceptable amount of data loss (in time).
Q: What is MTTR (Mean Time to Repair)?
A: Average time needed to fix a system after failure.
Q: What is MTBF (Mean Time Between Failures)?
A: Average time between system/device failures.
Q: What is an MOU (Memorandum of Understanding)?
A: Informal agreement to collaborate, not legally binding.
Q: What is an MOA (Memorandum of Agreement)?
A: More formal than MOU; both parties conditionally agree on terms.
Q: What is an MSA (Master Service Agreement)?
A: Legal contract outlining general terms between parties.
Q: What is an SOW (Statement of Work)?
A: A detailed list of deliverables and responsibilities.
Q: What is an NDA (Non-Disclosure Agreement)?
A: Legal contract to protect confidential information.
Q: What is a BPA (Business Partner Agreement)?
A: Agreement that defines roles and responsibilities between partners.
Q: What does SOX regulate?
A: Sarbanes-Oxley Act — regulates financial data reporting.
Q: What does GLBA regulate?
A: Gramm-Leach-Bliley Act — for financial institutions’ data handling.
Q: What is the role of a CCO?
A: Chief Compliance Officer — oversees adherence to laws/regulations.
Q: What is due care vs due diligence?
Due care: Internal responsibility
Due diligence: Evaluating external parties
Q: What is GDPR?
A: General Data Protection Regulation — EU law for personal data protection.
Q: What are the roles in data privacy?
Data Owner: Owns the data
Data Controller: Determines how data is used
Data Processor: Processes the data
Q: What is attestation?
A: An auditor’s opinion on an organization’s security posture.
Q: What is the role of an audit committee?
A: Internal group that initiates, oversees, or stops an audit.