5.0 Security Program Management and Oversight Flashcards

(27 cards)

1
Q

Q: What is NIST SP 800-61 Rev. 2?

A

A: A guide for incident response lifecycle: prepare → detect → contain → recover → post-incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Q: What is ISO?

A

A: International Organization for Standardization — sets global standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Q: What is NIST?

A

A: U.S. National Institute of Standards and Technology — provides cybersecurity frameworks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Q: What is change management?

A

A: The process for controlling changes in IT, including approval, testing, and backups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Q: What is ad hoc assessment?

A

A: A targeted assessment done for a specific issue or threat (“for this”).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Q: What are the four risk management strategies?

A

Transfer (e.g., insurance)

Accept

Avoid

Mitigate (e.g., firewall)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Q: What is RTO (Recovery Time Objective)?

A

A: Maximum time allowed to restore a system after disruption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Q: What is RPO (Recovery Point Objective)?

A

A: Maximum acceptable amount of data loss (in time).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Q: What is MTTR (Mean Time to Repair)?

A

A: Average time needed to fix a system after failure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Q: What is MTBF (Mean Time Between Failures)?

A

A: Average time between system/device failures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Q: What is an MOU (Memorandum of Understanding)?

A

A: Informal agreement to collaborate, not legally binding.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Q: What is an MOA (Memorandum of Agreement)?

A

A: More formal than MOU; both parties conditionally agree on terms.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Q: What is an MSA (Master Service Agreement)?

A

A: Legal contract outlining general terms between parties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Q: What is an SOW (Statement of Work)?

A

A: A detailed list of deliverables and responsibilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Q: What is an NDA (Non-Disclosure Agreement)?

A

A: Legal contract to protect confidential information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Q: What is a BPA (Business Partner Agreement)?

A

A: Agreement that defines roles and responsibilities between partners.

17
Q

Q: What does SOX regulate?

A

A: Sarbanes-Oxley Act — regulates financial data reporting.

18
Q

Q: What does GLBA regulate?

A

A: Gramm-Leach-Bliley Act — for financial institutions’ data handling.

19
Q

Q: What is the role of a CCO?

A

A: Chief Compliance Officer — oversees adherence to laws/regulations.

20
Q

Q: What is due care vs due diligence?

A

Due care: Internal responsibility

Due diligence: Evaluating external parties

21
Q

Q: What is GDPR?

A

A: General Data Protection Regulation — EU law for personal data protection.

22
Q

Q: What are the roles in data privacy?

A

Data Owner: Owns the data

Data Controller: Determines how data is used

Data Processor: Processes the data

23
Q

Q: What is attestation?

A

A: An auditor’s opinion on an organization’s security posture.

24
Q

Q: What is the role of an audit committee?

A

A: Internal group that initiates, oversees, or stops an audit.

25
Q: What is active reconnaissance?
A: Direct interaction with the target system; likely detectable.
26
Q: What is passive reconnaissance?
A: Collecting information without interacting directly; harder to detect. Dumpster diving
27
Q: What are the types of testing environments?
Known (white-box) Partially known (gray-box) Unknown (black-box)