Chapter 3.1 Flashcards

1
Q

Vendor specific

A

Vendor specific guides provide instructions on how to install and securely configure hardware and software specifically for a certain vendor.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Regulatory

A

Regulatory frameworks are based on specific laws and regulations and ensure compliance of those standards. They are highly controlled and regulated. Medical records are governed by regulatory laws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Industry specific

A

Industry-specific frameworks are governed according to the type of product provided. Financial information is covered under industry specific standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Non-regulatory

A

A non-regulatory framework is not enforced by a law or statute. Instead, non-regulatory frameworks identify their own standards and best practices to meet company needs and be successful.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

General purpose guide

A

General purpose guides help increase security in hardware and software by providing instructions to configure a system based on roles and appliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

User training

A

User training teaches users new functionality as well as proper policies and procedures for company and software.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

International

A

International frameworks are governed by international standards and are to be implemented globally versus nationally.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

NIST

A

The National Institute of Standards and Technology framework regulates the cybersecurity risks and activities in the United States. It is part of the U.S. Department of Commerce and considered a national framework.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Defense-in-depth

A

Defense-in-depth uses a combination of control types for control diversity. Currently, technical preventive and administrative detective controls are in place. Adding a door lock adds a physical deterrent control, and a backup system adds a technical correction control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Administrative

A

Administering penetration tests on an application to avoid attacks is an administrative control. Administrative controls are mandated by company policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly