D1: Security & Risk Management Flashcards
D1 from example test simulators keywords (203 cards)
NDA
Non Disclosure Agreement; restricts dissemination of information; Compelling parties to not reveal information to others; Keeping secrets;
NCA
Non Compete Agreement; relates to employment with competition; Work restrictions; Agreement not to enter into or start a similar line of work in competition against another party;
AUP
Authorized Use Policy; warns employees about proper use of organizational assets; Allows for firing employee for misuse;
Exit Interview
Useful for discovering serious problems that might not be otherwise disclosed;
Education
Providing fundamental knowledge & definitions
Training
Providing tactical knowledge necessary for a job or task
Awareness
Imparting sensitivity or importance to a topic/issue to all personnel
Indoctrination
Incorporating an individual or group into the culture of the larger organization
CEO
Chief Executive Officer; Responsible for overall organization and its mission
CIO
Chief Information Officer; Responsible for aligning information & technical strategies; Most senior official in an organization responsible for IT & Systems that support enterprise; Senior Technology official;
CPO
Chief Policy Officer: Responsible for ensuring that there is compliance with org and regulatory privacy rules
CISO
Chief Information Security Officer; Responsible for monitoring & analyzing risk information associate with data protection
CSO
Chief Security Officer; Responsible for physical & Technical security of orgs assets; Responsible for development, oversight, mitigation, & other risk strategies; Senior most security official;
CTO
Chief Technology Officer; Chooses technology & scientific items; Executive person tasked with identifying useful technology, IT strategies, & partnerships;
ISSO
Information Systems Security Officer; Organizational role charged with developing, implementing, testing, & reviewing IT security;
Risk Management Categorize
Related to assigning a security role to an IT system
Risk Management Select
Identifies the appropriate measures needed to reduce risk satisfactorily
Risk Management Implement
Regards enacting the selected security controls
Risk Management Assess
Involves an independent assessor to test the controls
Risk Management Authorize
Take the risk assessment and make a risk determination
Risk Management Monitor
Relates to ongoing review & updating of controls and security status
Opportunity Cost
Next best use for funds
Depreciated Cost
Reflects wear, tear, and evaluation over time
Replacement Cost
current expenditure to gain an identical item