Day 3 -12/24/2018 Flashcards

1
Q

Governance vs Management

A

Governence (board of directors) - financial/stakeholders/compliance

E D M
evaluate
direct
monitor

Management -administrative daily tasks as guided by Governence 
(PBRM)
PLAN
BUILD 
RUN 
Monitor
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

SCA

A

SCA
security control assessment
to evaluate security infratructure against a baseline
NIST 800-53A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

LAst step of Risk Ana,ysis

A

Risk Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

cobit vs coso

A

Control objectives , security goals for IT where

in COSO its for full organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

itil ,SDTOC

A
best practices for it services management 
5 service management publications
>strategy
>design
>transition
>operation
>continual improvement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

OCTAVE

A

operationally critical threat asset and vulnerability evaluation
> identfy threats
> identify vulnerabilities
> risk analysis and mitigation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

purpose of exit interview

A

> to review the formal restrictions

> reminder about NDA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Risk related all works done by management

A

bu safeguards or countermeasures are decided by sr management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

prevent collusion

A

> seperation > job rotation >job responsibilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Quantitive risk analysis procedures

A

> asset valuation AV
threat identification of each , for each threat calculate EF and SLE
Frequency of risk. ARO
derive loss potential ALE
research countermeasures for each threat
perform a cost benefit analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly