Domain 1 Flashcards
Study
A logical structure used to document and organize processes?
Framework
Framework for designing, establishing, implementing, maintaining, and monitoring an information security program.
ISMS (Information Security Management System)
Internationally recognized Information Security Framework
ISO 27000
Payment card system information security contractually enforced framework
PCI DSS (Payment Card Industry Data Security)
This type of metric is intended to help an organization compare themselves to peers
Benchmark
<p>Publisher of the SP800 series.</p>
<p>NIST</p>
This program is the U.S government repository of publicly available security guidance.
NCP (National Checklist Program)
This U.S framework is voluntary guidance, based on existing standards, guidelines, and practices, for critical infrastructure organizations to better manage and reduce cybersecurity risk
NIST Cybersecurity Framework
The U.S government repository of standards-based vulnerability management data.
NVD (National Vulnerability Database)
Principle that focuses on protection from unintentional accidental, or inadvertent change.
Integrity.
Process of tracing actions to their source.
Accountability.
Principle that only authorized subjects have access.
Confidentiality
Positive identification of a person or a system.
Authentication.
Process used to develop confidence that security measures are working as intended.
Assurance.
Principal that relates to operations and accessibility.
Availability.
Granting users and systems a predetermined level of access
Authorization.
Confidence that the system will act in a correct and predictable manner in every situation.
Trustworthy Computing.
Logging of access and use of information resources.
Accounting.
Expanded view of information security to include external relationships and global threats.
Cybersecurity.
The standard of care that a prudent person would have exercised under the same or similar conditions:
- Actions taken by an organization to protect its stakeholders, investors, employees, and customers from harm.
Due Care.
Is an investigation of a business or person generally before entering into a contract:
- Is is the care and caution a reasonable person would take.
Due Diligence.
Is the potential liability incurred by a company whose computer systems are compromised and becomes the source of harm.
Downstream Liability.
The board or a board committee duties include:
- Promoting effective governance.
- Determining organizational risk tolerance.
- Contributing to and authorizing strategic plans.
- Allocating funds.
- Approving policies and significant projects.
- Ensuring appropriate monitoring.
- Ensure compliance with laws, regulations and contracts.
- Reviewing audit and examination results.
- Honoring the legal constructs of due diligence and due care.
Executive management is responsible for:
- Strategic Alignment.
- Risk Management.
- Value delivery.
- Performance measurements.
- Resource management.
- Processes assurance.
Privacy is the right of an individual to control the use of their personal information.
Student educational records.
Federal Privacy Act (U.S.)
Data Collected by the Government.
Children's Online Privacy Protection Act (COPPA)
Plan and procedures for recovering technology and facilities.