Domain 1: Security and Risk Management Flashcards
3 main elements of Security Program
People, Process, Technology
Important for people
training, knowledge/skill set, company culture
important about process
controls how people interact with the technology
Information Security Triad
Confidentiality, Integrity, Availability
cost v. performance
always a balance between levels of security and performance. Security will reduce performance.
Confidentiality
Prevent unauthorized disclosure
Integrity
Prevent unauthorized modification
Availability
Timely access to resources
Why implement security?
to support the mission of the organization. Not security for security sake
GRC
Governance, Risk, Compliance
Why GRC Came about
Response to widescale fraud and unethical behaviors of organizations in the early 2000s. Open Compliance & Ethics Group (OCEG) provided open standards addressing GRC
Culpable Negligence
Not doing something a reasonably cautious person would do
Due Care
Acting on the research to show you have acted prudently
Due Care
Acting on the research to show you have acted prudently
Prudent Person Rule
You have used due diligence and due care to take reasonable actions, responsibly and cautiously
Ulimate Responsibliity/Liability
Senior Management
Information Security Frameworks
Provide standard set of IS requirements to guide organizations; foundation, structure
ISO 27001 has how many domains
14
ISO 27001
Specifies requirements for establishing, implementing, maintaining, and improving an IS Management system within an organization
GDPR
General Data Privacy Regulation
Who adheres to GDPR
Not the US, more popular in Europe
Goal of GDPR
Protect the Rights of data subjects
Data subject
person the data pertains to
Timeline for Breach Disclosure under GDPR
72 hours to notification