Evolving Security Standards & Practices Flashcards

1
Q

NIST 1.0 Framework

A

Identify
Protect
Detect
Respond
Recover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NIST 2.0 Framework

A

Identify
Protect
Detect
Respond
Recover
Govern

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Standard Development Organization in the Chemical Sector

A

American Chemistry Council

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Standard Development Organization in the Petroleum Sector

A

American Petroleum Institute

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Standard Development Organization in the Water & Wastewater Sector

A

American Water Works Association (AWWS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Standard Development Organization in the Electric Sector

A

North American Electric Reliability (NERC)
NERC CIP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

IEC

A

International Electrotechnical Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ISA

A

International Society of Automation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ANSI

A

American National Standards Institute

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

NIST

A

National Institute of Standards & Technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

NESA UAE

A

UAE Electronic Security Authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Three European SDO’s

A

CEN
CENELEC
ETSI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

NIST publication for IACS

A

Special Publication 800-82 Revision 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

ISO 27001:2022

A

IT - Security techniques - ISMS -requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ISO/IEC 21827:2008

A

IT-Security Techniques - System Security Engineering - Capability Maturity Model (SSE-CMM)

  • Standard ending in 2008 does not necessarily mean that standard is outdated.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

ISO/IEC 15408:2022

A

IT - Security Techniques - Evaluation Criteria of IT Security (Common Criteria)

15
Q

Control Objectives for Information and Related Technology (ISACA)

16
Q

CCS CSC

A

Council on Cyber Security Critical Security Controls.

17
Q

ISA/IEC 62443-2-1:2009

A

Requirements for IACSC security Management System (CSMS)

18
Q

ISA/IEC 62443-3-3:2013

A

System Security Requirements & Security Levels

19
Q

Frameworks Core

A

Frameworks Provide Common Taxonomy and Mechanism

20
Q

NIST CST Tiers

A

Tier 1 – Partial
Tier 2 – Risk Informed
Tier 3 – Repeatable
Tier 4 – Adaptive

21
Q

Characteristics of NIST CSF Tiers

A

1 - Organizations can use Tiers to shape their cybersecurity profiles, which reflect how they perceive and manage cybersecurity risks.

2 - Tiers range from basic and ad-hoc, reactive approaches to advanced, proactive ones guiding organizations in improving their cybersecurity governance and practices.

3 - Choosing Tiers establishes the organization’s approach to risk management.