Frameworks and Controls Flashcards
(15 cards)
What is a security lifecycle?
A security lifecycle is a constantly evolving set of polies and standards.
What Does CIA stand for
CIA is an abbreviation for Confidentiality, Integrity and Availability.
What is CIA used for?
CIA is a standard that helps inform how organizations consider risk when setting up systems and security policies.
What are security controls?
The are safeguards that are designed to mitigate specific security risks.
What are security frameworks?
They are guidelines to build plans to help mitigate threats to data and privacy.
NIST
National institute of Standards and Technology
What does the NIST do?
Develops multiple voluntary complience frameworks that organizations around the world can use to help manage risk.
Two examples of NIST frameworks
Cyber Security Framework (CSF) and Risk Management Framework (RMF)
PII
Personally Identifiable Information
SPII
Sensitive Personally Identifiable Information
Examples of PII
Name, Surname, Email, Phone Number
Examples of SPII
ID Number, Credit Card Information, Health Information
SIEM
Security Information and Event Management