InfoSec Flashcards
What is a security plan?
A plan that identifies and organizes the security activities for a system/organization
What is risk analysis?
A systematic investigation of the system, its environment, and what might go wrong
What is a security policy?
A security policy is a document that defines how an organization deals with some aspect of security.
What is a plan maintenance?
A plan that specify the order which controls are to be implemented.
What is a business continuity plan?
A (business) continuity plan documents how a business will continue to function during or after a computer security incident
What is a Incident response?
Tells the staff how to deal with a security incident
What is ISO/IEC 27005 about?
Information Security Risk Management (ISRM)
What is ISO 31000 about?
(general) Risk Management (RM) (principles and guidelines)
What is risk management?
Coordinated activities to direct and control an organization with regard to risk
What is risk assessment?
Overall process of risk identification, risk analysis and risk evaluation
What is risk identification?
process of finding, recognizing and describing risks
What is risk evaluation?
process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its magnitude is acceptable or tolerable
What does “Level of risk” mean?
magnitude of a risk expressed in terms of the combination of consequences and their likelihood
What does “residual risk” mean?
risk remaining after risk treatment
What does vulnerability mean?
Weakness of an asses or control that can be exploited by one or more threats
What does threat mean?
potential cause of an unwanted incident, which may result in harm to a system or organization
What is ISO?
the process to comprehend the nature of risk and to determine the level of risk
What is Risk analysis?
Organized process for identifying the most significant risks in a computing environment, determining the impact of those risks, and weighing the desirability of applying various controls against those risks
What is management systems?
A management system is a “set of interrelated or interacting elements of an organization to establish policies and objectives and processes to achieve those objectives” (ISO/IEC 27000:2014)
What is cyber terrorism?
The use of computers to launch a terrorist attack
What is an Economic attack?
An attack that causes economic damage.
What is cryptanalysis?
the study of methods for breaking ciphertext
What is cryptography?
the use and practice of cryptographic techniques
What is cryptology?
the study of both cryptography and cryptanalysis