Lecture 2 Flashcards
What is the relationship between risk and security controls?
The amount of risk drives reasons to invest in security controls
In the practical sense, what are security controls?
Knowing vulnerabilities and mitigating them
What is Vulnerability Management?
The Practice of:
1. Knowing known vulnerabilites in an environment
2. Mitigating them
A vulnerability assessment is a set of… what?
A set of activities used to identify security weaknesses in the system
What are the steps in the Vulnerability Management Life Cycle (4)?
- Collect Data
- Analyze Data
- Make Recommendations
- Implement Recommendations
- Regulatory compliance
- Satisfying customer demands
- Response to some fraud/incident
Within the context of our course, what are these?
Business drivers for vulnerability management
- Gaining a competitive edge
- Safeguarding/protecting critical infrastructures
Within the context of our course, what are these?
Business drivers for vulnerability management
- Payment Card Industry Data Security Standard (PCI DSS)
- Canada’s Information Technology Security Guidance Publication 33 (ITSG-33)
- Health Insurance Portability and Accountability Act (HIPAA)
Your organization deals with these regulatory standards/frameworks, what must you also do?
Perform vulnerability assessments
- Personal Health Information Protection Act (PHIPA)
- Personal Information Protection and Electronic Documents Act (PIPEDA)
- ISO 27001
- NIST
Your organization deals wit these regulatory standards/frameworks, what must you also do?
Perform vulnerability assessments