M1-Security Governance Through Principles and Policies Flashcards

Domain 1 (21 cards)

1
Q

What are the primary goals and objective of a security infrastructure

A

Confidentiality, Integrity, Availability - CIA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Principle that focuses on protection from unintentional,accidental, or inadvertent change

A

Integrity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Process of tracing actions to their source

A

Accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Principle that only authorized subjects have access

A

Confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Positive identification of a person or a system

A

Authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Process used to develop confidence that the security measures are working as intended

A

Assurance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Principle that relates to operations and accessibility

A

Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Granting users and systems a predetermined level of access

A

Authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Confidence that the system will work in a correct and predictable manner

A

Trustworthy computing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Logging of access and use of information resources

A

Accounting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Expanded view of information security to include external relations

A

Cyber security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A logical structure used to document and organize processes

A

Framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Framework for designing, establishing, implementing, maintaining and monitoring an information security program

A

ISMS = Information Security Management System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Internationally recognized information security framework

A

ISO27000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Payment Card Industry contractually enforced framework

A

PCI-DSS Payment Card Industry Data Security Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

This type of metric is intended to help organization to compare themselves to peers

17
Q

The publisher of the SP800 series

A

NIST-National Institute of Standards and Technology

18
Q

This program is the US government repository of publicly available security guidance

A

NCP - National Checklist Program

19
Q

This US framework is voluntary guidance, based on existing standards, guidelines, and practices for critical infrastructure organisations to better manage and reduce cyber-security risk

A

NIST Cybersecurity framework

20
Q

Voluntary Cyber-security framework designed specifically for the healthcare sector

21
Q

The US gov repository of standards based vulnerability management data

A

NVD - National Vulnerability Database