M1-Security Governance Through Principles and Policies Flashcards
Domain 1 (21 cards)
What are the primary goals and objective of a security infrastructure
Confidentiality, Integrity, Availability - CIA
Principle that focuses on protection from unintentional,accidental, or inadvertent change
Integrity
Process of tracing actions to their source
Accountability
Principle that only authorized subjects have access
Confidentiality
Positive identification of a person or a system
Authentication
Process used to develop confidence that the security measures are working as intended
Assurance
Principle that relates to operations and accessibility
Availability
Granting users and systems a predetermined level of access
Authorization
Confidence that the system will work in a correct and predictable manner
Trustworthy computing
Logging of access and use of information resources
Accounting
Expanded view of information security to include external relations
Cyber security
A logical structure used to document and organize processes
Framework
Framework for designing, establishing, implementing, maintaining and monitoring an information security program
ISMS = Information Security Management System
Internationally recognized information security framework
ISO27000
Payment Card Industry contractually enforced framework
PCI-DSS Payment Card Industry Data Security Standard
This type of metric is intended to help organization to compare themselves to peers
Benchmark
The publisher of the SP800 series
NIST-National Institute of Standards and Technology
This program is the US government repository of publicly available security guidance
NCP - National Checklist Program
This US framework is voluntary guidance, based on existing standards, guidelines, and practices for critical infrastructure organisations to better manage and reduce cyber-security risk
NIST Cybersecurity framework
Voluntary Cyber-security framework designed specifically for the healthcare sector
HITRUST
The US gov repository of standards based vulnerability management data
NVD - National Vulnerability Database