Midterm 2 Chapter 11 Flashcards

1
Q

Who is responsible fore security?

A

Managment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Management must take responsibility for:

A
  1. Policy development
  2. Effective communication of these policies
  3. Design of appropriate control policies
  4. Monitoring of the system and, if necessary, take corrective actions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Can the COSO structure be overlaid on the security model?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Time Based Model of Security

A

P>D+C
Preventative is greater than the sum of detective plus corrective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

P

A

The time it takes an attacker to break through the various controls that protect the company’s information system assets (we want these to be high)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

D

A

The time it takes for the company to detect that an attack has occurred (we want these to be low)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

C

A

The time it takes to respond to and stop the attack (we want these to be low)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the problem with symmetric encryption?

A

I have to give the key to you somehow - if the key is dropped or lost, anyone with access to it can have access to any of the codes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is asymmetric encryption based on?

A

Prime number factering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly