Play it Safe: Manage Security Risks Flashcards
(49 cards)
What does ‘Assess’ mean in the context of the NIST RMF?
The fifth step of the NIST RMF that means to determine if established controls are implemented correctly
What is an ‘Asset’?
An item perceived as having value to an organization
What are ‘Attack vectors’?
The pathways attackers use to penetrate security defenses
What is ‘Authentication’?
The process of verifying who someone is
What does ‘Authorization’ refer to?
The concept of granting access to specific resources in a system
What does ‘Authorize’ mean in the context of the NIST RMF?
The sixth step of the NIST RMF that refers to being accountable for the security and privacy risks that might exist in an organization
What is ‘Availability’?
The idea that data is accessible to those who are authorized to access it
What are biometrics?
The unique physical characteristics that can be used to verify a person’s identity.
What is business continuity?
An organization’s ability to maintain their everyday productivity by establishing risk disaster recovery plans.
What is the second step of the NIST RMF?
Categorize: It is used to develop risk management processes and tasks.
What is Chronicle?
A cloud-native tool designed to retain, analyze, and search data.
What does confidentiality mean?
The idea that only authorized users can access specific assets or data.
What is the CIA triad?
A model that helps inform how organizations consider risk when setting up systems and security policies.
What does detect mean in the context of NIST?
A core function related to identifying potential security incidents and improving monitoring capabilities to increase the speed and efficiency of detections.
What is encryption?
The process of converting data from a readable format to an encoded format.
What is an external threat?
Anything outside the organization that has the potential to harm organizational assets.
What is the Identify function in the NIST Cybersecurity Framework?
A NIST core function related to management of cybersecurity risk and its effect on an organization’s people and assets
What does Implement mean in the NIST Risk Management Framework (RMF)?
The fourth step of the NIST RMF that means to implement security and privacy plans for an organization
What is incident response?
An organization’s quick attempt to identify an attack, contain the damage, and correct the effects of a security breach
What does integrity refer to in cybersecurity?
The idea that the data is correct, authentic, and reliable
What is an internal threat?
A current or former employee, external vendor, or trusted partner who poses a security risk
What is a log in the context of cybersecurity?
A record of events that occur within an organization’s systems
What are metrics in software performance assessment?
Key technical attributes such as response time, availability, and failure rate, which are used to assess the performance of a software application
What does Monitor mean in the NIST RMF?
The seventh step of the NIST RMF that means be aware of how systems are operating