SEC+ Acronyms Flashcards
(54 cards)
GDPR
General Data Protection Regulation
Establishes personal data privacy enforcement and penalties for non-compliance and limits how an individual’s personal data can be shared. “Right to erasure.”
PCI-DSS
Payment Card Industry Data Security Standard
Protects cardholder data and authentication data (storage, processing, and transmission).
PAN
Primary Account Number
CIS
Center for Internet Security
Non-profit that provides cyber defense guidance, best practices, advisories, alert levels, and configuration baseline guidance
MS-ISAC
Multi-state information sharing and analysis center
provides historical cyber threat statistics, reports, incident response, and forensics to state and local U.S. governments.
RMF
NIST Risk Management Framework
Overall framework for the U.S. federal government to manage organizational risk throughout the system development life cycle; focuses on security control selection, deployment, and auditing using a six-step model
SSAE
Statement on Standards for Attestation Engagements
System and organization controls (SOC) reports examine an organization’s internal controls IRT security, availability, process integrity, confidentiality, etc. Current standard is SSAE 18.
CSA
Cloud Security Alliance
International organization that researches and developers best practices for cloud computing environments
ISO
International Organization for Standardization
Publishes international standards and guidelines.
NDA
Non-Disclosure Agreement
CBT
Computer-based training
AUP
Acceptable Use Policy
Defines the conditions in which company resources may be used.
SLA
Service-level Agreement
A formal definition of a service provided to or by the organization
MSA
Measurements System Analysis
A method of determining the amount of variation and uncertainty that exists within a measurement process
EOL
End of Life
End of support for a product
EOSL
End of Service Life
Agreed-upon service is no longer offered by the service provider
MOU
Memorandum of Understanding
A less formal agreement of mutual goals between two or more organizations with a focus on partitioning of responsibilities
BPA
Business Partnership Agreement
DPO
Data Protection Officer
Responsible for the care and protection of customer data.
PII
Personally Identifiable Information
PHI
Personal Health Information
IP
Intellectual Property
SLE
Single Loss Expectancy
how much realizing a risk costs for one occurrence
ALE
Annualized Loss Expectancy
how much realizing a risk costs per year