Security Management Flashcards

(18 cards)

1
Q

What does CIRT stand for and what is its primary responsibility?

A

Cyber Incident Response Team – responsible for responding to security breaches, viruses, and other cybersecurity incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does SOC stand for and what is its primary responsibility?

A

Security Operations Center – responsible for continuously monitoring and analyzing an organization’s security posture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Security Awareness in an organization?

A

A formal process for training and educating employees about IT protection, ensuring they understand and follow security policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Name three key components of a Security Awareness program.

A

Programs to educate employees

Emphasizing individual responsibility for company security policies

Measures to audit and assess awareness efforts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is A.5 Information security policies?

A

Controls on how the policies are written and reviewed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is A.6 Organization of information security?

A

Controls how responsibilities are assigned; includes mobile & teleworking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is A.7 Human resources security

A

Controls prior to employment, during employment, and after employment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is A.8 Asset management

A

Controls related to inventory of assets and acceptable use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is A.9 Access control ?

A

Controls for Access control policy, user access management, system and application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is A.10 Cryptography?

A

Controls related to encryption and key management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is A.11 Physical and environmental security?

A

Controls defining secure areas, entry controls, protection against threats,..

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is A.12 Operational security?

A

Controls related to management of IT production

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is A.13 Communication security?

A

Controls related to network security, segregation, network services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is A.14 System acquisition, development and maintenance?

A

Controls defining security requirements and security development/support process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is A.15 Supplier relationships?

A

Controls on what to include in agreements, and how to monitor the suppliers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is A.16 Information security incident management?

A

Controls for reporting events and weaknesses, defining responsibilities,…

17
Q

What is A.17 Information security aspects of business continuity management?

A

Controls requiring the planning of business continuity, procedures, verification and reviewing

18
Q

What is A.18 Compliance?

A

Controls requiring identification of applicable laws and regulations