1/74
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
FIPS 140-2
A detailed federal government standard for cryptographic modules, including HSMs.
A U.S. government encryption standard, and vendors often ensure that their hardware and software is FIPS 140‐2‐certified.
What is an accounting report on controls at a service organization that replaces older SAS 70 type reports?
A. SOC 1
B. SSAE 18
C. GAAP
D. SOC 2
Explanation
A. SOC 1
An accounting report is specifically about financials.
❌ SSAE 18 sounds right but doesn’t provide specifically an accounting report. It provides an attestation from CPAs/accountants.
CCM
Cloud Controls Matrix.
A security controls framework that provides mapping/cross relationships with the main industry‐accepted security standards, regulations, and controls frameworks such as the ISO 27001/27002, ISACA’s COBIT, and PCI‐DSS
The CCM cross‐references many industry standards, laws, and guidelines.
PIPEDA
The Personal Information Protection and Electronic Documents Act is a Canadian law relating to data privacy.
NIST Five Essential Characteristics of Cloud Computing
On-demand self-service, Broad network access, Resource pooling, Rapid elasticity, Measured service
NERC/CIP
The North American Electric Reliability Corporation’s Critical Infrastructure Program (NERC/CIP) provides security standards for electric utilities and other elements of critical infrastructure.
FISMA
The Federal Information Security Management Act (FISMA)
Managing federal government/agencies information security, including government contractors
For example, even though Company X is a private company, if it's operating with/on behalf of the government, FISMA requirements can therefore apply to that contractor/company.
CALEA
The Communications Assistance to Law Enforcement Act (CALEA) requires that all communications carriers make wiretaps possible for law enforcement officials who have an appropriate court order.
Requires that communications service providers cooperate with law enforcement requests
COBIT
The Control Objectives for Information Technology (COBIT) provide a generalized/broad governance/management framework for IT organizations.
ISO 27701
Provides control guidance for privacy programs.
How personal information is handled, privacy risks.
ISO 27001 → ISMS = Information Security Management System
ISO 27701 → PIMS = Privacy Information Management System
ISO 9000
Quality management
ISO 22301
Defines business continuity plans, systems, and processes
ISO 27001
Requirements for an Information security management system (ISMS)
Can be audited against to provide a certification that an organization has a holistic, comprehensive program of internal security controls.
ISO 27002
Guidance for security controls for ISMS
ISO 27017
Cloud security controls and guidance
ISO 27018
Cloud privacy
PII/privacy in public clouds
8=P, P for Privacy or PII.
ISO 20000-1
IT services, operational controls, ITIL, COBIT, IT service management
Concerned with managing IT services/Service Management Systems (SMS) effectively
NOT security related
ISO 27034
Application security.
Relevant to secure application development/application lifecycle security.
ONF, ANF
ONF
Organizational Normative Framework
The organization's centralized repository/framework for application-security information and controls.
ANF
Application Normative Framework
Security framework for a specific application
ONF vs ANF
ONF = organization's overall application-security framework
ANF = security framework for a specific application
ISO 27037, 27041, 27042, 27043
27037: Collecting, identifying, and preserving electronic evidence
27041: Validate proper tools/methods
27042: Digital evidence analysis
27043: Incident investigation principles and processes
What are the 4 ISO standards for handling digital evidence?
ISO 27037, 27041, 27042, 27043
ISO 27037
Guide for collecting, identifying, and preserving electronic evidence
ISO 27041
Validate proper tools/methods
ISO 27042
Guide for digital evidence analysis
ISO 27043
Incident investigation principles and processes
ISO 27050-1
Overview and principles for eDiscovery
ISO 28000
Supply chain security
ISMS = ___ ___
ISO 27001
ISO 31000
Risk Management
A general risk-management framework
Not a certifiable standard
Only provides guidance
ISO 31010
Risk Assessment Techniques
Provides guidance for selecting/applying techniques for assessing risk in different situations.
"What techniques can we use to assess risk?"
ISO 15408
Common Criteria/EAL
Establishes concepts/principles for evaluating the security properties/security-certifying of IT products.
Common Criteria uses Protection Profiles and Security Targets to define what security requirements are being evaluated.
ISO 17788
Cloud Computing Overview and Vocabulary
Provides an overview of cloud computing and establishes cloud-computing terminology and definitions.
NOT a security-controls standard.
ISO 18788
Establishes requirements for a management system (how it’s managed) for private security operations.
Makes sure a private security organization has a structured, controlled, and accountable way of operating.
ISO 18788 5 Phases:
Policy: Establish organizational commitment/direction
Planning: Determine objectives, risks, programs, and plans
Implementation and Operation: Put the plans into practice
Performance Evaluation: Measure/monitor how things are performing
Management Review: Leadership reviews results and determines needed changes
In ISO 18788:2015 — Management System for Private Security Operations – Requirements with Guidance for Use, at which phase of continual improvement is the need for changes considered?
A. Policy
B. Management Review
C. Performance Evaluation
D. Implementation and Operation
B. Management Review
❌ Performance Eval is a measure/monitor how things are performing
In ISO 18788:2015 Management System for Private Security Operations – Requirements with Guidance for Use, at which phase of continual improvement are strategic programs and risk assessments completed?
A. Implementation and Operation
B. Planning
C. Policy
D. Performance Evaluation
B. Planning
❌ Risk assessments are done in the planning phase. You have to PLAN for potential risks in advance. Strategic programs to complete objectives are also completed in the Planning phase.
❌ Risk assessments should be done BEFORE anything is implemented.
❌ Performance Eval measured how well things are performing. It doesn't have anything to do with risk assessments.
Uptime Institute (UI)
About data-center infrastructure availability/resilience
UI Tier 1
Basic Site Infrastructure
Maintenance requires shutting down facility
Will be affected by infrastructure failures
Useful as a backup
Hot/warm/cold site
Cheaper to operate
UI Tier 2
Redundant Capacity
Good for operating in public cloud environment
Low overhead
UI Tier 3
Concurrently Maintainable
Maintenance can occur without shutting down IT operations.
Critical operations can continue during infrastructure failure
Multiple distribution paths
UI Tier 4
Fault tolerant
ECPA
Electronic Communications Privacy Act of 1986
Privacy of electronic communications
U.S. federal law concerning privacy/protection of wire, oral, and electronic communications.
FERPA
Family Educational Rights and Privacy Act
Gives parents rights concerning their children's education records, including:
Access to records, Requesting amendments, Disclosure of PII
FedRAMP
Federal Risk and Authorization Management Program
Provides a standardized approach to assessing and authorizing cloud computing products and services used by federal agencies.
Think → Federal government + cloud services/products
Intended to standardize security assessment and authorization of cloud services for federal use.
SOX
Sarbanes-Oxley Act - Requires publicly traded corporations to provide info about their financial status and implement controls to ensure accuracy
Enacted to protect shareholders and the public from enterprise accounting errors and fraudulent practices.
US Federal Law. Does not apply to other countries.
CLOUD Act
Clarifying Lawful Overseas Use of Data Act
Concerns government/law enforcement access to electronic data when data is stored across borders/countries.
International data.
SOC
System and Organization Controls
SOC reports provide assurance regarding controls at a service organization.
Belinda is auditing the financial controls of a manufacturing company and learns that the financial systems are run on a major IaaS platform. She would like to gain assurance that the platform has appropriate security controls in place to assure the accuracy of her client’s financial statements. What action should she take?
A. Perform an IT audit of the cloud provider.
B. Obtain a SOC 1 report.
C. Obtain a SOC 2 report.
D. Continue testing only controls at the client and note the use of the cloud provider in her report.
B. Obtain a SOC 1 report.
❌ SOC 2 is tempting, because it mentions “security controls”, but SOC 2 has nothing to do with proving the accuracy of financials.
SOC 1
Controls (security, access, processing, etc.) relevant to accurate, complete, and reliable financial reporting.
Provides an accounting report on controls at a service organization and replaces SAS 70 type reports.
2 subclasses (Type 1, 2)
SOC Type 1
Controls are suitably designed at a point in time
Type 1 tells you: "Were the controls appropriately designed on this date?"
SOC Type 2
Controls are suitably designed and operated effectively over a period of time
SOC 1 Type 2 is “Were the financial controls done properly over this period of time?”
SOC 2 Type 2 is “Were the security controls done properly over this period of time?”
SOC 2
Security/privacy/operational controls
Concerned with controls related to the Trust Services Criteria:
Security, Availability, Processing integrity, Confidentiality, Privacy
Includes Business Continuity measures (Availability)
The 5 Trust Services Criteria
Security, Availability, Processing integrity, Confidentiality, Privacy
SOC 3
Reports designed to be shared with the public/general use
“Seal of approval”
Has no data about the security controls
An assertion the audit was conducted and passed
Your organization is evaluating a provider's service offerings and wants to ensure that the provider can fulfill your organization's long-term financial commitments and stay operational. What report should your organization review?
A. Audited financials or due diligence assessments, and SOC 2
B. Type 1
C. Service Organization Control (SOC) 1
D. Type 2
A.
❌ Just SOC 1 does not provide information on whether the provider will stay operational in the long term.
❌ Type 2 tells you operational efficiency over a period of time, but not financials
❌ Type 1 tells you controls designed at a specific point in time, not over time/long term.
SSAE 18
Statement on Standards for Attestation Engagements
U.S. rules/standards for performing attestation engagements - when an independent CPA/accountant examines a company's controls and provides an assurance report about them.
Can be done on cloud providers. Done by independent, external audit firms.
Uses a framework, including SOC 1, SOC 2, and SOC 3 reports.
ISAE 3402
International Standard on Assurance Engagements 3402
It addresses assurance reports on controls at service organizations.
Used to guide SOC audits outside the United States
NIST SP 800-37
The Risk Management Framework (RMF)
Used by federal government agencies to manage enterprise risk
NIST 800-145
The NIST Definition of Cloud Computing
It defines the five essential characteristics (On-demand self-service, Broad network access, Resource pooling, Rapid elasticity, Measured service),
SaaS, IaaS, PaaS,
And the four deployment models (private, community, hybrid, public).
NIST 800-146
Cloud Computing Synopsis and Recommendations
It discusses Cloud-computing benefits, Open issues, Major classes of cloud technology, Opportunities, Risks and Recommendations for cloud computing
NIST 800-145 vs NIST 800-146
800-145 = Definition
800-146 = Recommendations/risks
NIST 800-92
Log management
NIST 800-40
Enterprise patch management
NIST 500-292
NIST Cloud Computing Reference Architecture
The architecture/roles/components of cloud computing, providing a framework for describing cloud services and their components.
"What does the cloud architecture look like?"
GLBA
The Gramm-Leach-Bliley Act
U.S. federal law primarily concerned with protecting consumers' nonpublic personal information (NPI) held by financial institutions.
The 3 Big Import/Export Restrictions
ITAR, EAR, The Wassenaar Arrangement
ITAR
International Traffic in Arms Regulations – US
State department prohibits defense-related exports (includes cryptography systems)
EAR
Export Administration Regulations – US
Department of Commerce prohibits dual-use items (tech used for both commercial/ military purposes)
The Wassenaar Arrangement
Group of 41 members mutually agreed to inform each other about conventional military shipments to nonmember countries
Not a treaty, not legally binding, not a US law
May require org to notify government to stay within compliance
International agreement/framework for export controls
GAPP
Generally Accepted Privacy Principles
Addresses how an organization should handle personal information.
It's a set of privacy principles used to evaluate and manage how organizations handle personal information.
In the Association of International Certified Professional Accountants (AICPA) Generally Accepted Privacy Principles, which principle indicates that your organization defines, documents, and communicates its privacy policies and procedures?
A. Management
B. Collection
C. Notice
D. Access
A. Management
❌ Notice is to tell people how their information is collected and used.
In the Association of International Certified Professional Accountants (AICPA) Generally Accepted Privacy Principles, which principle allows individuals to review and correct their information?
A. Management
B. Quality
C. Access
D. Security
C. Access
❌ Quality is the organization's responsibility to ensure. Not the individual's whos data it is.
❌ Security has to do with how the organization has protected private information. It doesn't have anything to do with correcting wrong information.
Which organization develops cybersecurity standards and guidance?
NIST