SSCP Domain 1

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/25

flashcard set

Earn XP

Description and Tags

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

26 Terms

1
New cards

What is the purpose of security policies in an organization?

To define expectations, rules, and responsibilities for securing assets and data.

2
New cards

What are the three main types of security controls?

Administrative, technical (logical), and physical controls.

3
New cards

What does 'least privilege' mean in security operations?

Giving users only the access needed to perform their job duties — no more, no less.

4
New cards

What is Separation of Duties (SoD)?

No one person should control all critical aspects of a function to reduce fraud and error risk.

5
New cards

What does the principle of Need to Know entail?

Access should be granted only if information is required to perform a specific task.

6
New cards

What is Mandatory vacation in security controls?

Forcing employees to take time off to detect fraudulent activity that may require their presence.

7
New cards

What is a Policy in the context of security?

High-level direction.

8
New cards

What is a Standard in the context of security?

Mandatory rules.

9
New cards

What is a Guideline in the context of security?

Optional recommendations.

10
New cards

What is a Procedure?

Step-by-step instructions.

11
New cards

What is Configuration management?

A structured approach to controlling changes to IT systems to maintain integrity and security.

12
New cards

What is patch management?

The process of identifying, acquiring, installing, and verifying software updates to address vulnerabilities.

13
New cards

Why are security awareness programs important?

They educate users about security risks and their role in preventing breaches.

14
New cards

What does personnel security entail?

Hiring practices, background checks, onboarding/offboarding, and role-based training.

15
New cards

What are administrative controls?

Policies, procedures, and guidelines implemented by management to manage personnel and data.

16
New cards

What does auditing and accountability involve in operations?

Tracking user activity and ensuring actions can be linked to individuals.

17
New cards

What is Due Care?

Acting responsibly to protect assets.

18
New cards

What is Due Diligence?

Ongoing activities to assess and mitigate risks.

19
New cards

What is job rotation?

Regularly changing job roles to prevent collusion and identify suspicious activity.

20
New cards

What does 'clean desk' policy refer to?

No sensitive papers visible when unattended.

21
New cards

What does 'clear screen' policy refer to?

Lock or log off when leaving the computer.

22
New cards

What is privilege creep?

The accumulation of unnecessary access rights over time.

23
New cards

What is change management?

A formal process to request, review, approve, and implement system modifications.

24
New cards

What is onboarding in the context of security?

Granting access when someone joins the organization.

25
New cards

What is offboarding in the context of security?

Revoking access when someone leaves the organization.

26
New cards

What is background screening?

Verifying a person's history and suitability for a position of trust.