Becker - ISC S1 Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/89

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:06 PM on 8/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

90 Terms

1
New cards

National Institute of Standards and Technology (NIST)

Established to remove barriers to industrial competitiveness and improve access to resources to promote U.S. research capabilities; Also is in the cybersecurity field

2
New cards

Cybersecurity Framework (CSF), Privacy Framework, SP 800-53 (Security and Privacy Controls for Information Systems and Organizations)

What are the three most prolific sets of standardized frameworks promulgated by NIST?

3
New cards

Cybersecurity Framework (CSF)

Voluntary framework that includes three primary components to manage cybersecurity risk:

  1. CSF Core

  2. CSF Tiers

  3. CSF Organizational Profiles

4
New cards

NIST CSF Core

Describes cybersecurity outcomes that can be used by an organization of any size

The focus is to reduce an organization’s cybersecurity risks

Has six functions

5
New cards

Govern, Identify, Protect, Detect, Respond, Recover

What are the six functions of NIST CSF Core?

6
New cards

Identify

Function of NIST CSF Core that focuses on understanding the assets and suppliers of an organization and the cybersecurity risks related to assets and suppliers

Identifies improvement opportunities related to the organization’s cybersecurity risk management policies, plans, processes, procedures, and practices

7
New cards

Protect

Function of NIST CSF Core that focuses on an organization’s ability to secure its assets to prevent or reduce the likelihood and impact of adverse cybersecurity events

Examples include identity management, authentication, access control, awareness/training, data security, platform security, and infrastructure resiliency

8
New cards

Detect

Function of NIST CSF Core that focuses on the timely discovery of cybersecurity attacks and incidents by analyzing anomalies, indicators of compromise, and other potentially adverse events that may indicate an attack or incident is occurring

9
New cards

Response

Function of NIST CSF Core that focuses on a company’s ability to contain the effects of cybersecurity incidents

Outcomes cover incident management, analysis, mitigation, reporting, and communication

10
New cards

Recover

Function of NIST CSF Core that focuses on supporting the restoration of a company’s normal operations to reduce the impact of incidents and communicating recovery efforts effectively and appropriately

11
New cards

NIST CSF Tiers

Categorize the degree to which information security practices are integrated throughout an organization

Should complement an organization’s existing cybersecurity risk management methodology and can be used as a benchmark to communicate its organization-wide approach to managing cybersecurity risks

12
New cards

CSF Organizational Profiles

Mechanisms by which NIST recommends companies measure cybersecurity risk and how to minimize such risk

Determine success or failure of information security implementation

Should have a Current Profile (the outcome that an organization is achieving) and a Target Profile (the desired outcome that an organization has prioritized achieving)

13
New cards

Community Profiles

Baseline outcomes developed among a number of organizations due to the shared interest and goals of a particular industry sector, topic, or use case

14
New cards

Scope Profile, Gather Information, Create Profile, Analyze Gaps, Implement Action Plan

What is the repeatable, five-step approach in using Organization Profiles to help inform continuous improvement of an organization’s cybersecurity posture?

15
New cards

Partial, Risk-Informed, Repeatable, Adaptive

What are the four NIST CSF Tiers?

16
New cards

Partial

NIST CSF Tier in which risk management is ad hoc and reactive where prioritization of information security efforts is not formally based on organizational objectives or threat environment

There is limited awareness of cybersecurity risks at the organizational level

The organization implements cybersecurity risk management on an irregular, case-by-case basis and does not have processes that allow cybersecurity information to be shared within the organization for general awareness

17
New cards

Risk-Informed

NIST CSF Tier in which cybersecurity prioritization is based on organizational risk, and management approves cybersecurity efforts; however, cybersecurity policies may be isolated and not be established as organizational-wide policies

The organization is aware of the cybersecurity risks in general and specific risks associated with its suppliers, as well as the products and services it acquires and uses, but it does not act consistently or formally in response to those risks

18
New cards

Repeatable

NIST CSF Tier in which the organization utilizes cybersecurity in planning and has enshrined cybersecurity practices in formal, documented policies that are frequently updated based on shifts in business requirements, threats, and technological landscape

There is an organization-wide risk approach to cybersecurity where risks of assets, suppliers, and products and services are consistently and accurately monitored, as well as regularly communicated among senior leadership

19
New cards

Adaptive

NIST CSF Tier in which there is a risk-informed, organization-wide approach in managing cybersecurity risks

Senior executives monitor cybersecurity risks in the same context as financial and other organizational risks and cybersecurity risk management is part of the organizational culture

Through a process of continuous improvement that incorporates advanced cybersecurity technologies and practices, the organization actively adapts to a changing technological landscape and responds in a timely, effective manner to evolving, sophisticated threats

20
New cards

Identify, Govern, Control, Communicate, Protect

What are the five functions of the NIST Privacy Framework?

21
New cards

NIST Privacy Framework

Framework that was developed to protect individuals’ data as used in data processing applications and to be industry agnostic

Leverages a similar structure to the NIST CSF, so there is a degree of overlap between both frameworks

22
New cards

NIST SP 800-53

Set of security and privacy controls applicable to all information systems and now the standard for federal information security systems

Stricter standard compared to the NIST CSF or Privacy Frameworks

Controls are designed for protecting information systems against sophisticated threats; It can become burdensome given that there are nearly 1,200 detailed controls

23
New cards

Common (Inheritable), System-Specific, Hybrid

What are the three control implementation approaches that are to be implemented on a per-control basis according to NIST SP 800-53?

24
New cards

Common (Inheritable) Control

Implement controls at the organizational level, which are adopted by information systems

25
New cards

System-Specific Control

Implement controls at the information system level

26
New cards

Hybrid Control

Implement controls at the organization level where appropriate and the rest at the information system level

27
New cards

True

There is no single federal law that applies generally and regulates all personal data.

True or False?

28
New cards

Data Breach

The exposure of confidential information to unauthorized persons

Have significant consequences such as business disruption, reputational harm, financial loss, data loss, potential legal/regulatory implications, etc

29
New cards

Unintentional Data Breach

A breach resulting from negligence or error

30
New cards

Intentional Data Breach

A breach resulting from bad actors illegally gaining access to data

31
New cards

Detection/Escalation, Notification, Post-Breach Response, Loss of Business/Revenue

What are the four categories of expenditures related to a data breach?

32
New cards

Health Insurance Portability and Accountability Act (HIPAA)

Required the Department of Health and Human Services to adopt national standards promoting health care privacy and security

Applies to specific healthcare-related entities and businesses, called “covered entities,” which include health care providers, health plans, health care clearing houses, and service providers

33
New cards

Health Information Technology for Economic and Clinical Health (HITECH) Act

Amendment to HIPAA to promote the transition from paper to electronic records

Increased penalties for HIPAA violations, required that patients receive the option to obtain records in electronic form, and added “business associates” as a covered entity

Added breach notification rules requiring that covered entities provide notice of a breach to impacted individuals within 60 days after discovery of the breach

34
New cards

General Data Protection Regulation (GDPR)

Became the EU’s general applicability law regulating the privacy of data

Provides circumstances when it is lawful to process personal data, such as with proper consent or when complying with a legal obligation

One of the strictest privacy laws in the world

Scope extends well beyond the EU

35
New cards

Payment Card Industry Data Security Standard (PCI DSS)

A framework for entities to apply in an effort to promote data security when processing payments

Subjected data includes both cardholder data and sensitive authentication data (collectively referred to as account data)

36
New cards

Build/Maintain Secure Network/Systems, Protect Account Data, Maintain Vulnerability Management Program, Implement Strong Access Control Measures, Regularly Monitor/Test Networks, Maintain Information Security Policy

What are the six goals of PCI DSS?

37
New cards

Center for Internet Security (CIS) Controls

Recommended set of actions, processes, and best practices that can be adopted and implemented by organizations to strengthen their cybersecurity defenses

Currently supported by the SANS Institute which provides training, administers certification, and performs research

Task-focused and organized by activities

Each one has recommendations prescribed to achieve the control objective, which are referred to as Safeguards

38
New cards

Context, Coexistence, Consistency

What are the three design principles of CIS Controls?

39
New cards

IG1

Implementation group for CIS Controls that is for small or medium-sized organizations that have a limited cybersecurity defense mechanism in place in terms of personnel or IT assets

The main focus of this group is to keep the company operational because their cybersecurity expertise is limited, the data being used is not sensitive, and the company cannot sustain long periods of downtime

Tiers 1 and 2 (from the NIST Cybersecurity Framework) would fall into this group

40
New cards

IG2

Implementation group for CIS Controls that is for companies that have IT staff who support multiple departments that have various risk profiles

These organizations typically have sensitive client data, and they can tolerate short interruptions in service

One of the biggest concerns for these entities is loss of trust in the event of a data breach

Tier 3 (from the NIST Cybersecurity Framework) would fall into this group

41
New cards

IG3

Implementation group for CIS Controls that is for organizations that have security experts in all of the domains within cybersecurity like penetration testing, risk management, and application security

Data assets under management at these companies include those that are sensitive and likely subject to compliance with standards or regulatory oversight

Attacks on these organizations can cause significant damage to the company and the public welfare

Tier 4 (from the NIST Cybersecurity Framework) would fall into this group

42
New cards

Inventory and Control of Enterprise Assets (CIS Control 01)

This control helps organizations actively track and manage all IT assets connected to a company’s IT infrastructure physically or virtually within a cloud environment

This allows companies to know the totality of IT assets that should be monitored and protected

Using an IT inventory list will allow organizations to track various data points for company assets

Having a comprehensive view of company assets will also give visibility into how data flows throughout an organization

Companies should also focus on the potential for external devices to connect to a company’s network through means such as guest networks, even if they are segregated from the core network

43
New cards

Inventory and Control of Software Assets (CIS Control 02)

This control provides recommendations for organizations to track and actively manage all software applications so that only authorized software is installed on company devices

Also provides guidance on finding unmanaged and unauthorized software already installed so that it can be removed and remediated

Control lists and policies should be in place so that only approved software is installed on company devices

44
New cards

Data Protection (CIS Control 03)

This control helps organizations develop ways to securely manage the entire life cycle of their data, from the initial identification and classification data to its disposal

Organizations must identify, archive, label, and classify their data to understand the implications of the data being lost or compromised

Classification categories are labeled at the discretion of the enterprise and should be assigned based on sensitivity, such as “internal,” “public,” “sensitive,” and “confidential”

Data mapping should be developed that identifies the various software applications that access each of these sensitivity levels

Retention requirements, access control lists, access logging mechanisms, and data disposal plans can also be implemented in a tailored fashion once data classification levels are assigned

45
New cards

Secure Configuration of Enterprise Assets and Software (CIS Control 04)

This control helps organizations establish and maintain secure baseline configurations for their enterprise assets including servers, network devices, mobile/portable end-user devices, non-computing assets, operating systems, and other corporately managed hardware or software

Publicly available security standards can be used by organizations as a starting point for asset reconfiguration

Security hardening can be incorporated into adjusting target security configurations so that they are continuously “hardened” against new forms of attack

46
New cards

Account Management (CIS Control 05)

This control outlines best practices for companies to manage credentials and authorization for user accounts, privileged user accounts, and service accounts for company hardware and software

Accounts must be inventoried and tracked so that appropriate controls may be applied

Administrator accounts should be restricted to specific use cases

One common and convenient form of authentication is single sign-on (SSO)

47
New cards

Access Control Management (CIS Control 06)

This control expands on Account Management (CIS Control 05) by specifying the type of access that user accounts should have

These methodologies assist with the goal that users only have access to systems, services, and data needed to perform their job duties

Accounts that do not follow these principles pose a security risk to the organization by allowing unauthorized access

Protocols should be put in place for granting access and revoking access based on job duties, roles, and responsibilities

A comprehensive solution, ideally centralized, for provisioning and de-provisioning employee access should also be in place

48
New cards

Continuous Vulnerability Management (CIS Control 07)

This control assists organizations in continuously identifying and tracking vulnerabilities within its infrastructure so that it can remediate and eliminate weak points or windows of opportunity for bad actors

An evolving cybersecurity landscape requires organizations to keep abreast of threats and vulnerabilities to be able to defend against them

Organizations must remain proactive in scanning, monitoring, and managing vulnerabilities to reduce the window of opportunity for attackers to capitalize on them

49
New cards

Audit Log Management (CIS Control 08)

This control establishes an enterprise log management process so that organizations can be alerted and recover from an attack in real time, or near real time, using log collection and analytic features

Having access to event logs is critical to incident response, and it can also facilitate processes for legal matters, such as eDiscovery, accountability for auditing, lessons learned for process improvement, and data retention for compliance requirements

An enterprise log management process should address the entire life cycle of audit logs beginning with log collections and ending with log disposal

Audit logs may be captured from a variety of connection methods

Organizations should also be notified when failed user attempts are made to connect to resources without the appropriate privileges

50
New cards

Email and Web Browser Protections (CIS Control 09)

This control provides recommendations on how to detect and protect against cybercrime attempted through email or the internet by directly engaging employees

Attacks such as phishing scams and business email compromise can be conducted by attackers using email to target senior executives who control data and financial resources or target high-value assets with data that could be used for exploitation or financial gain

It is recommended that policies and tools be put in place to enforce URL filtering, block certain file types, and restrict options such as the ability for users to install add-ons

51
New cards

Malware Defenses (CIS Control 10)

This control assists companies in preventing the installation and propagation of malware onto company assets and its network

Malware can come in many forms such as viruses, worms, spyware, adware, keyloggers, and ransomware

Endpoint assets and devices can be leveraged as both entry points and targets for malware

Anti-malware solutions should be automated, centrally managed, maintained, and deployed to all potential entry points

As malware defenses become better at defending against threats, some malicious actors have adjusted their tactics to what is known as LotL, or “living-off-the-land”

Hackers use stolen credentials, power shell, FTP, Windows Management Instrumentation (WMI) interface, and other built-in tools

52
New cards

Data Recovery (CIS Control 11)

This control establishes data backup, testing, and restoration processes that allow organizations to effectively recover company assets to a pre-incident state

Organizational data is a critical resource for conducting business and can be targeted by ransomware attacks that encrypt data and leave criminals demanding ransom for its restoration

Human error, misconfigurations, and natural factors (power outages, flooding, etc) can also cause data to become unusable or unavailable

Data value, sensitivity, classification, and retention requirements all factor into the mechanisms and cadence that will be used for backup and storage methods

Automating the backup process, utilizing off-site storage in a different geographical location, and using encryption are all recommended practices

53
New cards

Network Infrastructure Management (CIS Control 12)

This control establishes procedures and tools for managing and securing a company’s network infrastructure

Network architecture documentation and diagrams should be kept up to date to accurately reflect the organization’s network topology and layout

Organizations must continuously identify and remediate insecure default network configuration settings, misconfigured network settings, insecure protocol usage, and outdated network software

54
New cards

Network Monitoring and Defense (CIS Control 13)

This control establishes processes for monitoring and defending a company’s network infrastructure against internal and external security threats

Two common ways networks can be attacked include denial of service (DoS) attacks and ransomware

Organizations should establish event logging and alerting mechanisms that can be implemented through tools such as security information and event management (SIEM) to help centralize and assist in log analysis

Traffic flow monitoring, alerting, and detection safeguards can also be implemented with tools such as NIPS, NGFW, DLP, and EDR systems

Many organizations have their own security or network operations center that is uniquely equipped to run a robust IT networking operation

55
New cards

Denial of Service (DoS) Attacks

Involve a perpetrator overwhelming a company’s network by flooding the network with illegitimate requests so that it is effectively rendered useless

56
New cards

Ransomware Attacks

Situations in which an attacker or group of attackers gain access to a company’s system, block employees from accessing it, demand payment to regain access, and threaten to either keep all systems blocked or publish sensitive data to the public (or dark web) if the company doesn’t comply

57
New cards

Security Awareness and Skills Training (CIS Control 14)

This control guides organizations in establishing a security awareness and training program to reduce cybersecurity risk

One of the goals of this type of training is to influence employee behavior in a way that makes them conscious about the various tactics that can be employed by attackers to allow unauthorized access

Uninformed employees pose one of the greatest risks to the security of an organization and risks can originate externally or internally

Regular training is one of the best ways to establish security awareness

Training should not be reduced to an annual occurrence, but should be more frequent and include messages that resonate with users

58
New cards

Service Provider Management (CIS Control 15)

This control helps organizations develop processes to evaluate third-party service providers that have access to sensitive data or are responsible for managing some or all of a company’s IT functions

Risks can be introduced by third-party service providers that do not hold themselves to the same security standards as the other organization

It is recommended that companies establish service provider management processes to oversee the entire service provider lifecycle

59
New cards

Application Software Security (CIS Control 16)

This control establishes safeguards that manage the entire lifecycle of software that is acquired, hosted, or developed in-house to detect, deter, and resolve cybersecurity weaknesses before they are exploited

Software vulnerabilities may exist for various reasons like a flawed design, poor infrastructure, coding errors, poor authentication protocols, and the failure to test for software anomalies

IT managers must consider whether best practices and safeguards are being followed such as secure design standards, secure code reviews, and security testing tools are integrated into the software development lifecycle

One common blind spot modern organizations have is the lack of visibility into Software-as-a-Service (SaaS) platforms

Some larger organizations may consider implementing a bug bounty program in which employees are paid for finding flaws in company-produced or company-used software

60
New cards

Incident Response Management (CIS Control 17)

This control provides the recommendations necessary to establish an incident response management program to detect, respond, and prepare for potential cybersecurity attacks, because when these attacks occur, their impact can be widespread throughout the organization

In certain cases, laws and regulations may require notification of data breaches and impose fines for noncompliance, which makes it imperative to have programs in place to detect, contain, and eliminate threats

The incident response process should include the designation of a key contact, the establishment of an incident response team, and the development of communication plans for notifying impacted business units, stakeholders, and regulatory agencies

It is also important to periodically carry out exercises to test the incident response process to ascertain its effectiveness and identify opportunities for improvement

61
New cards

Penetration Testing (CIS Control 18)

This control helps organizations test the sophistication of their cybersecurity defense system in place by simulating actual attacks in an effort to find and exploit weaknesses

Testing in this control is different than vulnerability testing in Control 7 in that this testing seeks to go beyond identifying weaknesses

“Red Team” exercises focus on specific tactics, techniques, and procedures (TTPs) to see how an organization fares against certain types of attackers; Each industry is exposed to a different mix of cybersecurity risks, with some bearing more risk simply due to the nature of the business

Generally begins with a discovery or observation of an organization’s environment, followed by scanning to locate vulnerabilities that can be used to gain access

62
New cards

Control Objectives for Information and Related Technologies (COBIT)

Widely used IT governance framework

Provides a roadmap that organizations can use to implement best practices for IT governance and management

63
New cards

Governance

Organizational ______ is typically the responsibility of a company’s board of directors, consisting of a chairperson and focused organizational structures (e.g., audit committee, executive committee, marketing committee)

64
New cards

Management

Selected and guided by the board of directors and is responsible for the daily planning and administration of company operations

Generally consists of CEO, CFO, COO, and other executive leaders

65
New cards

Internal Stakeholders

Include the board of directors and management

Others include business managers, IT managers, assurance providers, and risk managers

66
New cards

External Stakeholders

Include regulators, investors, business partners, and IT vendors

Parties who are entitled to some information about compliance and risk mitigation but are not entitled to the same information given to internal parties

67
New cards

Value, Holistic, Dynamic, Distinct, Tailored, End-to-End

What are the six principles for a governance system that were used to develop the COBIT 2019 core model?

68
New cards

Provide Stakeholder (Value)

Principle for a governance system

Governance systems should create value for the company’s stakeholders by balancing benefits, risks, and resources

This should be accomplished through a well-designed governance system with an actionable strategy

69
New cards

(Holistic) Approach

Principle for a governance system

Governance systems for IT can comprise diverse components, collectively providing a holistic model

70
New cards

(Dynamic) Governance System

Principle for a governance system

When a change in one governance system occurs, the impact on all others should be considered so that the system continues to meet the demands of the organization

71
New cards

Governance (Distinct) From Management

Principle for a governance system

Management activities and governance systems should be clearly distinguished from each other because they have different functions

72
New cards

(Tailored) to Enterprise Needs

Principle for a governance system

Governance models should be customized to each individual company, using design factors to prioritize and tailor the system

73
New cards

(End-to-End) Governance System

Principle for a governance system

More than just the IT function should be considered in a governance system; All processes in the organization involving information and technology should be factored into this approach

74
New cards

Conceptual, Flexible, Aligned

What are the three principles for a governance framework?

75
New cards

COBIT Core Model

Governance and management objectives should be set so that information technology and systems contribute to company goals

  1. Goals are established

  2. Governance and management objectives are developed to help achieve goals

  3. Information technology and systems are utilized to help meet objectives and ultimately reach goals

76
New cards

Governance Objectives

Always relate to a governance process, which board of directors are responsible for

77
New cards

Management Objectives

Always associated with management processes, which middle and senior management are responsible for

78
New cards

Evaluate, Direct, and Monitor (EDM)

Domain that governance objectives are grouped into in the COBIT Core Model

Those charged with governance evaluate strategic objectives, direct management to achieve those objectives, and monitor whether objectives are being met

There are five more specific objectives within this domain

79
New cards

Align, Plan, and Organize (APO)

One of the domains that management objectives are grouped into in the COBIT Core Model

Focuses on aligning information technology’s overall strategy, planning how to utilize technology in business operations of the organization, and organizing the resources for their most effective and efficient usage

There are fourteen more specific objectives within this domain (Managed Data is one of the most significant)

80
New cards

Build, Acquire, and Implement (BAI)

One of the domains that management objectives are grouped into in the COBIT Core Model

Addresses the building, acquiring, and implementation of information technology solutions in the organization’s business processes

There are eleven more specific objectives within this domain that offer guidance on requirements definition, identifying solutions, managing capacity, dealing with organizational and IT change, managing knowledge, administering of assets, and managing configuration

81
New cards

Deliver, Service, and Support (DSS)

One of the domains that management objectives are grouped into in the COBIT Core Model

Addresses the delivery, service, and support of IT services

There are six more specific objectives within this domain that cover managed operations, service requests, managed problems, continuity, security services, and business process controls

82
New cards

Monitor, Evaluate, and Assess (MEA)

One of the domains that management objectives are grouped into in the COBIT Core Model

Addresses information technology’s conformance to the company’s performance targets and control objectives along with external requirements

This is accomplished through continuous monitoring, evaluation, and assessment of information technology systems, controls, and components

There are four more specific objectives within this domain that cover managed performance/conformance monitoring, managed system of internal control, compliance with external requirements, and managed assurance

This must be done over the other three management objectives (APO, BAI, DSS)

83
New cards

Processes, Organization Structures, Principles/Policies/Frameworks, Information, Culture/Ethics/Behavior, People/Skills/Competencies, Services/Infrastructure/Applications

What are the seven components of the governance system per the COBIT Core Model?

84
New cards

Design Factors

Per COBIT, these influence the design of a company’s IT governance system, with a total of eleven factors that should be considered:

  • Enterprise Strategy

  • Enterprise Goals (Financial, Customer, Internal, Growth)

  • Risk Profile

  • Information and Technology

  • Threat Landscape

  • Compliance Requirements

  • Role of IT

  • Sourcing Model for IT

  • IT Implementation Methods

  • Technology Adoption Strategy

  • Enterprise Size

85
New cards

Support IT

An IT system that is not critical for operating a business or maintaining continuity

86
New cards

Factory IT

An IT system that will have an immediate impact in business operations and continuity if it fails

87
New cards

Turnaround IT

An IT system that drives innovation for the business but is not required for critical business operations

88
New cards

Strategic IT

An IT system that is crucial for both innovation and business operations

89
New cards

Focus Areas

Different types of governance issues, domains, or topics that can be solved by a combination of management and governance objectives, along with their underlying components

90
New cards

Introduction/Methodology (Framework), Governance/Management Objectives (Framework), Designing IT Governance Solution (Design Guide), Implementing/Optimizing IT Governance Solution (Implementation Guide)

What four publications are the roadmap to help achieve proper customization of the COBIT framework recommendations?