Untitled Flashcards Set

0.0(0)
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/19

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

20 Terms

1
New cards

What are step-by-step instructions designed to assist employees in following policies, standards, and guidelines called?

Procedures

2
New cards

What is the name of the worksheet that combines prioritized lists of assets and threats as a starting point for a risk assessment?

Threats-Vulnerabilities-Assets (TVA)

3
New cards

What is the process of implementing a formal program to continuously review and improve organizational efforts known as?

Continuous improvement

4
New cards

What is the process of assessing potential weaknesses in each information asset referred to as?

Threat assessment

5
New cards

What is a statement of the organization's position that influences decisions and actions called?

Policy

6
New cards

What are designed to modify employee behavior that endangers the security of the organization's information?

Security awareness and security training

7
New cards

What does the acronym CASP stand for in the context of a CompTIA security certification?

CompTIA Advanced Security Practitioner

8
New cards

What is a number that provides a relative risk associated with each vulnerable information asset called?

Risk rating

9
New cards

What is the process of addressing risk after it has been identified, assessed, and deemed unacceptable?

Risk treatment

10
New cards

What role combines the skills of a security technician and a security manager?

Security administrator

11
New cards

Who are the individuals accountable for the day-to-day operations of the InfoSec program?

Security managers

12
New cards

What type of document outlines the guidelines and principles governing an organization’s actions?

Policy

13
New cards

Which process aims to improve the efficiency and effectiveness of an organization's efforts continuously?

Continuous improvement

14
New cards

What term refers to the evaluation of a company's vulnerabilities to threat incidents?

Threat assessment

15
New cards

What type of training aims to raise awareness about the security of information?

Security awareness and security training

16
New cards

What is the designation for a certification that validates an expert-level security skill set?

CASP

17
New cards

What system is used to prioritize and evaluate information security risk?

Threats-Vulnerabilities-Assets (TVA)

18
New cards

What is a security professional primarily responsible for designing and implementing security measures in an organization?

Security administrator

19
New cards

Which assessment is necessary to determine the acceptable level of risk for an organization?

Risk rating

20
New cards

What do security managers oversee within an information security program?

Day-to-day operations of the InfoSec program