1/94
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What do security policies define, and what questions do they answer?
Security policies define the rules and high-level strategies used to provide confidentiality, integrity, and availability. They cover areas such as data storage, security events, Wi-Fi, and remote access and answer the "what" and "why," while technical controls answer the "how."
What is an information security policy?
A centralized resource containing an organization's security-related policies, compliance requirements, detailed security procedures, and roles and responsibilities; the organization must actively enforce these policies.
What is an Acceptable Use Policy (AUP)?
Detailed documentation defining acceptable use of company assets such as Internet access, telephones, computers, and mobile devices; it may be part of Rules of Behavior and can help limit legal liability.
What is the purpose of business continuity planning?
To document and test alternatives that allow the organization to continue operating during disruptions, such as manual transactions, paper receipts, and phone calls for transaction approvals.
What is a disaster recovery plan?
A component of business continuity planning that prepares IT for natural, technological, system, or human-created disasters and addresses recovery location, data recovery, application restoration, and personnel availability.
What are examples of security incidents in the notes?
Executing malware from an email attachment, a DDoS botnet attack, theft of confidential information, and peer-to-peer software allowing external access to internal servers.
Who may participate in incident response?
A specialized incident response team, IT security management, compliance officers, technical staff, and the user community.
What are the four phases of the NIST SP 800-61 incident response lifecycle?
Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-incident Activity.
What is the Software Development Life Cycle (SDLC)?
A framework for moving from an idea to an application while managing customer requirements, schedules, budgets, and the many parts of development; there is no single best method.
Why is change management important?
Changes such as software upgrades, firewall configuration changes, and switch-port modifications are common enterprise risks, so policies should define frequency, duration, installation processes, and fallback procedures.
What are security standards?
Formal definitions for using security technologies and processes so expectations are clearly documented and security risk is reduced; standards may be created internally or come from organizations such as ISO and NIST.
What should password security standards address?
Password complexity, acceptable authentication methods, secure password-reset procedures, password-change frequency, secure password storage, and password-manager options.
What should access-control standards define?
Which information can be accessed, when and under what circumstances, permitted access-control types, how privileges are granted, and how access is removed because of issues such as expiration or contract changes.
What should physical security standards define?
Rules for doors, building and property access, employee versus visitor access, electronic locks, monitoring, motion detection, escorts, and offboarding.
What should encryption standards define?
Specific methods for encrypting and securing data, including password-storage techniques and minimum algorithms or requirements for data in use, in transit, and at rest.
What is change control?
A formal process for managing changes by defining scope, analyzing risk, creating a plan, obtaining approval, presenting it to the change control board, preparing a backout plan, and documenting the change.
What occurs during onboarding?
New hires or transfers sign required IT agreements, receive appropriate accounts and group or department memberships, and are provided preconfigured hardware such as laptops or tablets.
What should occur during offboarding?
The process should be planned in advance and determine what happens to hardware and data; account information is usually deactivated but is not always deleted.
What is a security playbook?
A step-by-step set of conditional processes for situations such as investigating a breach or recovering from ransomware; it can be a manual checklist or support automated activities and is often integrated with SOAR.
Why must security procedures and playbooks be monitored and revised?
Security constantly changes, so organizations must update their security posture, change-control practices, playbooks, checks, and individual procedures as new concerns emerge.
What governance structures are described in the notes?
Boards gather or review information, committees of subject-matter experts determine next steps, government entities operate with legal and administrative requirements, centralized governance concentrates decisions, and decentralized governance distributes them.
What regulatory and legal considerations can affect security?
Regulations can mandate logging, data storage, protection, and retention; legal duties can include reporting illegal activities, preserving data for legal proceedings, breach notifications, and handling data across jurisdictions.
How can industry and geography affect security requirements?
Industries have different needs, such as isolated controls for utilities and strong storage, access logging, and encryption for medical data; requirements also differ at local, national, and global levels.
How do a data owner and a data controller differ?
A data owner is accountable for specific organizational data, often as a senior officer, while a data controller determines the purposes and means by which personal data is processed.
How do a data processor and data custodian or steward differ?
A data processor processes information on behalf of the controller, while a custodian or steward works directly with data to maintain accuracy, privacy, security, sensitivity labels, access rights, compliance, and security controls.
What is the purpose of risk management?
To understand potential risks, identify weaknesses before they become problems, manage potential risk, qualify internal and external threats, and use risk analysis to plan contingencies.
How do one-time and continuous risk assessments differ?
A one-time assessment may support a specific project such as an acquisition or equipment installation, while continuous assessments are part of an ongoing process such as change control.
How do ad hoc and recurring risk assessments differ?
An ad hoc assessment occurs when a situation requires it and may use a temporary committee; a recurring assessment occurs at established intervals or because a requirement mandates it.
How do qualitative and quantitative risk assessments differ?
Qualitative assessment uses opinions and descriptive significance, often displayed with a traffic-light grid; quantitative assessment uses numerical and monetary measurements.
What is Annualized Rate of Occurrence (ARO)?
A quantitative measurement estimating how often an event is expected to occur during a year.
What are Asset Value (AV) and Exposure Factor (EF)?
AV is the value of an asset to the organization, including direct and indirect effects; EF is the percentage of that value expected to be lost in a single incident.
What is Single Loss Expectancy (SLE), and how is it calculated?
The monetary loss expected from one event; SLE = Asset Value × Exposure Factor.
What is Annualized Loss Expectancy (ALE), and how is it calculated?
The expected annual monetary loss from a risk; ALE = Annualized Rate of Occurrence × Single Loss Expectancy.
What types of impact should be considered during risk analysis?
Life, property, safety, finance, and reputation, with life identified as the most important consideration.
What is the difference between risk likelihood and risk probability?
Risk likelihood is qualitative, using terms such as rare, possible, or almost certain; risk probability is quantitative and statistical and may be based on historical performance.
What are risk appetite, risk appetite posture, and risk tolerance?
Risk appetite describes the amount of risk considered acceptable before action is taken; posture describes readiness as conservative, neutral, or expansionary; tolerance is the acceptable variance from the appetite.
What is a risk register?
A documented record of project risks that identifies risks at each step, possible solutions, and the results of monitoring those risks.
What are key risk indicators, risk owners, and risk thresholds?
Key risk indicators identify risks that could affect the organization, risk owners are assigned responsibility for managing them, and a risk threshold compares mitigation cost with the value gained by mitigation.
What does transferring risk mean?
Moving risk to another party, such as by purchasing cybersecurity insurance.
What does accepting risk mean?
Making a business decision to take the risk rather than eliminate or reduce it.
How do accepting with an exemption and accepting with an exception differ?
An exemption applies when a security policy or regulation cannot be followed and may require approval; an exception occurs when an internal policy is temporarily not applied because of a specific circumstance.
How do risk avoidance and risk mitigation differ?
Avoidance stops participation in a high-risk activity and therefore removes the risk; mitigation decreases the level of risk, such as by investing in security systems.
What is a risk report?
A formal document describing identified risks in detail, commonly provided to senior management to support decisions about resources, budgets, and additional security tasks, especially for critical and emerging risks.
What is the difference between RTO and RPO?
Recovery Time Objective (RTO) is how quickly a service must return to an acceptable operating level; Recovery Point Objective (RPO) is how much data loss is acceptable or how far back recovered data may go.
What is the difference between MTTR and MTBF?
Mean Time to Repair (MTTR) is the average time required to diagnose and fix an issue; Mean Time Between Failures (MTBF) measures time between outages and can help predict or statistically plan for failures.
Why is third-party risk management necessary?
Organizations share important data with vendors for services such as payroll, CRM, email marketing, travel, and cloud services, so risks should be assessed by vendor and expectations enforced through contracts.
Why might an organization use third-party penetration testing and right-to-audit clauses?
Third-party pentesters provide specialized attack testing, while a right-to-audit clause gives the organization a legal option to perform a security audit of a business partner or provider.
Why should organizations obtain evidence of vendor internal audits?
Internal audits help verify security controls and processes such as access management, offboarding, password security, and VPN controls, and should be performed at reasonable intervals.
What is supply chain analysis?
Evaluating the systems, organizations, people, activities, and resources involved in moving a product or service from supplier to customer to identify weaknesses and opportunities for improvement.
What is an independent security assessment?
An evaluation performed by an outside specialist or team that reviews security and provides recommendations based on specialized experience.
What is due diligence during vendor selection?
Investigating and verifying a potential vendor before doing business, including financial status, legal issues, background checks, and personnel interviews.
What is a conflict of interest in third-party management?
A personal or business interest that could compromise judgment, such as a vendor working with a major competitor, employing a decision maker's relative, or offering gifts for signing a contract.
What is vendor monitoring?
Ongoing review of a vendor after a contract is signed, including financial health, IT security, news, social media, and other quantitative or qualitative indicators, usually managed by an assigned relationship owner.
How are questionnaires used in third-party risk management?
They obtain security information directly from vendors about topics such as due diligence, disaster recovery, and secure data storage, and the results update the vendor risk analysis throughout the relationship.
What should rules of engagement define?
The testing purpose and scope, test type and schedule, IP ranges, emergency contacts, handling of sensitive information, and in-scope and out-of-scope devices or applications.
What is a Service Level Agreement (SLA)?
An agreement defining minimum service terms such as uptime and response time, commonly used between customers and service providers.
How do a Memorandum of Understanding (MOU) and Memorandum of Agreement (MOA) differ?
An MOU is generally an informal understanding of common goals and may include confidentiality; an MOA is a step above an MOU and conditionally agrees to objectives but may still lack legally enforceable promises.
What is a Master Service Agreement (MSA)?
A legal contract establishing a broad framework and terms for future transactions and projects so detailed negotiations do not have to be repeated for every engagement.
What is a Work Order or Statement of Work (SOW)?
A specific list of work to be completed, often used with an MSA, describing items such as scope, location, deliverables, schedule, and acceptance criteria.
How do an NDA and a Business Partners Agreement (BPA) differ?
An NDA is a formal confidentiality agreement protecting information such as trade secrets and business activities; a BPA defines a business partnership, including ownership, finances, decision-making, and contingencies.
What is compliance?
Meeting the requirements of laws, policies, and regulations; requirements may be industry-specific, situational, domestic, or international, and penalties can include fines, job loss, or incarceration.
How do internal and external compliance reporting differ?
Internal reporting monitors organizational compliance and may support customers or investors; external reporting is required by regulators or industries and may be annual or ongoing, with invalid or missing reports potentially causing penalties.
What regulatory compliance examples are identified in the notes?
Sarbanes-Oxley Act (SOX), the Health Insurance Portability and Accountability Act (HIPAA), and the Gramm-Leach-Bliley Act (GLBA).
What reputational consequences can result from a security or compliance failure?
Organizations may have to disclose breaches, suffer damage to public reputation, and experience financial effects such as short-term declines in stock price.
What other consequences can non-compliance cause?
Loss of a license can prevent an organization from selling products and be costly to reverse, while inadequate compliance can also breach contractual requirements.
What is compliance monitoring?
Ensuring that compliance requirements are followed in day-to-day operations using internal tools, third-party participation where required, and ongoing monitoring.
How do due care and due diligence differ in compliance?
Both involve acting honestly and in good faith and investigating or verifying; due care generally refers to internal activities, while due diligence is often associated with third-party activities.
What are attestation and acknowledgment in compliance?
A formal sign-off on compliance documentation in which someone accepts responsibility for the accuracy of the information; large organizations commonly use automation to collect, compile, and report compliance data.
How can privacy requirements vary geographically?
Privacy guidelines may be local or regional through state and local rules, national through country-wide privacy laws, or global through cooperation and regulations spanning countries.
What is GDPR, and what is a data subject?
The General Data Protection Regulation protects personal data and privacy for individuals in the European Union and gives data subjects control over personal information, including a right to be forgotten; a data subject is an identified or identifiable person to whom personal data relates.
What is a data inventory, and what should it document?
A listing of all managed data that records information such as the owner, update frequency, and data format; internal and external data use should follow applicable laws and regulations.
What is the purpose of a cybersecurity audit, and what is attestation?
A cybersecurity audit examines infrastructure, software, devices, policies, and procedures to identify weaknesses; attestation is an auditor's opinion regarding the truth or accuracy of an organization's security posture.
What are internal audits, audit committees, and self-assessments?
Internal audits check areas such as regulatory and industry compliance; the audit committee oversees risk-management activities, and self-assessments allow the organization to perform its own checks and consolidate results into ongoing reports.
What is an external audit?
An assessment performed by an independent third party, often because of regulatory requirements, that may examine records, compile reports, gather additional details, assess current activities, and recommend improvements.
What does physical penetration testing evaluate?
Whether physical access can bypass operating-system security through methods such as changing the boot process or OS files and whether unauthorized people can enter buildings or reach protected areas.
How do red-team, blue-team, and integrated penetration-testing perspectives differ?
The red team takes an offensive approach and attacks systems; the blue team detects and prevents attacks; an integrated approach repeatedly identifies, patches, and retests exploitable systems and services.
What are known, partially known, and unknown penetration-testing environments?
A known environment provides full disclosure, a partially known environment provides a mixture of known and unknown information focused on selected systems, and an unknown environment gives the pentester no system information and is a blind test.
What is the purpose of reconnaissance before a penetration test?
To gather a digital footprint, understand security posture and configurations, focus on key systems, and create a network map of routers, networks, and remote sites.
What is passive reconnaissance?
Gathering information from open sources without directly probing the target, including social media, corporate websites, forums, social engineering, dumpster diving, and business organizations.
What is active reconnaissance?
Directly probing the environment in ways visible in network traffic and logs, such as ping scans, port scans, DNS queries, OS fingerprinting, and service or version scans.
Why do organizations conduct simulated phishing campaigns?
To determine how employees respond to phishing by sending simulated messages, centrally tracking incorrect clicks, and providing immediate feedback, training, or additional in-person instruction.
What indicators can help users recognize phishing?
Spelling and grammatical errors, inconsistent domain or email information, unusual attachments, and requests for personal information.
How should suspicious email messages be handled?
Email filtering can remove many threats, users should not click suspicious links or run attachments, and organizations should maintain a process for reporting suspected phishing.
What are risky, unexpected, and unintentional anomalous behaviors?
Risky behavior includes changing hosts or core OS files or uploading sensitive files; unexpected behavior includes foreign-country logins or increased data transfers; unintentional behavior includes mistyped domains, misplaced USB drives, and misconfigured security settings.
What security-awareness metrics can be monitored?
Phishing click rates, password-manager adoption, MFA use, password sharing, and other measures collected and analyzed through automated reporting.
How should initial and recurring security-awareness problems be handled?
A first occurrence can be used as a training opportunity, while long-term recurring monitoring identifies high-frequency issues and users who require additional help.
What should occur during development of a security-awareness program?
Create a security-awareness team, define training and monitoring roles, establish a minimum awareness level, vary training depth by job function, integrate compliance mandates, and define performance metrics.
What should occur during execution of a security-awareness program?
Create and deploy training materials, define how success will be measured, identify stakeholders, provide ongoing metrics, use methods such as classroom training, posters, or emails, and continuously track user training.
When should users receive security-awareness training, and who should receive specialized training?
Users should be trained before receiving access; training should reflect each role's unique responsibilities and should also apply to third parties such as contractors, partners, and suppliers.
How should policies and handbooks support user training?
Security requirements should be documented, made available through online policy guidelines, and referenced in the employee handbook.
What is situational awareness in user security training?
Users should continually look for software threats such as suspicious links, attachments, URLs, and messages and physical threats such as unknown USB drives or unlocked building doors.
How should organizations reduce insider-threat risk?
Use multiple approvals for critical processes, monitor files and systems as much as possible, and make unauthorized changes difficult to perform.
What password-management guidance should users receive?
Users should be given standard password requirements such as length and complexity, and these requirements can often be enforced through technology such as Group Policy.
Why should users be cautious with removable media, cables, and social engineering?
Unknown USB drives may contain malware, unknown cables may connect to malicious systems, and social-engineering attacks require extensive ongoing training because users are a front-line defense.
What should users understand about operational security and hybrid or remote work?
Operational security requires viewing security from an attacker's perspective, identifying sensitive information, and keeping it private; remote work also requires protecting endpoints, restricting family or friend access, and following VPN security policies.