Comptia Sec+ (5.0 Governance, Risk, and Compliance)

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/94

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:11 AM on 8/11/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

95 Terms

1
New cards

What do security policies define, and what questions do they answer?

Security policies define the rules and high-level strategies used to provide confidentiality, integrity, and availability. They cover areas such as data storage, security events, Wi-Fi, and remote access and answer the "what" and "why," while technical controls answer the "how."

2
New cards

What is an information security policy?

A centralized resource containing an organization's security-related policies, compliance requirements, detailed security procedures, and roles and responsibilities; the organization must actively enforce these policies.

3
New cards

What is an Acceptable Use Policy (AUP)?

Detailed documentation defining acceptable use of company assets such as Internet access, telephones, computers, and mobile devices; it may be part of Rules of Behavior and can help limit legal liability.

4
New cards

What is the purpose of business continuity planning?

To document and test alternatives that allow the organization to continue operating during disruptions, such as manual transactions, paper receipts, and phone calls for transaction approvals.

5
New cards

What is a disaster recovery plan?

A component of business continuity planning that prepares IT for natural, technological, system, or human-created disasters and addresses recovery location, data recovery, application restoration, and personnel availability.

6
New cards

What are examples of security incidents in the notes?

Executing malware from an email attachment, a DDoS botnet attack, theft of confidential information, and peer-to-peer software allowing external access to internal servers.

7
New cards

Who may participate in incident response?

A specialized incident response team, IT security management, compliance officers, technical staff, and the user community.

8
New cards

What are the four phases of the NIST SP 800-61 incident response lifecycle?

Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-incident Activity.

9
New cards

What is the Software Development Life Cycle (SDLC)?

A framework for moving from an idea to an application while managing customer requirements, schedules, budgets, and the many parts of development; there is no single best method.

10
New cards

Why is change management important?

Changes such as software upgrades, firewall configuration changes, and switch-port modifications are common enterprise risks, so policies should define frequency, duration, installation processes, and fallback procedures.

11
New cards

What are security standards?

Formal definitions for using security technologies and processes so expectations are clearly documented and security risk is reduced; standards may be created internally or come from organizations such as ISO and NIST.

12
New cards

What should password security standards address?

Password complexity, acceptable authentication methods, secure password-reset procedures, password-change frequency, secure password storage, and password-manager options.

13
New cards

What should access-control standards define?

Which information can be accessed, when and under what circumstances, permitted access-control types, how privileges are granted, and how access is removed because of issues such as expiration or contract changes.

14
New cards

What should physical security standards define?

Rules for doors, building and property access, employee versus visitor access, electronic locks, monitoring, motion detection, escorts, and offboarding.

15
New cards

What should encryption standards define?

Specific methods for encrypting and securing data, including password-storage techniques and minimum algorithms or requirements for data in use, in transit, and at rest.

16
New cards

What is change control?

A formal process for managing changes by defining scope, analyzing risk, creating a plan, obtaining approval, presenting it to the change control board, preparing a backout plan, and documenting the change.

17
New cards

What occurs during onboarding?

New hires or transfers sign required IT agreements, receive appropriate accounts and group or department memberships, and are provided preconfigured hardware such as laptops or tablets.

18
New cards

What should occur during offboarding?

The process should be planned in advance and determine what happens to hardware and data; account information is usually deactivated but is not always deleted.

19
New cards

What is a security playbook?

A step-by-step set of conditional processes for situations such as investigating a breach or recovering from ransomware; it can be a manual checklist or support automated activities and is often integrated with SOAR.

20
New cards

Why must security procedures and playbooks be monitored and revised?

Security constantly changes, so organizations must update their security posture, change-control practices, playbooks, checks, and individual procedures as new concerns emerge.

21
New cards

What governance structures are described in the notes?

Boards gather or review information, committees of subject-matter experts determine next steps, government entities operate with legal and administrative requirements, centralized governance concentrates decisions, and decentralized governance distributes them.

22
New cards

What regulatory and legal considerations can affect security?

Regulations can mandate logging, data storage, protection, and retention; legal duties can include reporting illegal activities, preserving data for legal proceedings, breach notifications, and handling data across jurisdictions.

23
New cards

How can industry and geography affect security requirements?

Industries have different needs, such as isolated controls for utilities and strong storage, access logging, and encryption for medical data; requirements also differ at local, national, and global levels.

24
New cards

How do a data owner and a data controller differ?

A data owner is accountable for specific organizational data, often as a senior officer, while a data controller determines the purposes and means by which personal data is processed.

25
New cards

How do a data processor and data custodian or steward differ?

A data processor processes information on behalf of the controller, while a custodian or steward works directly with data to maintain accuracy, privacy, security, sensitivity labels, access rights, compliance, and security controls.

26
New cards

What is the purpose of risk management?

To understand potential risks, identify weaknesses before they become problems, manage potential risk, qualify internal and external threats, and use risk analysis to plan contingencies.

27
New cards

How do one-time and continuous risk assessments differ?

A one-time assessment may support a specific project such as an acquisition or equipment installation, while continuous assessments are part of an ongoing process such as change control.

28
New cards

How do ad hoc and recurring risk assessments differ?

An ad hoc assessment occurs when a situation requires it and may use a temporary committee; a recurring assessment occurs at established intervals or because a requirement mandates it.

29
New cards

How do qualitative and quantitative risk assessments differ?

Qualitative assessment uses opinions and descriptive significance, often displayed with a traffic-light grid; quantitative assessment uses numerical and monetary measurements.

30
New cards

What is Annualized Rate of Occurrence (ARO)?

A quantitative measurement estimating how often an event is expected to occur during a year.

31
New cards

What are Asset Value (AV) and Exposure Factor (EF)?

AV is the value of an asset to the organization, including direct and indirect effects; EF is the percentage of that value expected to be lost in a single incident.

32
New cards

What is Single Loss Expectancy (SLE), and how is it calculated?

The monetary loss expected from one event; SLE = Asset Value × Exposure Factor.

33
New cards

What is Annualized Loss Expectancy (ALE), and how is it calculated?

The expected annual monetary loss from a risk; ALE = Annualized Rate of Occurrence × Single Loss Expectancy.

34
New cards

What types of impact should be considered during risk analysis?

Life, property, safety, finance, and reputation, with life identified as the most important consideration.

35
New cards

What is the difference between risk likelihood and risk probability?

Risk likelihood is qualitative, using terms such as rare, possible, or almost certain; risk probability is quantitative and statistical and may be based on historical performance.

36
New cards

What are risk appetite, risk appetite posture, and risk tolerance?

Risk appetite describes the amount of risk considered acceptable before action is taken; posture describes readiness as conservative, neutral, or expansionary; tolerance is the acceptable variance from the appetite.

37
New cards

What is a risk register?

A documented record of project risks that identifies risks at each step, possible solutions, and the results of monitoring those risks.

38
New cards

What are key risk indicators, risk owners, and risk thresholds?

Key risk indicators identify risks that could affect the organization, risk owners are assigned responsibility for managing them, and a risk threshold compares mitigation cost with the value gained by mitigation.

39
New cards

What does transferring risk mean?

Moving risk to another party, such as by purchasing cybersecurity insurance.

40
New cards

What does accepting risk mean?

Making a business decision to take the risk rather than eliminate or reduce it.

41
New cards

How do accepting with an exemption and accepting with an exception differ?

An exemption applies when a security policy or regulation cannot be followed and may require approval; an exception occurs when an internal policy is temporarily not applied because of a specific circumstance.

42
New cards

How do risk avoidance and risk mitigation differ?

Avoidance stops participation in a high-risk activity and therefore removes the risk; mitigation decreases the level of risk, such as by investing in security systems.

43
New cards

What is a risk report?

A formal document describing identified risks in detail, commonly provided to senior management to support decisions about resources, budgets, and additional security tasks, especially for critical and emerging risks.

44
New cards

What is the difference between RTO and RPO?

Recovery Time Objective (RTO) is how quickly a service must return to an acceptable operating level; Recovery Point Objective (RPO) is how much data loss is acceptable or how far back recovered data may go.

45
New cards

What is the difference between MTTR and MTBF?

Mean Time to Repair (MTTR) is the average time required to diagnose and fix an issue; Mean Time Between Failures (MTBF) measures time between outages and can help predict or statistically plan for failures.

46
New cards

Why is third-party risk management necessary?

Organizations share important data with vendors for services such as payroll, CRM, email marketing, travel, and cloud services, so risks should be assessed by vendor and expectations enforced through contracts.

47
New cards

Why might an organization use third-party penetration testing and right-to-audit clauses?

Third-party pentesters provide specialized attack testing, while a right-to-audit clause gives the organization a legal option to perform a security audit of a business partner or provider.

48
New cards

Why should organizations obtain evidence of vendor internal audits?

Internal audits help verify security controls and processes such as access management, offboarding, password security, and VPN controls, and should be performed at reasonable intervals.

49
New cards

What is supply chain analysis?

Evaluating the systems, organizations, people, activities, and resources involved in moving a product or service from supplier to customer to identify weaknesses and opportunities for improvement.

50
New cards

What is an independent security assessment?

An evaluation performed by an outside specialist or team that reviews security and provides recommendations based on specialized experience.

51
New cards

What is due diligence during vendor selection?

Investigating and verifying a potential vendor before doing business, including financial status, legal issues, background checks, and personnel interviews.

52
New cards

What is a conflict of interest in third-party management?

A personal or business interest that could compromise judgment, such as a vendor working with a major competitor, employing a decision maker's relative, or offering gifts for signing a contract.

53
New cards

What is vendor monitoring?

Ongoing review of a vendor after a contract is signed, including financial health, IT security, news, social media, and other quantitative or qualitative indicators, usually managed by an assigned relationship owner.

54
New cards

How are questionnaires used in third-party risk management?

They obtain security information directly from vendors about topics such as due diligence, disaster recovery, and secure data storage, and the results update the vendor risk analysis throughout the relationship.

55
New cards

What should rules of engagement define?

The testing purpose and scope, test type and schedule, IP ranges, emergency contacts, handling of sensitive information, and in-scope and out-of-scope devices or applications.

56
New cards

What is a Service Level Agreement (SLA)?

An agreement defining minimum service terms such as uptime and response time, commonly used between customers and service providers.

57
New cards

How do a Memorandum of Understanding (MOU) and Memorandum of Agreement (MOA) differ?

An MOU is generally an informal understanding of common goals and may include confidentiality; an MOA is a step above an MOU and conditionally agrees to objectives but may still lack legally enforceable promises.

58
New cards

What is a Master Service Agreement (MSA)?

A legal contract establishing a broad framework and terms for future transactions and projects so detailed negotiations do not have to be repeated for every engagement.

59
New cards

What is a Work Order or Statement of Work (SOW)?

A specific list of work to be completed, often used with an MSA, describing items such as scope, location, deliverables, schedule, and acceptance criteria.

60
New cards

How do an NDA and a Business Partners Agreement (BPA) differ?

An NDA is a formal confidentiality agreement protecting information such as trade secrets and business activities; a BPA defines a business partnership, including ownership, finances, decision-making, and contingencies.

61
New cards

What is compliance?

Meeting the requirements of laws, policies, and regulations; requirements may be industry-specific, situational, domestic, or international, and penalties can include fines, job loss, or incarceration.

62
New cards

How do internal and external compliance reporting differ?

Internal reporting monitors organizational compliance and may support customers or investors; external reporting is required by regulators or industries and may be annual or ongoing, with invalid or missing reports potentially causing penalties.

63
New cards

What regulatory compliance examples are identified in the notes?

Sarbanes-Oxley Act (SOX), the Health Insurance Portability and Accountability Act (HIPAA), and the Gramm-Leach-Bliley Act (GLBA).

64
New cards

What reputational consequences can result from a security or compliance failure?

Organizations may have to disclose breaches, suffer damage to public reputation, and experience financial effects such as short-term declines in stock price.

65
New cards

What other consequences can non-compliance cause?

Loss of a license can prevent an organization from selling products and be costly to reverse, while inadequate compliance can also breach contractual requirements.

66
New cards

What is compliance monitoring?

Ensuring that compliance requirements are followed in day-to-day operations using internal tools, third-party participation where required, and ongoing monitoring.

67
New cards

How do due care and due diligence differ in compliance?

Both involve acting honestly and in good faith and investigating or verifying; due care generally refers to internal activities, while due diligence is often associated with third-party activities.

68
New cards

What are attestation and acknowledgment in compliance?

A formal sign-off on compliance documentation in which someone accepts responsibility for the accuracy of the information; large organizations commonly use automation to collect, compile, and report compliance data.

69
New cards

How can privacy requirements vary geographically?

Privacy guidelines may be local or regional through state and local rules, national through country-wide privacy laws, or global through cooperation and regulations spanning countries.

70
New cards

What is GDPR, and what is a data subject?

The General Data Protection Regulation protects personal data and privacy for individuals in the European Union and gives data subjects control over personal information, including a right to be forgotten; a data subject is an identified or identifiable person to whom personal data relates.

71
New cards

What is a data inventory, and what should it document?

A listing of all managed data that records information such as the owner, update frequency, and data format; internal and external data use should follow applicable laws and regulations.

72
New cards

What is the purpose of a cybersecurity audit, and what is attestation?

A cybersecurity audit examines infrastructure, software, devices, policies, and procedures to identify weaknesses; attestation is an auditor's opinion regarding the truth or accuracy of an organization's security posture.

73
New cards

What are internal audits, audit committees, and self-assessments?

Internal audits check areas such as regulatory and industry compliance; the audit committee oversees risk-management activities, and self-assessments allow the organization to perform its own checks and consolidate results into ongoing reports.

74
New cards

What is an external audit?

An assessment performed by an independent third party, often because of regulatory requirements, that may examine records, compile reports, gather additional details, assess current activities, and recommend improvements.

75
New cards

What does physical penetration testing evaluate?

Whether physical access can bypass operating-system security through methods such as changing the boot process or OS files and whether unauthorized people can enter buildings or reach protected areas.

76
New cards

How do red-team, blue-team, and integrated penetration-testing perspectives differ?

The red team takes an offensive approach and attacks systems; the blue team detects and prevents attacks; an integrated approach repeatedly identifies, patches, and retests exploitable systems and services.

77
New cards

What are known, partially known, and unknown penetration-testing environments?

A known environment provides full disclosure, a partially known environment provides a mixture of known and unknown information focused on selected systems, and an unknown environment gives the pentester no system information and is a blind test.

78
New cards

What is the purpose of reconnaissance before a penetration test?

To gather a digital footprint, understand security posture and configurations, focus on key systems, and create a network map of routers, networks, and remote sites.

79
New cards

What is passive reconnaissance?

Gathering information from open sources without directly probing the target, including social media, corporate websites, forums, social engineering, dumpster diving, and business organizations.

80
New cards

What is active reconnaissance?

Directly probing the environment in ways visible in network traffic and logs, such as ping scans, port scans, DNS queries, OS fingerprinting, and service or version scans.

81
New cards

Why do organizations conduct simulated phishing campaigns?

To determine how employees respond to phishing by sending simulated messages, centrally tracking incorrect clicks, and providing immediate feedback, training, or additional in-person instruction.

82
New cards

What indicators can help users recognize phishing?

Spelling and grammatical errors, inconsistent domain or email information, unusual attachments, and requests for personal information.

83
New cards

How should suspicious email messages be handled?

Email filtering can remove many threats, users should not click suspicious links or run attachments, and organizations should maintain a process for reporting suspected phishing.

84
New cards

What are risky, unexpected, and unintentional anomalous behaviors?

Risky behavior includes changing hosts or core OS files or uploading sensitive files; unexpected behavior includes foreign-country logins or increased data transfers; unintentional behavior includes mistyped domains, misplaced USB drives, and misconfigured security settings.

85
New cards

What security-awareness metrics can be monitored?

Phishing click rates, password-manager adoption, MFA use, password sharing, and other measures collected and analyzed through automated reporting.

86
New cards

How should initial and recurring security-awareness problems be handled?

A first occurrence can be used as a training opportunity, while long-term recurring monitoring identifies high-frequency issues and users who require additional help.

87
New cards

What should occur during development of a security-awareness program?

Create a security-awareness team, define training and monitoring roles, establish a minimum awareness level, vary training depth by job function, integrate compliance mandates, and define performance metrics.

88
New cards

What should occur during execution of a security-awareness program?

Create and deploy training materials, define how success will be measured, identify stakeholders, provide ongoing metrics, use methods such as classroom training, posters, or emails, and continuously track user training.

89
New cards

When should users receive security-awareness training, and who should receive specialized training?

Users should be trained before receiving access; training should reflect each role's unique responsibilities and should also apply to third parties such as contractors, partners, and suppliers.

90
New cards

How should policies and handbooks support user training?

Security requirements should be documented, made available through online policy guidelines, and referenced in the employee handbook.

91
New cards

What is situational awareness in user security training?

Users should continually look for software threats such as suspicious links, attachments, URLs, and messages and physical threats such as unknown USB drives or unlocked building doors.

92
New cards

How should organizations reduce insider-threat risk?

Use multiple approvals for critical processes, monitor files and systems as much as possible, and make unauthorized changes difficult to perform.

93
New cards

What password-management guidance should users receive?

Users should be given standard password requirements such as length and complexity, and these requirements can often be enforced through technology such as Group Policy.

94
New cards

Why should users be cautious with removable media, cables, and social engineering?

Unknown USB drives may contain malware, unknown cables may connect to malicious systems, and social-engineering attacks require extensive ongoing training because users are a front-line defense.

95
New cards

What should users understand about operational security and hybrid or remote work?

Operational security requires viewing security from an attacker's perspective, identifying sensitive information, and keeping it private; remote work also requires protecting endpoints, restricting family or friend access, and following VPN security policies.