Flashcards ISC S1

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/111

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:32 PM on 9/13/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

112 Terms

1
New cards

1) CSF Core

2) CSF Tiers

3) CSF Organizational Profiles

NIST Cybersecurity Framework:

1) CSF ___

2) CSF ___

3) CSF ___

2
New cards

NIST CSF Core

The ___ describes cybersecurity outcomes that can be used by an organization of any size to reduce its cybersecurity risks.

3
New cards

1) Govern

2) Identify

3) Protect

4) Detect

5) Respond

6) Recover

NIST CSF Core:

1) ___

2) ___

3) ___

4) ___

5) ___

6) ___

4
New cards

Govern

NIST CSF Core

___: this function establishes, communicates, and monitors the organization's cybersecurity risk management strategy, expectations, and policy. This function assists an organization in achieving and prioritizing outcomes of the other 5 functions in relation to the organization's mission and stakeholder expectations

5
New cards

Identify

NIST CSF Core

___: this function focuses on understanding the assets and suppliers of an organization and the cybersecurity risks related to these assets and suppliers. This function also includes identifying improvement opportunities related to the organization's cybersecurity risk management policies, procedures, plans, processes, practices

6
New cards

Protect

NIST CSF Core

___: this function focuses on an organization's ability to secure its assets to prevent or reduce the likelihood and impact of adverse cybersecurity events. Examples of the safeguards used to manage cybersecurity risks include identity management, authentication, and access control; awareness and training; data security; platform security; and infrastructure resiliency

7
New cards

Detect

NIST CSF Core

___: this function focuses on the timely discovery of cybersecurity attacks and incidents by analyzing anomalies, indicators of compromise, and other potentially adverse events that may indicate that a cybersecurity attack or incident is occurring

8
New cards

Respond

NIST CSF Core

___: this function focuses on a company's ability to contain the effects of cybersecurity incidents. Outcomes within this function cover incident management, analysis, mitigation, reporting, and communication

9
New cards

Recover

NIST CSF Core

___: this function focuses on supporting the timely restoration of a company's normal operations to reduce the impact of cybersecurity incidents and communicate recovery efforts effectively and appropriately

10
New cards

Categories

___: tie outcomes to specific activities and company needs

11
New cards

Subcategories

___: divide categories into management and technical activities that help achieve the category outcomes

12
New cards

four

The NIST CSF provides a measure of an organization's information security infrastructure sophistication in the form of ___ tiers. The tiers categorize the degree to which information security practices are integrated throughout an organization

13
New cards

Organizational Profiles, Tiers

The CSF ____ determine success or failure of information security implementation, whereas the CSF ____ inform an organization as to the rigor of the governance and management practices associated with those profiles.

14
New cards

Tier 1 (Partial)

Tier ___

-risk management is ad hoc and reactive where prioritization of information security efforts is not formally based on organizational objectives or threat environment

-limited awareness of cybersecurity risks at the organizational level

-implements cybersecurity risk management on an irregular, case-by-case basis and doesn't have processes that allow cybersecurity information to be shared within the organization for general awareness

15
New cards

Tier 2 (Risk-Informed)

Tier ___

-prioritization is based on organizational risk, and management approves cybersecurity efforts; however, policies may be isolated and not be established as organizational-wide policies

-org is aware of the risks in general and specific risks associated with its suppliers, as well as the products and services it acquires and uses, but it doesn't act consistently or formally in response to those risks

16
New cards

Tier 3 (Repeatable)

Tier ___

-utilizes cybersecurity in planning and has enshrined cybersecurity practices in formal, documented policies. These policies are frequently updated based on shifts in business requirements, threats, and technological landscape

-organization-wide risk approach where risks of assets, suppliers, and products and services are consistently and accurately communicated among senior leadership

17
New cards

Tier 4 (Adaptive)

Tier ___

-risk-informed, organization-wide approach in managing cybersecurity risks. Senior executives monitor cybersecurity risks in the same context as financial and other organizational risks and cybersecurity risk management is part of the organizational culture

-process of continuous improvement that incorporates advanced cybersecurity technologies and practices, the organization actively adapts to a changing technological landscape and responds in a timely, effective manner to evolving, sophisticated threats

18
New cards

Target

A ___ profile that specifies the desired outcome that an organization has prioritized achieving, and that considers anticipated changes to the organization's cybersecurity posture

19
New cards

Current

A ___ profile that specifies the outcome that an organization is achieving based on the current cybersecurity posture

20
New cards

Community

___ profiles are baseline outcomes developed among. a number of organizations due to the shared interest and goals of a particular industry sector, topic, or use case. Can be used by orgs to develop their own Target Profile

21
New cards

Organizational

___ Profiles should factor organizational mission objectives, stakeholder expectations, threat landscape, and risk management priorities

22
New cards

Privacy

The NIST ___ Framework was published in early 2020 to protect individuals' data as used in data processing applications. Provides a common language for understanding, managing, and communicating privacy risk with internal and external stakeholders. Expresses control objectives in the form of a Framework Core, with sophistication measures in Framework Profiles, and finally mechanisms to drive organizational change and success through Framework Implementation Tiers

23
New cards

SP 800-53

Originally for those who process and store information to satify security and privacy. NIST ___ Security and Privacy Controls are Information Systems and Organizations has evolved into a set of security and privacy controls applicable to all information systems and has become the standard for federal information security systems

24
New cards

Access Control

NIST SP 800-53

___: How does the organization manage application and resource access?

25
New cards

Awareness and Training

NIST SP 800-53

___: How should the company deliver training on information security risk?

26
New cards

Audit and Accountability

NIST SP 800-53

___: How does the company evaluate information security controls?

27
New cards

Assessment, Authorization, and Monitoring

NIST SP 800-53

___: How does the organization collect information security telemetry and use it to hunt for threats?

28
New cards

Configuration Management

NIST SP 800-53

___: How are assets and software configured securely?

29
New cards

Contingency Planning

NIST SP 800-53

___: How is the company prepared for downtime and outages?

30
New cards

Identity and Authentication

NIST SP 800-53

___: How is identification and authentication managed?

31
New cards

Incident Response

NIST SP 800-53

___: How is the organization prepared for information security and events?

32
New cards

Maintenance

NIST SP 800-53

___: How does the company ensure secure maintenance of infrastructure?

33
New cards

Media Protection

NIST SP 800-53

___: How is information on physical media managed?

34
New cards

Physical and Environmental Protection

NIST SP 800-53

___: How are facilities secured from intrusion or harm?

35
New cards

Planning

NIST SP 800-53

___: How does the organization manage information security planning?

36
New cards

Program Management

NIST SP 800-53

___: How does the organization securely manage its information security program?

37
New cards

Personnel Security

NIST SP 800-53

___: How are employees evaluated for potential compromise?

38
New cards

Processing and Transparency

NIST SP 800-53

___: How is personally identifiable information managed?

39
New cards

Risk Assessment

NIST SP 800-53

___: How is environmental risk evaluated?

40
New cards

System and Services Acquisition

NIST SP 800-53

___: How are systems securely evaluated and acquired?

41
New cards

System and Communications Protection

NIST SP 800-53

___: How is data securely transmitted digitally?

42
New cards

System and Information Integrity

NIST SP 800-53

___: How is the integrity of data in company systems maintained and evaluated?

43
New cards

Supply Chain Risk Management

NIST SP 800-53

___: How does the company secure its supply chain

44
New cards

1) Common (Inheritable)

2) System-Specific

3) Hybrid

With respect to implementation models, NIST SP 800-53 outlines three control implementation approaches that are to be implemented on a per-control basis:

1) ___: implement controls at the organizational level, which are adopted by information systems

2) ___: implement controls at the information system level

3) ___: implement controls at the organization level where appropriate and the remainder at the information system level

45
New cards

Privacy laws

___ exist to protect an individual's private life and keep personal details out of the public domain. Create trust between consumers and enterprises

46
New cards

Unintentional

___: a breach resulting from negligence or error

47
New cards

Intentional

___: a breach resulting from bad actors illegally gaining access to data

48
New cards

Detection and Escalation

___: the cost to detect a breach, such as forensics and investigative efforts

49
New cards

Notification

___: the cost to notify necessary parties, such as consumers and regulators

50
New cards

Post-Breach Response

___: the cost to rectify the effects of the breach, such as paying regulatory fines, implementing credit-monitoring services for consumers, and providing ongoing communications to consumers

51
New cards

Loss of Business and Revenue

___: revenue is temporarily lost during downtime caused by data breaches, and this can ultimately lead to loss of customers, which creates a more permanent loss of revenue

52
New cards

HIPPA

The ___ Act of 1996 required the Department of Health and Human Services to adopt national standards promoting health care privacy and security

53
New cards

protected health information (PHI)

The HIPPA Privacy Rule governs the privacy of ___. This rule applies to specific health care-related entities and businesses, called covered entities, which include any of the following:

-Health care providers that transmit health information electronically

-Health plans

-Health care clearing houses

-Business associates who are service providers who need access to PHI to perform services for covered entities

54
New cards

-individual

The Privacy Rule permits a covered entity to use and disclose PHI, with no further authorization required:

-to the ___

-for treatment, payment, and health care operations

-incident to an otherwise permitted use and disclosure

-with valid authorization

-after giving the individual the opportunity to agree or object

-as a limited dataset for research, public health, or health care operations

-for public interest and benefit activities

55
New cards

Administrative Safeguards

Physical Safeguards

Technical Safeguards

HIPPA requires different safeguards for covered entities or business associates, including the following:

___: standards include security management processes, assigned security responsibility, workforce security, information access management, security awareness and training, security incident procedures, contingency plans, and evaluation

___: standards include facility access controls, workstation use, workstation security, and device and media controls

___: standards include access control, audit controls, data integrity controls, person or entity authentication, and transmission security

56
New cards

HITECH

___ was enacted in 2009 to promote health information technology and the transition from paper to electronic records.

-increased penalties for HIPPA violations

-required that patients receive the option to obtain records in electronic form

-added "business associates" as a covered entity

-addition of breach notification rules

57
New cards

GDPR

Effective May 2018, ___ became the European Union's general applicability law regulating the privacy of data.

-provides circumstances when it's lawful to process personal data

58
New cards

GDPR applies to any of the following:

-data processors based in the ___, even if the actual processing takes place outside of the EU

-data processors not based in the EU if the processor is offering goods or services to those in the EU or is monitoring the behavior of those in the EU

-data processors not based in the EU but where EU law applies via public international law

59
New cards

Lawfulness, Fairness, Transparency

Purpose Limitation

Data Minimization

Accuracy

Storage Limitation

Integrity and Confidentiality

GDPR provides 6 principles that must be followed when processing data:

___: data must be processed lawfully, fairly, and in a transparent manner

___: data must be processed for specified, explicit, legitimate purposes. Further processing beyond the purpose is permitted for public interest archiving, scientific or historical research, or statistical purposes

___: data processing must be adequate, relevant, and limited to what is necessary for the purpose

___: data must be accurate and kept updated

___: data must be stored only for as long as is necessary

___: data must be processed securely and protected against unauthorized or unlawful processing, accidental loss, destruction, or damage

60
New cards

Center for Internet Security (CIS) Controls

The ___ are a recommended set of actions, processes, and best practices that can be adopted and implemented by organizations to strengthen their cybersecurity defenses.

There are 18 controls

61
New cards

Context

CIS Controls

___: an enhancement to the scope and practical applicability of safeguards through incorporation of examples and explanations

62
New cards

Coexistence

CIS Controls

___: alignment with evolving industry standards and frameworks, including NIST's CSF 2.0 framework

63
New cards

Consistency

CIS Controls

___: disruption to controls users are minimized, limiting the impact on implementation groups

64
New cards

IG1

Implementation Groups

___: small or medium sized organizations that have a limited cybersecurity defense mechanism in place in terms of personnel or IT assets. The main focus of this group is to keep the company operational because their cybersecurity expertise is limited, the data being used is not sensitive, and the company cannot sustain long periods of downtime

65
New cards

IG2

Implementation Groups

___: IT staff who support multiple departments that have various risk profiles. These organizations typically have sensitive client data, and they can tolerate short interruptions in service. One of the biggest concerns for these entities is loss of trust in the event of a data breach

66
New cards

IG3

Implementation Groups

___: security experts in all the domains within cybersecurity like penetration testing, risk management, and application security. Data assets under management at these companies include those that are sensitive and likely subject to compliance standards or regulatory oversight. Attacks on these organizations can cause significant damage to the company and the public welfare

67
New cards

Inventory and Control of Enterprise Assets

Control 1: ___

-actively track and manage all IT assets connected to a company's IT infrastructure physically or virtually within a cloud environment

-focus on the potential for external devices to connect to a company's network through means such as guest networks

68
New cards

Inventory and Control of Software Assets

Control 2: ___

-track and actively manage all software applications so that only authorized software is installed on company devices

-finding unmanaged and unauthorized software already installed so that it can be removed and remediated

-allowlisting should be in place so that only approved software is installed on company devices

69
New cards

Data Protection

Control 3: ___

-securely manage the entire life cycle of their data, from the initial identification and classification data to its disposal

-identify, archive, label, and classify their data to understand the implications of the data being lost or compromised

70
New cards

Configuration of Enterprise Assets and Software

Control 4: ___

-establish and maintain secure baseline configurations for their enterprise assets, including servers, network devices, mobile and portable end-user devices, non-computing assets such as Internet of Things devices, operating systems, and other corporately managed hardware or software

-security hardening

71
New cards

Account Management

Control 5: ___

-manage credentials and authorization for user accounts, privileged user accounts, and service accounts for company hardware and software

-accounts must be inventoried and tracked

-acceptable use policy and account safety guidelines

-credential should be treated as highly sensitive information and formal training should be provided to educate users on account safety best practices

-administrative accounts should be restricted to specific use cases

72
New cards

Access Control Management

Control 6: ___

-specifying the type of access that user accounts should have

-only have the necessary privileges required for their job role

-access control models (RBAC) or PBAC) can be utilized to help facilitate this process by defining roles within the organization and assigning appropriate access to each role to provide separation of duties

73
New cards

Continuous Vulnerability Management

Control 7: ___

-continuously identifying and tracking vulnerabilities within their infrastructure so that they can remediate and eliminate weak points or windows of opportunity for bad actors

-remain proactive in scanning, monitoring, and managing vulnerabilities

74
New cards

Audit Log Management

Control 8: ___

-enterprise log management process so that orgs can be altered and recover from an attack in real time using log collection and analytic features

-system logs and audit logs

75
New cards

System

___ Log: provide a list of events such as start and end times, points of restoration, and system crashes

76
New cards

Audit

___ Logs: tied to a specific user, recording when a person logs in or out, accesses a file, or opens an application

77
New cards

Email and Web Browser Protections

Control 9: ___

-how to detect and protect against cybercrime attempted through email or the internet by directly engaging employees

-web browser attacks can come in the form of exploiting vulnerabilities from insecure or unpatched browsers

78
New cards

CIS CONTROL Malware Defenses

Control 10: ___

-preventing installation and propagation of malware onto company assets and its network

-malware can infiltrate as viruses, worms, spyware, adware, keyloggers, and ransomware

-endpoint assets and devices can be leveraged as both entry points and targets for malware

-malware can cause substantial damage to an organization by stealing intellectual property or log-in credentials, destroying data, encryption data for ransom, or executing other nefarious activities

-anti-malware solutions should be automated, centrally managed, maintained, and deployed to all potential entry points

79
New cards

CIS CONTROL Data Recovery

Control 11: ___

-establishes data backup, testing, restoration processes that allow organizations to effectively recover company assets to a pre-incident state

-org data is a critical resource for conducting business and can be targeted by ransomware attacks that encrypt data and leave criminals demanding ransom for its restoration, human error, misconfigurations, and natural factors can also cause data to become unusable or unavailable

80
New cards

CIS CONTROL Network Infrastructure Management

Control 12: ___

-procedures and tools for managing and securing a company's network infrastructure

-network architecture documentation and diagrams should be kept up-to-date to accurately reflect the organization's network topology and layout

81
New cards

CIS CONTROL Network Monitoring and Defense

Control 13: ___

-processes for monitoring and defending a company's network infrastructure against internal and external security threats

2 common ways networks can be attacked:

-denial of service

-ransomeware

82
New cards

DoS

___ attacks involve a perpetrator overwhelming a company's network by flooding the network with illegitimate requests so that it is effectively rendered useless

83
New cards

Ransomware

___ attacks are situations in which an attacker or group of attackers gain access to a company's system, block employees from accessing it, demand payment to regain access, and threaten to either keep all systems blocked or publish sensitive data to the public

84
New cards

CIS CONTROL Security Awareness and Skills Training

Control 14: ___

-establishing a security awareness and training program

-uniformed employees pose one of the greatest risks to the security of an organization

-regular training

85
New cards

CIS CONTROL Service Provider Management

Control 15: ___

-develop processes to evaluate third-party service providers that have access to sensitive data or that are responsible for managing some or all of a company's IT functions

86
New cards

CIS CONTROL Application Software Security

Control 16: ___

-safeguards that manage the entire life cycle of software that is acquired, hosted, or developed in-house to detect, deter, and resolve cybersecurity weaknesses before they are exploited

87
New cards

CIS CONTROL Incident Response Management

Control 17: ___

-establish an incident response management to detect, respond, and prepare for potential cybersecurity attacks

-laws and regulations may require notification of data breaches and impose fines for noncompliance

-designation of key contact, establishment of an incident response team, development of communication plans for notifying impacted business units, stakeholders, and regulatory agencies

88
New cards

CIS CONTROL Penetration Testing

Control 18: ___

-test the sophistication of their cybersecurity defense system in place by simulating actual attacks in an effort to find and exploit weaknesses

-dramatic demonstration of an attack

-seeks to go beyond identifying weaknesses

-exploit those weak points and see what additional damage could be done once that first point of failure is reached

-"Red Team"

89
New cards

COBIT Framework

To accomplish its mission, ISACA created the ___, which provides a road map that organizations can use to implement best practices for IT governance and management

90
New cards

governance, management

COBIT distinguishes between ___ and ___, recognizing them as two unique disciplines that each exist for different reasons and require different sets of organizational resources

91
New cards

Organizational governance

___ is typically the responsibility of a company's board of directors, consisting of a chairperson and focused org structures

92
New cards

Management

___ is responsible for the daily planning and administration of company operations, generally consisting of CEO, CFO, COO

93
New cards

Stakeholders

___ can either be internal or external, with the BOD and management considered internal

94
New cards

COBIT SIX GOVERNANCE PRINCIPLES Provide Stakeholder Value

Holistic Approach

Dynamic Governance System

Governance Distinct from Management

Tailored to Enterprise Needs

End-to-End Governance System

COBIT SIX GOVERNANCE PRINCIPLES

___: create value for company's stakeholders by balancing benefits, risks, resources

___: comprise diverse components, collectively providing a holistic model

___: when a change in one governance system occurs, the impact on all others should be considered so that the system continues to meet the demands of the organization

___: management activities and governance systems should be clearly distinguished from each other because they have different functions

___: customized to each company, using design factors to prioritize and tailor the system

___: more than just the IT function should be considered in a governance system. All processes in the organization involving information and technology should be factored into an end-to-end approach

95
New cards

COBIT 3 Principles for a governance framework Based on Conceptual Model

Open and Flexible

Aligned to Major Standards

COBIT 3 Principles for a governance framework

___: identify key components as well as the relationships between those components in order to provide for greater automation and to maximize consistency

___: frameworks should have the ability to change, adding relevant content, and removing irrelevant content, while keeping consistency and integrity

___: frameworks should align with regulations, frameworks, and standards

96
New cards

governance, management

___ objectives always relate to a governance process while ___ objectives are always associated with management processes

97
New cards

COBIT CORE MODEL- 1 GOVERNANCE OBJECTIVE Evaluate, Direct, Monitor (EDM)

___: TCWG evaluate strategic objectives, direct management to achieve those objectives, and monitor whether objectives are being met. There are 5 objectives within this domain.

98
New cards

COBIT CORE MODEL- 3 MANAGEMENT OBJECTIVES Align, Plan, Organize (APO)

___: focuses on information technology's overall strategy, organization, and supporting activities. There are 14 objectives within this domain.

99
New cards

COBIT CORE MODEL- 4 MANAGEMENT OBJECTIVES Build, Acquire, and Implement (BAI)

___: addresses the implementation of information technology solutions in the organization's business processes. 11 objectives

100
New cards

COBIT CORE MODEL- 4 MANAGEMENT OBJECTIVES Deliver, Service, and Support (DSS)

___: addresses the security, delivery, and support of IT services. The 6 objectives