1/111
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
1) CSF Core
2) CSF Tiers
3) CSF Organizational Profiles
NIST Cybersecurity Framework:
1) CSF ___
2) CSF ___
3) CSF ___
NIST CSF Core
The ___ describes cybersecurity outcomes that can be used by an organization of any size to reduce its cybersecurity risks.
1) Govern
2) Identify
3) Protect
4) Detect
5) Respond
6) Recover
NIST CSF Core:
1) ___
2) ___
3) ___
4) ___
5) ___
6) ___
Govern
NIST CSF Core
___: this function establishes, communicates, and monitors the organization's cybersecurity risk management strategy, expectations, and policy. This function assists an organization in achieving and prioritizing outcomes of the other 5 functions in relation to the organization's mission and stakeholder expectations
Identify
NIST CSF Core
___: this function focuses on understanding the assets and suppliers of an organization and the cybersecurity risks related to these assets and suppliers. This function also includes identifying improvement opportunities related to the organization's cybersecurity risk management policies, procedures, plans, processes, practices
Protect
NIST CSF Core
___: this function focuses on an organization's ability to secure its assets to prevent or reduce the likelihood and impact of adverse cybersecurity events. Examples of the safeguards used to manage cybersecurity risks include identity management, authentication, and access control; awareness and training; data security; platform security; and infrastructure resiliency
Detect
NIST CSF Core
___: this function focuses on the timely discovery of cybersecurity attacks and incidents by analyzing anomalies, indicators of compromise, and other potentially adverse events that may indicate that a cybersecurity attack or incident is occurring
Respond
NIST CSF Core
___: this function focuses on a company's ability to contain the effects of cybersecurity incidents. Outcomes within this function cover incident management, analysis, mitigation, reporting, and communication
Recover
NIST CSF Core
___: this function focuses on supporting the timely restoration of a company's normal operations to reduce the impact of cybersecurity incidents and communicate recovery efforts effectively and appropriately
Categories
___: tie outcomes to specific activities and company needs
Subcategories
___: divide categories into management and technical activities that help achieve the category outcomes
four
The NIST CSF provides a measure of an organization's information security infrastructure sophistication in the form of ___ tiers. The tiers categorize the degree to which information security practices are integrated throughout an organization
Organizational Profiles, Tiers
The CSF ____ determine success or failure of information security implementation, whereas the CSF ____ inform an organization as to the rigor of the governance and management practices associated with those profiles.
Tier 1 (Partial)
Tier ___
-risk management is ad hoc and reactive where prioritization of information security efforts is not formally based on organizational objectives or threat environment
-limited awareness of cybersecurity risks at the organizational level
-implements cybersecurity risk management on an irregular, case-by-case basis and doesn't have processes that allow cybersecurity information to be shared within the organization for general awareness
Tier 2 (Risk-Informed)
Tier ___
-prioritization is based on organizational risk, and management approves cybersecurity efforts; however, policies may be isolated and not be established as organizational-wide policies
-org is aware of the risks in general and specific risks associated with its suppliers, as well as the products and services it acquires and uses, but it doesn't act consistently or formally in response to those risks
Tier 3 (Repeatable)
Tier ___
-utilizes cybersecurity in planning and has enshrined cybersecurity practices in formal, documented policies. These policies are frequently updated based on shifts in business requirements, threats, and technological landscape
-organization-wide risk approach where risks of assets, suppliers, and products and services are consistently and accurately communicated among senior leadership
Tier 4 (Adaptive)
Tier ___
-risk-informed, organization-wide approach in managing cybersecurity risks. Senior executives monitor cybersecurity risks in the same context as financial and other organizational risks and cybersecurity risk management is part of the organizational culture
-process of continuous improvement that incorporates advanced cybersecurity technologies and practices, the organization actively adapts to a changing technological landscape and responds in a timely, effective manner to evolving, sophisticated threats
Target
A ___ profile that specifies the desired outcome that an organization has prioritized achieving, and that considers anticipated changes to the organization's cybersecurity posture
Current
A ___ profile that specifies the outcome that an organization is achieving based on the current cybersecurity posture
Community
___ profiles are baseline outcomes developed among. a number of organizations due to the shared interest and goals of a particular industry sector, topic, or use case. Can be used by orgs to develop their own Target Profile
Organizational
___ Profiles should factor organizational mission objectives, stakeholder expectations, threat landscape, and risk management priorities
Privacy
The NIST ___ Framework was published in early 2020 to protect individuals' data as used in data processing applications. Provides a common language for understanding, managing, and communicating privacy risk with internal and external stakeholders. Expresses control objectives in the form of a Framework Core, with sophistication measures in Framework Profiles, and finally mechanisms to drive organizational change and success through Framework Implementation Tiers
SP 800-53
Originally for those who process and store information to satify security and privacy. NIST ___ Security and Privacy Controls are Information Systems and Organizations has evolved into a set of security and privacy controls applicable to all information systems and has become the standard for federal information security systems
Access Control
NIST SP 800-53
___: How does the organization manage application and resource access?
Awareness and Training
NIST SP 800-53
___: How should the company deliver training on information security risk?
Audit and Accountability
NIST SP 800-53
___: How does the company evaluate information security controls?
Assessment, Authorization, and Monitoring
NIST SP 800-53
___: How does the organization collect information security telemetry and use it to hunt for threats?
Configuration Management
NIST SP 800-53
___: How are assets and software configured securely?
Contingency Planning
NIST SP 800-53
___: How is the company prepared for downtime and outages?
Identity and Authentication
NIST SP 800-53
___: How is identification and authentication managed?
Incident Response
NIST SP 800-53
___: How is the organization prepared for information security and events?
Maintenance
NIST SP 800-53
___: How does the company ensure secure maintenance of infrastructure?
Media Protection
NIST SP 800-53
___: How is information on physical media managed?
Physical and Environmental Protection
NIST SP 800-53
___: How are facilities secured from intrusion or harm?
Planning
NIST SP 800-53
___: How does the organization manage information security planning?
Program Management
NIST SP 800-53
___: How does the organization securely manage its information security program?
Personnel Security
NIST SP 800-53
___: How are employees evaluated for potential compromise?
Processing and Transparency
NIST SP 800-53
___: How is personally identifiable information managed?
Risk Assessment
NIST SP 800-53
___: How is environmental risk evaluated?
System and Services Acquisition
NIST SP 800-53
___: How are systems securely evaluated and acquired?
System and Communications Protection
NIST SP 800-53
___: How is data securely transmitted digitally?
System and Information Integrity
NIST SP 800-53
___: How is the integrity of data in company systems maintained and evaluated?
Supply Chain Risk Management
NIST SP 800-53
___: How does the company secure its supply chain
1) Common (Inheritable)
2) System-Specific
3) Hybrid
With respect to implementation models, NIST SP 800-53 outlines three control implementation approaches that are to be implemented on a per-control basis:
1) ___: implement controls at the organizational level, which are adopted by information systems
2) ___: implement controls at the information system level
3) ___: implement controls at the organization level where appropriate and the remainder at the information system level
Privacy laws
___ exist to protect an individual's private life and keep personal details out of the public domain. Create trust between consumers and enterprises
Unintentional
___: a breach resulting from negligence or error
Intentional
___: a breach resulting from bad actors illegally gaining access to data
Detection and Escalation
___: the cost to detect a breach, such as forensics and investigative efforts
Notification
___: the cost to notify necessary parties, such as consumers and regulators
Post-Breach Response
___: the cost to rectify the effects of the breach, such as paying regulatory fines, implementing credit-monitoring services for consumers, and providing ongoing communications to consumers
Loss of Business and Revenue
___: revenue is temporarily lost during downtime caused by data breaches, and this can ultimately lead to loss of customers, which creates a more permanent loss of revenue
HIPPA
The ___ Act of 1996 required the Department of Health and Human Services to adopt national standards promoting health care privacy and security
protected health information (PHI)
The HIPPA Privacy Rule governs the privacy of ___. This rule applies to specific health care-related entities and businesses, called covered entities, which include any of the following:
-Health care providers that transmit health information electronically
-Health plans
-Health care clearing houses
-Business associates who are service providers who need access to PHI to perform services for covered entities
-individual
The Privacy Rule permits a covered entity to use and disclose PHI, with no further authorization required:
-to the ___
-for treatment, payment, and health care operations
-incident to an otherwise permitted use and disclosure
-with valid authorization
-after giving the individual the opportunity to agree or object
-as a limited dataset for research, public health, or health care operations
-for public interest and benefit activities
Administrative Safeguards
Physical Safeguards
Technical Safeguards
HIPPA requires different safeguards for covered entities or business associates, including the following:
___: standards include security management processes, assigned security responsibility, workforce security, information access management, security awareness and training, security incident procedures, contingency plans, and evaluation
___: standards include facility access controls, workstation use, workstation security, and device and media controls
___: standards include access control, audit controls, data integrity controls, person or entity authentication, and transmission security
HITECH
___ was enacted in 2009 to promote health information technology and the transition from paper to electronic records.
-increased penalties for HIPPA violations
-required that patients receive the option to obtain records in electronic form
-added "business associates" as a covered entity
-addition of breach notification rules
GDPR
Effective May 2018, ___ became the European Union's general applicability law regulating the privacy of data.
-provides circumstances when it's lawful to process personal data
GDPR applies to any of the following:
-data processors based in the ___, even if the actual processing takes place outside of the EU
-data processors not based in the EU if the processor is offering goods or services to those in the EU or is monitoring the behavior of those in the EU
-data processors not based in the EU but where EU law applies via public international law
Lawfulness, Fairness, Transparency
Purpose Limitation
Data Minimization
Accuracy
Storage Limitation
Integrity and Confidentiality
GDPR provides 6 principles that must be followed when processing data:
___: data must be processed lawfully, fairly, and in a transparent manner
___: data must be processed for specified, explicit, legitimate purposes. Further processing beyond the purpose is permitted for public interest archiving, scientific or historical research, or statistical purposes
___: data processing must be adequate, relevant, and limited to what is necessary for the purpose
___: data must be accurate and kept updated
___: data must be stored only for as long as is necessary
___: data must be processed securely and protected against unauthorized or unlawful processing, accidental loss, destruction, or damage
Center for Internet Security (CIS) Controls
The ___ are a recommended set of actions, processes, and best practices that can be adopted and implemented by organizations to strengthen their cybersecurity defenses.
There are 18 controls
Context
CIS Controls
___: an enhancement to the scope and practical applicability of safeguards through incorporation of examples and explanations
Coexistence
CIS Controls
___: alignment with evolving industry standards and frameworks, including NIST's CSF 2.0 framework
Consistency
CIS Controls
___: disruption to controls users are minimized, limiting the impact on implementation groups
IG1
Implementation Groups
___: small or medium sized organizations that have a limited cybersecurity defense mechanism in place in terms of personnel or IT assets. The main focus of this group is to keep the company operational because their cybersecurity expertise is limited, the data being used is not sensitive, and the company cannot sustain long periods of downtime
IG2
Implementation Groups
___: IT staff who support multiple departments that have various risk profiles. These organizations typically have sensitive client data, and they can tolerate short interruptions in service. One of the biggest concerns for these entities is loss of trust in the event of a data breach
IG3
Implementation Groups
___: security experts in all the domains within cybersecurity like penetration testing, risk management, and application security. Data assets under management at these companies include those that are sensitive and likely subject to compliance standards or regulatory oversight. Attacks on these organizations can cause significant damage to the company and the public welfare
Inventory and Control of Enterprise Assets
Control 1: ___
-actively track and manage all IT assets connected to a company's IT infrastructure physically or virtually within a cloud environment
-focus on the potential for external devices to connect to a company's network through means such as guest networks
Inventory and Control of Software Assets
Control 2: ___
-track and actively manage all software applications so that only authorized software is installed on company devices
-finding unmanaged and unauthorized software already installed so that it can be removed and remediated
-allowlisting should be in place so that only approved software is installed on company devices
Data Protection
Control 3: ___
-securely manage the entire life cycle of their data, from the initial identification and classification data to its disposal
-identify, archive, label, and classify their data to understand the implications of the data being lost or compromised
Configuration of Enterprise Assets and Software
Control 4: ___
-establish and maintain secure baseline configurations for their enterprise assets, including servers, network devices, mobile and portable end-user devices, non-computing assets such as Internet of Things devices, operating systems, and other corporately managed hardware or software
-security hardening
Account Management
Control 5: ___
-manage credentials and authorization for user accounts, privileged user accounts, and service accounts for company hardware and software
-accounts must be inventoried and tracked
-acceptable use policy and account safety guidelines
-credential should be treated as highly sensitive information and formal training should be provided to educate users on account safety best practices
-administrative accounts should be restricted to specific use cases
Access Control Management
Control 6: ___
-specifying the type of access that user accounts should have
-only have the necessary privileges required for their job role
-access control models (RBAC) or PBAC) can be utilized to help facilitate this process by defining roles within the organization and assigning appropriate access to each role to provide separation of duties
Continuous Vulnerability Management
Control 7: ___
-continuously identifying and tracking vulnerabilities within their infrastructure so that they can remediate and eliminate weak points or windows of opportunity for bad actors
-remain proactive in scanning, monitoring, and managing vulnerabilities
Audit Log Management
Control 8: ___
-enterprise log management process so that orgs can be altered and recover from an attack in real time using log collection and analytic features
-system logs and audit logs
System
___ Log: provide a list of events such as start and end times, points of restoration, and system crashes
Audit
___ Logs: tied to a specific user, recording when a person logs in or out, accesses a file, or opens an application
Email and Web Browser Protections
Control 9: ___
-how to detect and protect against cybercrime attempted through email or the internet by directly engaging employees
-web browser attacks can come in the form of exploiting vulnerabilities from insecure or unpatched browsers
CIS CONTROL Malware Defenses
Control 10: ___
-preventing installation and propagation of malware onto company assets and its network
-malware can infiltrate as viruses, worms, spyware, adware, keyloggers, and ransomware
-endpoint assets and devices can be leveraged as both entry points and targets for malware
-malware can cause substantial damage to an organization by stealing intellectual property or log-in credentials, destroying data, encryption data for ransom, or executing other nefarious activities
-anti-malware solutions should be automated, centrally managed, maintained, and deployed to all potential entry points
CIS CONTROL Data Recovery
Control 11: ___
-establishes data backup, testing, restoration processes that allow organizations to effectively recover company assets to a pre-incident state
-org data is a critical resource for conducting business and can be targeted by ransomware attacks that encrypt data and leave criminals demanding ransom for its restoration, human error, misconfigurations, and natural factors can also cause data to become unusable or unavailable
CIS CONTROL Network Infrastructure Management
Control 12: ___
-procedures and tools for managing and securing a company's network infrastructure
-network architecture documentation and diagrams should be kept up-to-date to accurately reflect the organization's network topology and layout
CIS CONTROL Network Monitoring and Defense
Control 13: ___
-processes for monitoring and defending a company's network infrastructure against internal and external security threats
2 common ways networks can be attacked:
-denial of service
-ransomeware
DoS
___ attacks involve a perpetrator overwhelming a company's network by flooding the network with illegitimate requests so that it is effectively rendered useless
Ransomware
___ attacks are situations in which an attacker or group of attackers gain access to a company's system, block employees from accessing it, demand payment to regain access, and threaten to either keep all systems blocked or publish sensitive data to the public
CIS CONTROL Security Awareness and Skills Training
Control 14: ___
-establishing a security awareness and training program
-uniformed employees pose one of the greatest risks to the security of an organization
-regular training
CIS CONTROL Service Provider Management
Control 15: ___
-develop processes to evaluate third-party service providers that have access to sensitive data or that are responsible for managing some or all of a company's IT functions
CIS CONTROL Application Software Security
Control 16: ___
-safeguards that manage the entire life cycle of software that is acquired, hosted, or developed in-house to detect, deter, and resolve cybersecurity weaknesses before they are exploited
CIS CONTROL Incident Response Management
Control 17: ___
-establish an incident response management to detect, respond, and prepare for potential cybersecurity attacks
-laws and regulations may require notification of data breaches and impose fines for noncompliance
-designation of key contact, establishment of an incident response team, development of communication plans for notifying impacted business units, stakeholders, and regulatory agencies
CIS CONTROL Penetration Testing
Control 18: ___
-test the sophistication of their cybersecurity defense system in place by simulating actual attacks in an effort to find and exploit weaknesses
-dramatic demonstration of an attack
-seeks to go beyond identifying weaknesses
-exploit those weak points and see what additional damage could be done once that first point of failure is reached
-"Red Team"
COBIT Framework
To accomplish its mission, ISACA created the ___, which provides a road map that organizations can use to implement best practices for IT governance and management
governance, management
COBIT distinguishes between ___ and ___, recognizing them as two unique disciplines that each exist for different reasons and require different sets of organizational resources
Organizational governance
___ is typically the responsibility of a company's board of directors, consisting of a chairperson and focused org structures
Management
___ is responsible for the daily planning and administration of company operations, generally consisting of CEO, CFO, COO
Stakeholders
___ can either be internal or external, with the BOD and management considered internal
COBIT SIX GOVERNANCE PRINCIPLES Provide Stakeholder Value
Holistic Approach
Dynamic Governance System
Governance Distinct from Management
Tailored to Enterprise Needs
End-to-End Governance System
COBIT SIX GOVERNANCE PRINCIPLES
___: create value for company's stakeholders by balancing benefits, risks, resources
___: comprise diverse components, collectively providing a holistic model
___: when a change in one governance system occurs, the impact on all others should be considered so that the system continues to meet the demands of the organization
___: management activities and governance systems should be clearly distinguished from each other because they have different functions
___: customized to each company, using design factors to prioritize and tailor the system
___: more than just the IT function should be considered in a governance system. All processes in the organization involving information and technology should be factored into an end-to-end approach
COBIT 3 Principles for a governance framework Based on Conceptual Model
Open and Flexible
Aligned to Major Standards
COBIT 3 Principles for a governance framework
___: identify key components as well as the relationships between those components in order to provide for greater automation and to maximize consistency
___: frameworks should have the ability to change, adding relevant content, and removing irrelevant content, while keeping consistency and integrity
___: frameworks should align with regulations, frameworks, and standards
governance, management
___ objectives always relate to a governance process while ___ objectives are always associated with management processes
COBIT CORE MODEL- 1 GOVERNANCE OBJECTIVE Evaluate, Direct, Monitor (EDM)
___: TCWG evaluate strategic objectives, direct management to achieve those objectives, and monitor whether objectives are being met. There are 5 objectives within this domain.
COBIT CORE MODEL- 3 MANAGEMENT OBJECTIVES Align, Plan, Organize (APO)
___: focuses on information technology's overall strategy, organization, and supporting activities. There are 14 objectives within this domain.
COBIT CORE MODEL- 4 MANAGEMENT OBJECTIVES Build, Acquire, and Implement (BAI)
___: addresses the implementation of information technology solutions in the organization's business processes. 11 objectives
COBIT CORE MODEL- 4 MANAGEMENT OBJECTIVES Deliver, Service, and Support (DSS)
___: addresses the security, delivery, and support of IT services. The 6 objectives