1/22
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
Due diligence
Process of setting controls to maintain compliance.
Due care
Process of implementing, maintaining, and responding to those controls.
General Data Protection Regulation (GDPR)
Regulation for EU residents that protects personal information and privacy.
Right to be informed
Right of EU residents to be informed about the processing of their personal data.
Right of access
Right of EU residents to access their personal data held by organizations.
Right to rectification
Right of EU residents to correct inaccurate personal data.
Right to be forgotten
Right of EU residents to request deletion of their personal data.
Payment Card Industry Data Security Standard (PCI DSS)
Compliance requirements for the security of cardholder data.
CIS Critical Security Controls (CSC)
Security framework consisting of recommended security controls organized in 18 areas.
Risk Management Framework (RMF)
Systematic process required by public sector organizations to address risks.
ISO/IEC 27001
Standard for implementing an information management security system (ISMS).
SOC 2 Type 1
AICPA point-in-time audit of a service entity's security controls.
SOC 2 Type 2
Periodic, annual audit of a service entity's security controls.
Secure baseline
Set of standardized security configurations and controls to provide minimum security.
Business continuity plan (BCP)
Set of processes followed to maintain business continuity during a disaster.
Data governance
How data is collected and accessed during its life cycle.
Gamification
Use of game-like elements to enhance personnel training.
Instructor-led training (ILT)
Live training delivered by an instructor.
Anomalous behavior
Recognizing actions or patterns that deviate from normal operational behavior.
Password policy
Guidelines for password complexity and expiration.
Background check policy
Policy requiring background checks for new employees.
Mandatory vacation policy
Policy requiring employees to take paid time off to expose security issues.
Incident response plan (IRP)
Processes followed to recognize, respond, and recover from an incident.