Information Security and Governance

0.0(0)
studied byStudied by 0 people
full-widthCall with Kai
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/18

flashcard set

Earn XP

Description and Tags

Flashcards covering key terms and definitions related to information security principles, governance, risk management, and compliance.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

19 Terms

1
New cards

ISC2 Code of Ethics

A set of principles that information security professionals must adhere to, ensuring their commitment to ethical standards.

2
New cards

Preamble

Introduces the ISC2 Code of Ethics and emphasizes the importance of safety, welfare, and ethical behavior.

3
New cards

The Canons

Fundamental beliefs of ISC2 members regarding their duties to society, honesty, service, and the profession.

4
New cards

Privacy in the Working Environment

A critical aspect of information security focused on protecting sensitive information from unauthorized access.

5
New cards

HIPAA

Health Insurance Portability and Accountability Act, establishing standards for the protection of medical information in the United States.

6
New cards

GDPR

General Data Protection Regulation, a framework in the EU that gives individuals control over their personal data and imposes heavy penalties for breaches.

7
New cards

Risk Management Terminology

Key concepts in cybersecurity including assets, vulnerabilities, and threats used in assessing and managing organizational risk.

8
New cards

Asset

Anything that needs protection within an organization, such as data or systems.

9
New cards

Vulnerability

A weakness or gap in an organization's security that can be exploited by threats.

10
New cards

Threat

Any potential danger that can exploit a vulnerability to cause harm to an asset.

11
New cards

Risk Tolerance

The level of risk an organization is willing to accept in pursuit of its goals.

12
New cards

Governance

The framework of rules, practices, and processes used to guide and control an organization.

13
New cards

Compliance

Adherence to laws, regulations, and standards as required by governing authorities.

14
New cards

Security Controls

Measures implemented to protect information systems; includes physical, technical, and administrative controls.

15
New cards

Physical Controls

Security measures that use physical devices to protect assets, such as locks and badge readers.

16
New cards

Technical Controls

Security measures implemented through technology, such as firewalls and encryption.

17
New cards

Administrative Controls

Policies and procedures aimed at managing organizational behaviors and operations concerning security.

18
New cards

NIST

National Institute of Standards and Technology, a U.S. government agency that develops and publishes standards for various industries.

19
New cards

ISO

International Organization for Standardization, an organization that develops and publishes international standards.