1/79
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
(ISC)2
International Information System Security Certification Consortium. A security certification granting organization with a long history of certifications that were difficult to get. This difficulty has made their certificates seen as having higher value in the industry.
Administrative Law
Law created and enforced by executive branch agencies rather than directly by legislatures.
SAS 70
Statement on Auditing Standards No. 70. A recognized standard of the American Institute of Certified Public Accountants in response to issues that also led to Sarbanes-Oxley. It was deprecated in 2011 by Statement on Standards for Attestation Engagements No. 16.
AICPA
American Institute of Certified Public Accountants. The organization that established SAS 70 and later SSAE 16.
COPA
Child Online Protection Act. An attempt to restrict access by minors to material defined as harmful to minors. A permanent injunction against the law was issued in 2009.
Cloud Security Alliance Notorious Nine
Nine cloud security threats published by the Cloud Security Alliance:
Data Breaches Data Loss Account or Service Traffic Hijacking Insecure Interfaces and APIs | Denial of Service Malicious Insiders Abuse of Cloud Services Insufficient Due Diligence Shared Technology Vulnerabilities. |
CSA
Cloud Security Alliance. An organization associated with cloud security frameworks and programs such as STAR, CAIQ, and the Cloud Controls Matrix.
CSA STAR
Cloud Security Alliance Security, Trust, and Assurance Registry. A cloud security assurance program that uses tools such as the Consensus Assessments Initiative Questionnaire, Cloud Controls Matrix, and GDPR Self-Assessment.
CSA STAR Level 1
Uses the Consensus Assessments Initiative Questionnaire, Cloud Controls Matrix, and GDPR Self-Assessment as inputs to certify an organization to Level 1.
CSA STAR Level 2
Integrates the CSA Cloud Controls Matrix and AICPA Trust Service Principles for STAR attestation.
CSA STAR Certification
Uses the CSA Cloud Controls Matrix and the requirements of the ISO/IEC 27001 management system standard. Certification certificates follow normal ISO/IEC 27001 protocol for a third-party assessment.
CSA CCM
Cloud Security Alliance Cloud Controls Matrix. Composed of 17 domains covering key elements of cloud security and containing 170 objectives within those domains. It integrates with the STAR program.
COBIT
Control Objectives for Information and Related Technologies. A framework for IT governance and management. Initially used to achieve compliance with Sarbanes-Oxley and focused on IT controls. Since 2019, the emphasis has shifted to information governance.
COBIT's Five Principles
Meeting Stakeholder Needs; Covering the Enterprise End-to-End; Applying a Single Integrated Framework; Enabling a Holistic Approach; and Separating Governance from Management.
Common Criteria
A standard used to evaluate IT products. Products are evaluated by an independent laboratory and assigned an Evaluation Assurance Level based on the degree and type of testing.
EAL
Evaluation Assurance Level. A rating assigned to an IT product after it has been evaluated by an independent laboratory. Level 1 is the least and Level 7 is the most.
Common Criteria Functional Requirements
Common Criteria contains 60 functional requirements in 11 classes and is an accepted standard among military organizations of the United States and many allies.
CAIQ
Consensus Assessments Initiative Questionnaire. A Cloud Security Alliance initiative that provides industry-accepted documentation of security controls and, as of 2020, is combined with the Cloud Controls Matrix. It can be used as evidence for entry to the CSA STAR registry.
CLOUD Act
Clarifying Lawful Overseas Use of Data. U.S. law that allows law enforcement and courts to compel U.S. companies to provide data stored in foreign data centers under applicable legal authority.
DMCA
Digital Millennium Copyright Act. An act intended to align U.S. copyright law with the requirements of treaties and the World Intellectual Property Organization.
ENISA
European Union Agency for Cybersecurity. An organization that provides support, information, and collaboration on cybersecurity issues. It also publishes a list of major threats each year.
EU Data Directive
Regulates the processing of PII in the European Union. Because it is a directive, each country must pass laws establishing how it will enforce the directive. It includes seven principles governing the OECD's recommendations for protection of personal data.
ESAC
Eurocloud Star Audit Certification. A nonprofit organization that maintains information security standards or best practices and provides assessments and certification of compliance.
EAR
Export Administration Regulations. U.S. Department of Commerce regulations that restrict exports of certain dual-use technologies that can have both commercial and military applications.
ECPA
Electronic Communications Privacy Act. U.S. laws that restrict government wiretapping of telephone calls and electronic communications.
FERPA
Family Educational Rights and Privacy Act. A federal law that protects the privacy of student education records. It applies to schools that receive funds under an applicable program of the U.S. Department of Education.
FedRAMP
A U.S. federal program that standardizes security assessments, authorization, and continuous monitoring for cloud products and services used by federal agencies and contractors.
FIPS 140-2
Federal Information Processing Standard 140-2. A standard used for protecting sensitive but unclassified information and validating cryptographic modules. It provides four increasing qualitative levels of security, with Level 1 being the lowest and Level 4 the highest.
FIPS 140-3
The successor to FIPS 140-2.
CMVP
Cryptographic Module Validation Program. A joint effort between NIST and the Communications Security Establishment of the Government of Canada that validates cryptographic modules to FIPS 140-2 and other cryptography-based standards.
FISMA
Federal Information Systems Management Act. A U.S. law requiring federal agencies to develop, document, and implement cybersecurity management programs. NIST plays a major role in implementing FISMA and has promulgated numerous security standards and guidelines.
OMB's Role in FISMA
The Office of Management and Budget monitors compliance with NIST programs related to FISMA.
GDPR
General Data Protection Regulation. A European Union privacy regulation that gives individuals control over their personal data and requires all member states to comply with a single regulation. It specifies rights of data subjects and requirements for data controllers and data processors.
GDPR Data Subject Rights
Rights include access, rectification, erasure, and the ability to object to the use of personal information.
GAPP
Generally Accepted Privacy Principles described by the AICPA. Principles and practices agreed upon by 23 countries in response to investor and regulator concerns about transparency, independence, and governance of the accounting industry.
GLBA
Gramm-Leach-Bliley Act. Requires companies that offer financial products or services to safeguard sensitive customer data and inform customers of those requirements.
HIPAA
Health Insurance Portability and Accountability Act. Modernized healthcare information and stipulated how personally identifiable information kept by healthcare and healthcare insurance industries should be protected.
HITECH
An act that motivated the implementation of electronic health records and supporting technology. It increased some penalties for HIPAA noncompliance and established breach notification requirements for impacted patients.
IDCA
International Data Center Authority. An organization attempting to be a standardization, education, and certification body for the application ecosystem and supporting digital infrastructure. IDCA-certified auditors assess cloud providers for compliance with IDCA Grade Levels.
ITAR
International Traffic in Arms Regulations. U.S. State Department regulations that restrict exports of defense-related items and technologies, including certain cryptographic systems.
ISO
International Standards Organization. An international standards body composed of representatives from various standards organizations.
ISO/IEC 20000-1
Information Technology – Service Management. A standard defining operational controls and standards for managing IT services, including approaches associated with ITIL and COBIT.
ISO/IEC 27001
A standard on managing information security. It includes requirements for establishing, implementing, maintaining, and continually improving information management.
ISO/IEC 27002
Provides best practices for information security controls for organizations attempting to comply with ISO/IEC 27001.
ISO/IEC 27017
A standard created to supplement ISO/IEC 27002 by providing additional security controls for cloud environments.
ISO/IEC 27018
An IT security standard and code of practice for the protection of personally identifiable information in public clouds.
ISO/IEC 27034-1
A standard that mandates a framework for application security within an organization. Each organization should have an Organizational Normative Framework, and each application should have its own Application Normative Framework.
ISO/IEC 27037:2012
An ISO standard providing guidance for identifying, collecting, and preserving electronic evidence.
ISO/IEC 27041:2015
An ISO standard providing guidance for incident investigation.
ISO/IEC 27042:2015
An ISO standard providing guidance for the analysis and interpretation of digital evidence.
ISO/IEC 27043:2015
An ISO standard describing principles and processes for incident investigation.
ISO/IEC 27050-1:2016
An ISO standard providing an overview and principles for electronic discovery.
ISO/IEC 28000:2007
A standard for ensuring security assurance in the supply chain.
ISO/IEC 31000:2009
A standard providing industry-independent principles and guidelines for risk management. It does not attempt to achieve uniformity but instead supports the most appropriate risk management for each organization's objectives, context, structure, operations, processes, functions, services, or assets.
ISO/IEC 31010:2009
An international standard providing techniques and guidance for risk assessment and risk management.
ISO/IEC 17788
An international standard providing an overview of cloud computing along with cloud computing terms and definitions.
ISO/IEC 15408-1:2009
Common Criteria Assurance Framework. A framework for providing assurance that security products meet stated security requirements and have been thoroughly evaluated by independent third-party testers.
NFPA
National Fire Protection Association. A nonprofit organization attempting to eliminate death, injury, property loss, and economic loss due to fire, electrical, and related hazards.
NIST
National Institute of Standards and Technology. An agency of the Department of Commerce whose mission is to promote innovation and industrial competitiveness. It also creates numerous standards and requirements for the Department of Defense, federal government, and government contractors relating to cybersecurity.
NIST SP 800-37
Establishes the Risk Management Framework using a life-cycle approach for security and privacy. The RMF provides a disciplined, structured, and flexible process for managing security and privacy risk, including categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
NIST SP 800-53
Provides security and privacy controls for information systems and organizations.
NIST SP 800-92
Guide to Computer Security Log Management. Provides practical guidance on developing, implementing, and maintaining effective log management practices throughout an enterprise, including log management infrastructure, processes, and logging technologies.
NIST 800-145
The NIST publication that defines cloud computing as convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or provider interaction.
NIST 800-146
A NIST document describing cloud computing benefits, open issues, major cloud technologies, and guidelines for evaluating cloud opportunities and risks.
OWASP
Open Web Application Security Project. A nonprofit organization working to improve software security. It is known for publishing the Top 10 most critical security concerns for web application security.
OECD and 7 Principles
Organization for Economic Cooperation and Development. Produced seven principles governing the protection of personal data.
1. Notice—data subjects should be given notice when their data is being collected;
2. Purpose—data should only be used for the purpose stated and not for any other purposes;
3. Consent—data should not be disclosed without the data subject’s consent;
4. Security—collected data should be kept secure from any potential abuses;
5. Disclosure—data subjects should be informed as to who is collecting their data;
6. Access—data subjects should be allowed to access their data and make corrections to any inaccurate data
7. Accountability—data subjects should have a method available to them to hold data collectors accountable for not following the above principles.
-
PANDASC? Sounds like Pandas See?
PIPEDA
Personal Information Protection and Electronic Documents Act. A Canadian data privacy law that protects the PII of individuals. It allows individuals to inspect data held by an organization and challenge its accuracy and requires organizations to obtain consent when collecting, using, and disclosing PII.
PLA
Privacy Level Agreement. An agreement that contracts how a third-party provider will ensure the confidentiality of information an organization permits the provider to access.
RMF and Steps
Risk Management Framework. A set of standards and guidelines used to develop a risk-based approach to information security.
Prepare for risk management Categorize systems and information based on impact studies Select appropriate controls based on risk assessments | Implement and document the controls Assess how well the controls work Authorize the system to operate Monitor controls and changes to system risks. |
SABSA
Sherwood Applied Business Security Architecture. A framework for enterprise security architecture and service management.
SOX
Sarbanes-Oxley Act. A law passed to increase independence in audit practices and require the retention and accuracy of financial records as a result of financial and stock scandals associated with Enron.
SEC
U.S. Securities and Exchange Commission. Its primary purpose is to combat market manipulation, and it also enforces the Sarbanes-Oxley Act.
SRE
Site Reliability Engineering. A set of practices and principles intended to produce scalable and highly reliable software systems.
DevOps
Practices that combine software development and IT operations. DevOps is closely related to Site Reliability Engineering.
SSAE 16
Statement on Standards for Attestation Engagements No. 16. An auditing standard that succeeded SAS 70 and led to subsequent SOC reports.
SOC Reports
System and Organization Controls reports. Reports that help companies establish trust and confidence in service delivery and controls. They are produced by third-party certified public accountants.
OMB
U.S. Office of Management and Budget. A component of the Executive Branch that manages FedRAMP and directs its use for the federal government's use of cloud computing.
Uptime Institute
An organization that created and promotes the Tier Standard, which guides the design, construction, and operation of sites worldwide.
Uptime Institute Tier Ratings
Data centers can be rated from Tier 1, the lowest, to Tier 4 based on built-in redundancy, distribution paths, concurrent maintenance, fault tolerance, compartmentalization, and cooling.
USPTO
U.S. Patent and Trademark Office. The government office that registers patents and tra