ISC S1 BABY LETS GOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/28

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:56 AM on 9/22/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

29 Terms

1
New cards

NIST framework incl what 3 3 other frameworks

  • CSF

  • Priv framework

  • Sec. & priv. cntrls for info sys & orgs


2
New cards

cybersecurity framework (CSF) contains which 3 things

CSF = voluntary framework

  • CSF core

  • CSF tiers

  • CSF org profiles


3
New cards

6 components of CSF core

  • ID

    • understand risks of assets & suppliers of an org

  • protect

    • org’s aability to secure assets and prevent attacks

  • detect

    • timely disovery of attacks & incidents

  • respond

    • ability to contain effects of incidents

  • recover

    • restore ops and comm efforts

  • govern

    • anything governing related



4
New cards

CSF tiers

1) partial (limited awareness, case by case basis)

2) risk-informed (isolated policies, acts inconsistently)

3) repeatable (policies get updated & doc’d, good comms)

4) adaptive (part of the culture, contd. improvement)


each tier subdivided into risk governance & risk mgmt

5
New cards

CSF org profiles

should have 1 or both of either target profile or current profile (obv)

6
New cards

NIST priv. framework (5 steps)

some steps shared with CSF

1) ID (also in csf)

2) govern (also csf)

3) control (only priv) (anything related to processing)

4) communicate (only priv)

5) protect (in csf as well)

same 4 implementation tiers as before

7
New cards

NIST security & privacy cntrls (SP 800-53)

stricter compared to CSF & privacy, those are about cost effectiveness but this one is about sophisticated threats

must satisfy:

  • office of mgmt & budget (OMB)

  • fed info sec. modernization act (FISMA)


8
New cards

3 control implementation approaches to be used on a per control basis (for NIST sec & privacy cntrls / SP 800-53)

  • common (inheritable) cntrls

    • implement at org level

  • sys-specific cntrls

    • implement at infy-sys level

  • hybrid cntrls

    • implement at both levels


9
New cards

what is the EU’s set of priv laws

GDPR, way stricter than US

10
New cards

covered entities in HIPAA

  • HC providers

  • H plans

  • HC clearing houses

  • service providers who access PHI (priv health info)


also recently now incl business things (idr the name)


11
New cards

when can covered entities use / disclose PHI w/o auth?

  • to the patient

  • for treatment, pmt, & HC ops

  • valid auth

  • after giving patient opportunity to agree or object

  • public interest / lawful activities

  • research or public benefit stuff



12
New cards

all covered entities must: 3 things

  • ensure protection of all PHI

  • prot against reasonably anticipated threats

  • ensure workfore compliance



13
New cards

HIPAA safeguards (3)

  • admin

  • physical

  • technical


14
New cards

HITECH of 2009

  • paper → electronic

  • increased penalties

  • 60d notice to breached individuals



15
New cards

who does GDPR apply to

anyone who does business in the EU or is located in EU / a EU embassy

16
New cards

privacy shield / safe harbor

declared INVALID by EU (companies in EU gotta be careful sending their data across the atlantic to the US)

17
New cards

pmt card industry data sec. standard (PCIDSS) (

for cashless transactions

pen testing / vuln scanning every 3mo!!

6 goals / reqs of PCIDSS:

  • build & maintain secure networks

  • protect acct data

  • vuln mgmt program

  • implement access cntrls

  • monitor & test cntrls

  • maintain info sec. policy


18
New cards

what are CIS cntrls (center for internet security)

these are the 18 rec’d cntrls, also incl IG1-3

19
New cards

IG1-3 (implementation groups) for CIS cntrls

1

  • small / med firms w/ limited IT experience

  • partial / risk informed

  • NO PHI or PII

2

  • incl. 1

  • for firms that have sensitive client info & IT staffs

  • repeatable

3

  • incl 1-2

  • firms have sec. experts in all domains

  • they have data sets subject to regulations

  • adaptive


20
New cards

CIS cntrls 1-6

1) inventory & cntrl of enterprise assets

  • org & track all IT assets (physical or virtual) to know which ones should be monitored / protected. know which ones have sensitive info, also focus on potential external devices that could connect via guest network

2) inventory & cntrl of software assets

  • track & manage all software so that only auth’d software is used, also so unauth’d software is located and removed quickly and make sure software is up to date

3) data protection

  • manage entire life cycle of data, classify based on sensitivity, ID & archive properly

4) secure config of enterprise assets & software

  • basically change the default / initial config to make it actually fit your business.. incl. ‘sec hardening’ which is to constantly improve against new attacks

5) acct mgmt

  • best practices for managing credentials, auth for user accts, privileged user accts, service accts for hardware / software, admin accts should be restricted to specific cases, SSO & MFA

6) access cntrl mgmt

  • expands on cntrl 5 by clarifying the type of cntrl that user accts should have = least privilege / need to know. incl protocols for granting / revoking access



21
New cards

CIS cntrls 7-12

7) continuous vuln mgmt

  • continuously track & ID vulns so that you can find the weak points, 0-day exploits = attack when there’s no known solution

8) audit log mgmt

  • get alerted / recover from attacks in real time. Sys logs = events, restoration points, crashes, start and end times. audit logs = access times

9) email & web browser protection

  • URL filtering, block certain file types, restrict user options

10) malware defense

  • prevents installation and spread of malware. living off land = using org’s tools against itself

11) data recovery

  • data backup, testing, & restoration. offsite storage = good

12) network infrastructure mgmt

  • procedures & tools for managing network infrastructure, firewalls, routers, switches, wireless access points, architecture docs and diagrams, always ID & remediate insecure network config settings



22
New cards

CIS cntrls 13-18

13) network monitoring & defense

  • monitor against internal & external threats, like DoS or ransomware. use traffic flow monitoring

14) security awareness & skills training

  • positively influence employee behavior & educate them on threats, MORE than annual training

15) service provider mgmt

  • eval all 3rd party services that have access to sensitive data or if they manage IT functions. SOC reports can help

16) application software security

  • safeguards to manage entire lifecycle of any software to resolve weaknesses, incl buffer overflows, XCC, sql injections, be aware of lack of visibility of SaaS programs

17) incident response mgmt

  • detect, respond, prepare for attacks. might have to notify

18) penetration testing

  • testing sec by simulating attacks. red team = focus on specific tasks, techniques, & procedures


23
New cards

COBIT 2019 governance vs mgmt

gov

  • usually BoD, focused on committees & org structures

mgmt

  • selected & guided by BoD, handles d2d ops, c suite


24
New cards

what principles are in COBIT 2019

6 principles for gov system

3 principles for a gov framework

25
New cards

6 principles for gov system COBIT 2019

  • SH value

  • holistic approach (18 CIS cntrls)

  • dynamic gov sys

  • gov distinct from mgmt

  • tailored to enterprise needs

  • end to end gov sys (should consider more than just IT functions)


26
New cards

3 principles for gov framework

  • based on conceptual model (ID key stuff for best efficiency)

  • open & flexible

  • aligned to major standards


27
New cards

governance objectives (COBIT 2019) (EDM)

EDM = eval, direct, monitor

incl:

  • ensure benefits delivery

  • gov framework setting

  • risk optimization

  • resource optimization

  • SH engagement


28
New cards

4 domains of mgmt objectives (BAI, DSS, MEA, APO)

  • build acquire implement (BAI)

  • deliver service support (DSS)

  • monitor, eval, assess (MEA)

  • align plan organize (APO)


29
New cards

available COBIT 2019 publications

introduction & methodology

  • obvious

gov & mgmt objectives

  • comprehensive outline of the 40 objectives / components

design guide: designing IT gov solutions

  • basically everything ‘design’

implementation guide

  • continuous improvement