D320 Chapter 11

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/35

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:14 AM on 9/10/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

36 Terms

1
New cards

Risk Appetite/Tolerance

The amount of risk an organization is willing to accept, as determined by senior management.

2
New cards

Secrets Manager

Like a password manager for organizational/IT use. It manages passwords for applications/systems.

3
New cards

OWASP 3 Requirements for “break‐glass” Secrets Backup Environments

Ensuring automated backups are in place and executed regularly.

Frequently testing the restore procedures.

Encrypting backups and placing them on secure, monitored storage.

4
New cards

Common Criteria EAL Levels

EAL = Evaluation and Assurance Levels

EAL1: Functionally Tested

EAL2: Structurally Tested

EAL3: Methodically tested and checked

EAL4: Methodically designed, tested, and reviewed

EAL5: Semi-formally designed and tested

EAL6: Semi-formally verified design and tested

EAL7: Formally verified design and tested


5
New cards

CSA

Cloud Security and Alliance. Provides a set of vendor‐neutral design patterns for cloud security.

6
New cards

CSA STAR

Cloud Security and Alliance - Security, Trust, and Assurance Registry. A framework and registry used to evaluate cloud providers and their security controls as part of vendor management and due diligence.

7
New cards

Risk Profiles

A comprehensive analysis of the possible risks facing an organization, including operational, geographic, legal, and public perception risks.

8
New cards

Physical Controls

Controls that physically restrict or protect access to assets and reduce the impact of physical events, such as locks, fences, guards, and fire suppression.

9
New cards

Technical Controls

Logical controls that enhance the confidentiality, integrity, and availability of information, such as encryption, ACLs, audit trails, and logs.

10
New cards

Administrative Controls

Security processes and activities such as background checks, log reviews, mandatory vacations, policies, procedures, and business process design.

11
New cards

ISO 31000:2018

An international standard focused on designing, implementing, and reviewing risk management processes and practices.

12
New cards

NIST SP 800-37

A NIST methodology for managing organizational risk in a holistic, comprehensive, and continuous manner.

13
New cards

ENISA

Europe Network and Information Security Agency. EU counterpart to NIST. Standard and model developed in EU. Responsible for producing Cloud Computing: Benefits, Risks, and Recommendations for Information Security. Identifies top eight security risks based on likelihood and impact

14
New cards

COBIT

A framework for the governance and management of enterprise IT.

15
New cards

ISO/IEC 31010:2009

An international standard providing techniques and guidance for risk assessment and risk management.

16
New cards

Risk Management Metrics

A numerical scale used to rate risk severity: 5 is Critical, 4 is High, 3 is Moderate, 2 is Low, and 1 is Minimal.

17
New cards

ISO/IEC 15408-1:2009

Common Criteria Assurance Framework. Provide assurances for security claims by vendors. Assurance for security products customers purchase have been thoroughly tested by 3 rd  party testers and meets requirements.

18
New cards

ISO 28000:2007

An international standard addressing security management and controls within supply chains.

19
New cards

CSA STAR Program – Open Certification Framework

A cloud security assurance program with three levels:

Level One self-assessment

Level Two third-party attestation

Level Three continuous monitoring by a certified third party.

20
New cards

PKI

A framework of programs, procedures, communication protocols, and public-key cryptography that enables secure communication among diverse users and systems.

21
New cards

Cross-Certification Model

A federation model in which every participating organization reviews and approves every other organization, making the model difficult to scale.

22
New cards

Management Plane

The logical infrastructure and technology used by administrators to remotely manage cloud resources, such as launching virtual machines and configuring virtual networks.

23
New cards

Information Commissioner

An official responsible for enforcing UK GDPR and providing advice and assistance concerning the handling of personal information.

24
New cards

NIS Directive (EU 2016/1148)

The first EU-wide cybersecurity legislation, requiring covered organizations to notify competent authorities or CSIRTs about certain security incidents.

25
New cards

NIST 800-145

The NIST publication that defines cloud computing as convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or provider interaction.

26
New cards

NIST 800-146

A NIST document describing cloud computing benefits, open issues, major cloud technologies, and guidelines for evaluating cloud opportunities and risks.

27
New cards

Functional Requirements

Performance aspects of a device, process, or employee that are necessary for accomplishing a business task.

28
New cards

Nonfunctional Requirements

Desired or expected aspects of a device, process, or employee that are not necessary for accomplishing the business task.

29
New cards

Eucalyptus

Software used to build AWS-compatible private or hybrid cloud computing environments with multitenancy.

30
New cards

ISO/IEC 17788

An international standard providing an overview of cloud computing along with cloud computing terms and definitions.

31
New cards

NIST 500-292

A NIST document addressing the adoption of cloud computing by the U.S. federal government.

32
New cards

Metastructure

Protocols and mechanisms that provide an interface between the infrastructure layer and other cloud layers, connecting management and configuration technologies.

33
New cards

Software-Defined Infrastructure

Computing infrastructure that is controlled entirely through software with little or no direct human intervention.

34
New cards

Chaos Engineering

A testing method that deliberately introduces failures and faulty conditions into systems to verify resilience.

35
New cards

Differential Backup

A backup containing all data that has changed since the last full backup; each differential becomes larger until another full backup is performed.

36
New cards

Incremental Backup

A backup containing only data that has changed since the most recent backup; it uses less storage but can require more time to restore because multiple backups may be r