1/68
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
When the question mentions U.S. government cybersecurity guidance / risk frameworks, think …
NIST. National Institute of Standards and Technology
A U.S. federal agency responsible for granting patents and registering trademarks = …
USPTO = U.S. Patent and Trademark Office.
Is an Agency/Organization
It's associated with validating cryptographic modules against FIPS 140 requirements = …
CMVP = Cryptographic Module Validation Program
A federal law that establishes requirements for information security in federal agencies and federal information systems = …
FISMA = Federal Information Systems Management Act
Trigger words:
web applications
application security
application vulnerabilities
secure coding
SQL injection
XSS
Think…
OWASP = Open Web Application Security Project
Trigger words:
electronic communications
emails
phone communications
stored communications
interception
unauthorized access to communications
Think…
ECPA = Electronic Communications Privacy Act
It's a set of privacy principles used to evaluate and manage how organizations handle personal information. = …
GAPP = Generally Accepted Privacy Principles
“What are children being exposed to online?” Think…
“What information is being collected about children?” Think…
COPA = Child Online Protection Act
COPPA = Children's Online Privacy Protection Act
It was aimed at restricting minors' access to harmful material online = …
COPA = Child Online Protection Act
It focuses on the online collection of personal information from children under 13, including requirements involving parental consent = …
COPPA = Children's Online Privacy Protection Act
Trigger words:
Canada
Canadian privacy
personal information
private-sector organizations
collection/use/disclosure of personal information
Think…
PIPEDA = Personal Information Protection and Electronic Documents Act
It's associated with data-center standards, infrastructure, and operational practices. = …
IDCA = International Data Center Authority
Trigger words:
data center
data-center infrastructure
data-center design
data-center operations
availability/reliability of data centers
Think…
IDCA = International Data Center Authority
It's a professional cybersecurity organization associated with certifications such as CISSP = …
(ISC)2 = International Information System Security Certification Consortium
ISO 31??? = “How do we manage risk?”
ISO 31??? = “How do we assess the risk?”
ISO 31000
ISO 31010
The overall principles and guidelines for MANAGING risk = …
ISO 31000
A cloud security transparency program. It gives customers information about a cloud provider's security practices = …
CSA STAR. Cloud Security Alliance Security, Trust, and Assurance Registry.
Self-assessment of cloud security by the cloud provider = …
CSA STAR Level 1
Third-party assessment/certification of cloud security of a cloud provider = …
CSA STAR Level 2
“A company wants a framework containing controls specifically addressing cloud security.”
Think…
“A U.S. federal agency needs a catalog of security and privacy controls for its information system.”
Think…
CSA CCM
NIST 800-53
A framework/catalog of cloud-specific security controls = …
CSA CCM (Cloud Controls Matrix).
“Questions I ask a cloud provider about their security.” = …
CAIQ = Consensus Assessments Initiative Questionnaire
Trigger words:
overseas data
cross-border
different jurisdictions
government access to electronic data
data stored outside the U.S.
conflicting laws between countries
Think …
CLOUD Act. Clarifying Lawful Overseas Use of Data.
The techniques/tools for risk assessment/measuring risk = …
ISO 31010
If you see:
Cloud computing terms/definitions
Cloud terminology
Overview of cloud computing
Think…
ISO 17788
Application security, application framework, ONF, ANF = …
ISO 27034-1
Common Criteria / EAL = …
ISO 15408-1
Old, depreciated auditing standards = …
SAS 70
"I want to see the report about the service provider's controls." = …
SOC
"Which international standard guides the examination of a service organization’s controls?" = ..
ISAE 3402. International Standard on Assurance Engagements
"Which U.S. standard guides the examination of a service organization’s controls?" = ..
SSAE 16. Statement on Standards for Attestation Engagements No. 16
Accounting, accountants = …
AICPA. American Institute of Certified Public Accountants
When a question mentions cryptography, think …
FIPS. Federal Information Processing Standards
When a question mentions international standards / management systems, think …
ISO. International Organization for Standardization.
When a question mentions publicly traded companies / financial reporting & controls think …
SOX. Sarbanes-Oxley Act
“What law requires public companies to have financial reporting/internal controls?” = …
SOX. Sarbanes-Oxley Act
A U.S. federal government agency that regulates securities markets and public companies = …
SEC = Securities and Exchange Commission
When a question mentions protecting customer financial information think …
GLBA. Gramm-Leach-Bliley Act
When a question mentions auditing / assurance reports think …
SOC / SSAE / ISAE
System and Organization Controls / Statement on Standards for Attestation Engagements / International Standard on Assurance Engagements
Federal cloud authorization, federal cloud approval = …
FedRAMP
Trigger words:
Evaluate a security product
IT product
EAL
Evaluation Assurance Level
EAL1–EAL7
Think … or …
Common Criteria, CC or ISO 15408-1
Security evaluation of IT products = …
Common Criteria, CC
When you see things like:
Risk assessment
Incident response
Federal cybersecurity guidance
CUI
Security frameworks
Think …
NIST. National Institute of Standards and Technology
If you see:
ISMS
Information security management
Cloud security
Privacy management
Think …
ISO. International Organization for Standardization.
Which standard provides an ISMS?
ISMS is Information Security Management System
Think Information Security Management → ISO
ISO 27001
Which publication provides a catalog of federal security controls?
NIST 800-53
Which organization develops cybersecurity standards and guidance?
NIST
NIST 800-145 and NIST 800-146 are both ___
Cloud
NIST 800-171 = _ _ _
NIST 800-171 = CUI
Remember there are only three NIST that have 3 digits after 800. 145-146 are cloud related. Just remember that the other 3 digit NIST (171) is CUI (also 3 letters).
CUI = Controlled Unclassified Information
RMF, Risk Management Framework, authorization, security lifecycle = …
NIST 800-37
ISMS = ___ ___
ISO 27001
How to implement controls/guidance = ___
List of privacy and security controls = ___
ISO 27002
NIST 800-53
Trigger words:
HSM
Cryptographic module
Encryption hardware
Cryptographic keys
Federal cryptography
Security requirements for cryptographic modules
Think …
FIPS 140-2 or FIPS 140-3 (newer)
Do not select 140-3 as an answer if 140-2 is there.
Logging, log management, security logs = …
NIST 800-92
Cloud computing, 5 essential characteristics, service/deployment models = …
NIST 800-145
Cloud business case = …
NIST 800-146
Privacy, privacy information management, PIMS = …
ISO 27701
Cloud security, cloud service security controls = …
ISO 27017
Cloud architecture, cloud computing reference architecture = …
ISO 17789
Acquire, preserve digital evidence = …
ISO 27037
Forensic methods, forensic tools, methodology = …
ISO 27041
Interpret digital evidence = …
ISO 27042
Investigation principles/process = …
ISO 27043
Electronically stored information, discovery process = …
ISO 27050-1
Private security operations, security operations management = …
ISO 18788
ISO 270??–270?? = Digital evidence/forensics family
ISO 27037-27043
How do I secure the cloud? Think…
ISO 27017
How is the cloud structured? Think…
ISO 17789
ISO 27037 = __ __ 41 =__ __ 42 = __ __ 43 = __ __
37 = Get it → 41 = Verify it → 42 = Analyze it → 43 = Investigate it
Get it (digital evidence)