(ISC)2 Certified in Cybersecurity - Exam Prep
30 studiers today 4.6 (90 reviews)
Save
Students also studied
Flashcard sets Study guides
ISC2 - CC ISC2 Certified In Cybersecurity (CC)... Chapter 1: Security Principles CompT
174 terms Teacher 150 terms Teacher 57 terms 126 term
fpnjie Preview Marga_Tabah Preview ISC2Education Preview end
Terms in this set (598) Hide definitions
Document specific requirements that a customer has C) SLR (Service-Level Requirements)
about any aspect of a vendor's service performance.
A) DLR
B) Contract
C) SLR
D) NDA
_________ identifies and triages risks. Risk Assessment
_________ are external forces that jeopardize security. Threats
_________ are methods used by attackers. Threat Vectors
_________ are the combination of a threat and a vulnerability. Risks
We rank risks by _________ and _________. Likelihood and impact
_________ use subjective ratings to evaluate risk likelihood Qualitative Risk Assessment
and impact.
_________ use objective numeric ratings to evaluate risk Quantitative Risk Assessment
likelihood and impact.
, _________ analyzes and implements possible responses to Risk Treatment
control risk.
_________ changes business practices to make a risk Risk Avoidance
irrelevant.
_________ reduces the likelihood or impact of a risk. Risk Mitigation
An organization's _________ is the set of risks that it faces. Risk Profile
_________ Initial Risk of an organization. Inherent Risk
_________ Risk that remains in an organization after controls. Residual Risk
_________ is the level of risk an organization is willing to Risk Tolerance
accept.
_________ reduce the likelihood or impact of a risk and help Security Controls
identify issues.
_________ stop a security issue from occurring. Preventive Control
_________ identify security issues requiring investigation. Detective Control
_________ remediate security issues that have occurred. Recovery Control
Hardening == Preventative Virus == Detective
Backups == Recovery For exam (Local and Technical Controls are the same)
_________ use technology to achieve control objectives. Technical Controls
_________ use processes to achieve control objectives. Administrative Controls
_________ impact the physical world. Physical Controls
_________ tracks specific device settings. Configuration Management
_________ provide a configuration snapshot. Baselines (track changes)
_________ assigns numbers to each version. Versioning
_________ serve as important configuration artifacts. Diagrams
_________ and _________ help ensure a stable operating Change and Configuration Management
environment.