Home
Flashcards
Preview
Compliance SEC+
The flashcards below were created by user
anthonyrt2015
on
FreezingBlue Flashcards
.
Home
Mobile
Quiz
What are the control categories?
Preventive
Deterrent
Detective
Corrective
Recovery
Directive
Compensating
Physical Security
Protection of computing facilities
Physical protection for end-user systems:
Media access control and disposal procedures
Backup systems and provisions for offsite backup storage
____Dictates the security structure of an organization and establishes the goals of the security program
Security Policy
To be effective in a security policy
Planned
Implemented
Maintained
_____is the reason for mandatory vactions
Fraud
Job rotations are good for____
Fraud protection
____cover a clearly stated policy regarding privacy
Privacy Policy
Three measure for risk analysis are:
Likelihood
Annualized Loss Expectancy(ALE)
Impact
What are the two major risk analysis types:
Quantitative Analysis and Qualitative Analysis
Hint: Quantitative(numbers) Qualitative(judgements)
Steps in Quantitative Analysis Process
Identify threats, threat vectors, vulnerabilities and impacts
Types of Evidence
Best
Secondary
Direct
Conclusive
Opinion
circumstantial
Hearsay
Author
anthonyrt2015
ID
305003
Card Set
Compliance SEC+
Description
Compliance
Updated
2015-07-09T15:14:21Z
Show Answers
n
Home
Flashcards
Preview