5.1 Security Standards Flashcards

(20 cards)

1
Q

What do standards in the technology industry provide?

A

Extensive documentation for handling different situations and reducing risk in environments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are two organizations that provide a set of security standards?

A
  • ISO (International Organization for Standardization)
  • NIST (National Institute of Standards and Technology)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a key aspect of password security standards?

A

Defining what a good password is and the appropriate password complexity for an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What might a password policy standard define?

A
  • Frequency of password changes
  • Secure storage of passwords
  • Acceptable types of password managers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does access control determine?

A

What type of information someone can access and when they can access it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False: A discretionary access control policy is always required by organizations.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What might be required to determine user access type?

A
  • Management sign-off
  • Completion of a course
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are some reasons for removing user access?

A
  • Security issues
  • Account expiration
  • User leaving the organization
  • Contract expiration
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is an important consideration for physical security standards?

A

Securing the property, especially with many people coming in and out.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What might physical security standards require from users?

A

Presenting an ID badge for access through electronic door locks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Fill in the blank: An organization might have standards defining the type of __________ that are in use.

A

electronic door locks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What could be an example of a requirement for electronic door locks?

A

Biometric aspects for additional security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What documentation is recommended for encryption technologies?

A

Well-documented standards on how encryption should be used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are different states of data that might have different encryption requirements?

A
  • Data at use
  • Data in transit
  • Data at rest
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a good practice for storing passwords?

A

Storing them as a hash or a salted hash.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What should standards define regarding password storage?

A

The exact hashing algorithm required.

17
Q

What does encryption aim to protect?

A

The confidentiality of information being stored.

18
Q

What might require ongoing monitoring in an organization?

A

Physical security measures.

19
Q

True or False: Standards for offboarding are the same across all organizations.

20
Q

What is the purpose of security standards in organizations?

A

To keep everyone safe and prevent unauthorized access.