Intelligence-led testing Flashcards

(16 cards)

1
Q

Describe Intelligence-led Security Testing

A

Understanding the range of scenarios in which threat intelligence can be used within an organisation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Importance of Intelligence-led Testing

A

Helps organisations understand the threat they face and ensures they are defending themselves against threats specific to them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Purpose of Intelligence-led Testing

A

Understand the threat to protect yourself from it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CTI Component in Testing Frameworks

A

Ensures organisations are tested on their ability to prevent, detect and respond to realistic, contemporary and accurate attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is CBEST?

A

Part of the Bank of England and PRA’s toolkit to assess cyber resilience of firms’ important business services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is TIBER-NL?

A

Threat Intelligence Based Ethical Red-teaming for the Dutch financial sector.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

TBEST

A

Framework for the UK telecoms sector.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

TIBER-EU

A

Framework for the European financial sector.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

iCAST

A

Intelligence-led Cyber Attack Simulation Testing for Hong Kong’s financial sector.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

GBEST

A

Framework for UK government departments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

ATTEST

A

Framework for the UK aviation industry.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk Formula

A

Risk = Vulnerability x Threat x Impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Definition of Threat

A

The intent and capability of an adversary to target an asset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Threat Understanding

A

Organisations need to know who is likely to target what assets, where, when, how and why to defend themselves.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Risk Assessment

A

Combine threat understanding with cyber defence maturity to calculate likelihood of an incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Risk Score

A

Likelihood X Impact.