NIST Framework Flashcards

(17 cards)

1
Q

Front

A

Back

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NIST steht für?

A

National Institute of Standards and Technology.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Was bedeutet RMF?

A

Risk Management Framework.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Welches Dokument definiert das RMF?

A

NIST SP 800-37.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Nenne die 6 Schritte des RMF.

A

Categorize → Select → Implement → Assess → Authorize → Monitor.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Wofür steht SP in NIST SP 800-30?

A

Special Publication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Was beschreibt NIST SP 800-30?

A

Anleitung zur Risikobewertung (Threats, Vulnerabilities, Impact, Likelihood).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Welches Dokument enthält den Katalog von Sicherheitskontrollen?

A

NIST SP 800-53.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Welche drei Ebenen betrachtet NIST SP 800-39?

A

Organisation → Business/Mission → Information System.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Wofür steht CSF?

A

Cybersecurity Framework.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Nenne die 5 Funktionen des NIST CSF.

A

Identify → Protect → Detect → Respond → Recover.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Welches Dokument beschreibt Incident Response Prozesse?

A

NIST SP 800-61.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Nenne die Incident Response Phasen nach NIST SP 800-61.

A

Prepare → Detect/Analyze → Contain/Eradicate/Recover → Lessons Learned.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Wofür steht FIPS?

A

Federal Information Processing Standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Was definiert FIPS 199?

A

Kategorisierung von Systemen nach Vertraulichkeit, Integrität, Verfügbarkeit (Low/Moderate/High).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Was definiert FIPS 200?

A

Mindest-Sicherheitsanforderungen basierend auf der Einstufung aus FIPS 199.

17
Q

Welche Publikation behandelt Security Testing und Penetration Testing?

A

NIST SP 800-115.