WorksheetsIS Security - Jason Andreas 2024
Total questions: 20
Worksheet time: 10mins
Information security is defined as
“protecting information and information systems from ....
disruption
disclosure
authentication
authorization
Part of Parkerian Hexad
Authenticity
Possession of Control
Utility
Alteration
Type of Attack of Confidentiality on CIA Triad
Interruption
Modification
Interception
Fabrication
Potential activities cause harms
Risk
Threat
Vulnerability
All
Incident Response Standard
ISO 31000
ISO 27002
ISO 27001
ISO 27035
Defensive Measure in Application Layer
Encryption
Content Filtering
SSO
Backup
In Authentication, Token or ATM called as
Something You Are
Something You Have
Something You Know
Something You Do
Part of Biometrics requirements
Universality
Clearly
Permanence
All Wrong
In Access Control, the owner of the resource determines who gets access to it and exactly what level of access they can have
RBAC
DAC
MAC
RuBAC
A Model of Multilevel Access Control which combine of DAC and MAC
Brewer and Nash Model
Biba Model
Bell-LaPadula Model
No Option
"Be aware of wet floor" is part of
Repudiation
Non-repudiation
IDS and IPS
Deterrence
Private Key Cryptography known as
Linear Cryptography
Asymmetric Cryptography
Symmetric Cryptography
Cingular Cryptography
The example of Algorithm in Symmetric Cryptography
3DES
RSA
AES
All
The example of Hash Functions
SHA
MD5
DES
Crypto
Protecting Data in Motion
HTML
SSL
TLS
VPN
Part of Government Regulatory Compliance
SOX
FedRAMP
HIPAA
FISMA
Part of Industry Regulatory Compliance
CIPA
PCI DSS
GLBA
SOX
Year of GDPR enacted in Europe
2013
2017
2019
2018
“Guide for Applying the Risk Management Framework to Federal Information Systems,” ... NIST no ... ?
NIST SP 800 - 57
NIST SP 800 - 37
NIST SP 800 - 53
NIST SP 800 - 60
Technology Law in Indonesia
POSKAMLING
SPBE
UU ITE
KAMSIBER
