The National Institute of Standards and ...
Technology
Is it HIPPA or HIPAA? (2 P's or 2 A's)
HIPAA
True or False...FERPA is a law.
True!
A catalog of cyber security and privacy controls published by NIST.
What cyber security concepts are represented in the CIA triad?
Confidentiality, integrity, and availability.
What is the type of product that NIST failed to standardize sizing for?
Women's Clothing
What does HIPAA stand for?
Health Insurance Portability and Accountability Act
True or False...PCI-DSS is a law
False; it was created by the Payment Card Industry Security Standards Council as optional standards.
There are [x] control families in NIST 800-53.
20
What would we be doing if we adjust and modify controls to meet our organization's specific needs?
Tailoring
What is the shape used to represent the functions in the NIST Cyber Security Framework CSF?
A Circle
True or False...HIPAA is not a law but it is a guideline created by the Nurses of America Group.
False; It is a federal US law.
There are four levels of PCI-DSS standards/complinace. What are those levels based on?
The amount of transactions made per year.
Each control in NIST 800-53 has a unique identifier which includes a 2-letter acronym and a number? (Ex. AC-2)
Where does the acronym come from?
What is the process of identifying the relationships between security controls of multiple frameworks?
Mapping
The NIST Cyber Security Framework contains [x] functions that all contribute to managing cyber risk.
6
What is the difference between the HIPAA Privacy Rule and the HIPAA Security Rule?
HIPAA Privacy Rule established how PHI can be used/disclosed.
HIPAA Security Rule established how to protect ePHI.
True or False...FERPA only applies to digital education records and PII.
False; It applies to digital, verbal, and physical records.
Every control family has a '-1' control
(Ex. AC-1, CM-1, AT-1).
What do the '-1's' regard?
Policies to implement the control family.
What is the difference between PII and PHI?
Personally Identifiable Information
Protected Health Information
In what year was the NIST Cyber Security Framework (CSF) 2.0 launched?
2024
HIPAA is purposefully vague because....
What does FERPA and PCI-DSS stand for?
Family Educational Rights and Privacy Act
Payment Card Industry - Data Security Standard
If you saw a control identifier that looked like
AC-3(2)
Why is there a 2 in parenthesis?
The 2 is called an enhancement which further defines a control.
How would you explain the concept of mapping through an analogy?
Imagine you and your roommates are planning a big dinner.
Roommate A writes a shopping list: “Buy bread, cheese, lettuce.”
Roommate B writes their own: “Get sandwich fixings.”
Roommate C says: “We need carbohydrates, dairy, and vegetables.”