Governance & Policy
Risk Management
Legal & Compliance
Ethics & Standards
Misc. Mayhem
100

This is the highest-level document that outlines an organization's security intentions?

What is a security policy?

100

This is the risk that remains after all controls are applied.

What is residual risk?

100

This law protects health-related personal data in the U.S.

What is HIPAA?

100

The CISSP code of ethics says to protect this first.

What is society/the common good?

100

The three parts of the CIA triad.

What are confidentiality, integrity, and availability?

200

This concept ensures individuals only access data they need to do their job?

What is least privilege?

200

Name the 4 common risk response strategies.

What are accept, avoid, transfer, and mitigate?

200

This EU law protects the privacy of citizens’ personal data.

What is GDPR?

200

Acting with integrity, honesty, and respect aligns with this part of CISSP ethics.

What is act honorably, honestly, justly, responsibly, and legally?

200

This term means layering security controls across an environment.

What is defense in depth?

300

This is what a data owner primarily does.

What is classify data and determine access?

300

This is the formula for Annualized Loss Expectancy (ALE).

What is SLE × ARO?

300

This is the difference between civil and criminal law?

Civil = lawsuits/penalties; Criminal = jail/fines/punishment by state

300

Which international framework focuses on information security management systems?

What is ISO/IEC 27001?

300

The main goal of business continuity planning

What is to keep critical functions running during/after disruptions?

400

This document defines how to carry out a policy.

What is a standard or procedure?

400

This is the SLE of a server worth $100k and has an exposure factor of 0.3.

What is $30,000?

400

This is the legal term for failing to act with reasonable care.

What is negligence?

400

What’s the difference between due care and due diligence?

Due diligence = research; Due care = action taken

400

RTO and RPO in disaster recovery.

RTO = time to restore; RPO = max data loss acceptable

500

This principle requires multiple people to complete a critical task to prevent fraud.

What is separation of duties?

500

This method of evaluating risk uses rankings like High, Medium, and Low instead of dollar values.

What is qualitative risk analysis?

500

 This type of intellectual property protects creative works like books and music.

What is copyright?

500

This principle means ensuring security is considered from the very beginning of a project.

What is security by design?

500

STRIDE is used in this type of analysis.

What is threat modeling?

M
e
n
u