Domain 1: Security and Risk Management - Security Frameworks

17 important questions on Domain 1: Security and Risk Management - Security Frameworks

What is meant with "security through obscurity"?

This concept is assuming that you are smarter than your enemies and they cannot figure out something you feel tricky about.

Can you describe a non tech example of security through obscurity?

Key under doormat

In what was can vulnerabilities been spot by an attacker?

1. Reverse engineer
2. Fuzzing
3. Data validation inputs
4. Etc...
  • Higher grades + faster learning
  • Never study anything twice
  • 100% sure, 100% understanding
Discover Study Smart

Is it smart to develop your own inhouse cryptographic algorithm?

No, attackers will find problems within it. Better use widely used and tested encryption

Of which entities is a security program (framework) made up of?

1. Logical (technical)
2. Administrative (controls)
3. Physical (controls)
4. Procedures
5. Business processes
6. People working together on protecting the environment

A framework has multiple layers which protect each other, how?

Each layer should provide support for the layer above it and protection for the layer below it.

How do you build a security program (framework)?

By using a structure laid out within a blueprint that is created by an architect. Industry standards are developed for this purpose.

What standards are being developed for the security industry?

1. Security Program Development
  • ISO/IEC 27000 series
2. Enterprise Architecture Development
  • Zachman Framework
  • TOGAF
  • DoDAF
  • MODAF
  • SABSA model
3. Security Controls Development
  • COBIT 5
  • NIST SP 800-53
  • COSO Internal Control - Integrated Framework
4. Process Management Development
  • ITIL
  • Six Sigma
  • Capability Maturity Model Integration (CMMI)

What is the ISO/IEC 27000 series about?

International standards on how to develop and maintain an ISMS developed by ISO and IEC

What is the Zachman Framework about?

Model for the development of enterprise architectures developed by The Open Group.

What is the TOGAF model about?

Model and methodology for the development of enterprise architecture developed by The Open Group

What is the DoDAF framework about?

U.S. Department of Defense architecture framework that ensures interoperability of systems to meet military mission goals

What is the MODAF Framework about?

Architecture framework used mainly in military support missions developed by the British Ministry of Defence.

What is the SABSA model about?

Model and methodology for the development of information security enterprise architectures.

What is the COBIT 5 Framework about?

A business framework to allow for IT enterprise management and governance that was developed by Information Systems Audit and Control Association (ISACA)

What is the COSO Internal Control - Integrated Framework about?

Set of internal corporate controls to help reduce the risk of financial fraud developed by the Committee of Sponsoring Organizations (COSO) of the Treadway Commission.

What is the Capability Maturity Model Integration (CMMI) about?

Organizational development for process improvement developed by Carnegie Mellon University.

The question on the page originate from the summary of the following study material:

  • A unique study and practice tool
  • Never study anything twice again
  • Get the grades you hope for
  • 100% sure, 100% understanding
Remember faster, study better. Scientifically proven.
Trustpilot Logo