MoIS4 CH06 Review Questions
1 What is an InfoSec framework?
2 What is an InfoSec blueprint?
An InfoSec blueprint is the detailed plan for the complete design, selection, and implementation
3 What is a security model?
A security model is a generic approach useful in planning information security offered by a
4 How might an InfoSec professional use a security model?
InfoSec professionals can use security models as an outline for a comprehensive design for an
5 What is access control?
Access control regulates the admission of users into trusted areas of the organizationboth
6 What are the essential processes of access control?
Access control includes four processes: obtaining the identity of the entity requesting access to a
7 What are the key principles on which access control is founded?
Access control is built on several key principles including least privilege, need-to-know, and
8 Identify at least two approaches used to categorize access control methodologies. List the
types of controls found in each.
One approach depicts controls by their inherent characteristics and classifies each control as one
of the following:
9 What is a mandatory access control?
A mandatory access control (MAC) is an implementation in which software elements are
10 What is a data classification model? How is data classification different from a clearance
level?
A data classification model (DAC) provides guidance as to the sensitivity level for information
11 Which international InfoSec standards have evolved from the BS 7799 model? What do
they include?
The ISO/IEC 27000 series has evolved from the BS 7799 model. Its security model has 10
12 What is an alternative model to the BS 7799 model (and its successors)? What does it
include?
The NIST collection of InfoSec management practices offers an alternative to BS 7799 and its
13 What are the documents in the ISO/IEC 27000 series?
14 What is COBIT? Who is its sponsor? What does it accomplish?
Control Objectives for Information and Related Technology (COBIT) is an IT governance
15 What are the two primary advantages of NIST security models?
They are publicly available at no charge, and they have been available for some time and are thus
16 What is the common name for NIST SP 80012? What is the document’s purpose? What
resources does it provide?
17 What is the common name for NIST SP 80014? What is the document’s purpose? What
resources does it provide?
The common name for NIST SP80014 is “Generally Accepted Principles and Practices for
18 What are the common names for NIST SP 800-53 and NIST SP 800-53A? What is the
purpose of each document? What resources do they provide?
NIST SP 800-53A, Rev. 1 is commonly called “Building Effective Security Assessment Plans.”
19 What is the common name of NIST SP 80030? What is the document’s purpose? What
resources does it provide?
The common name of NIST SP 800-30 is “Risk Management Guide for Information Technology
20 What is COSO, and why is it important?
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) is a U.S.