FlashKeepers

IT Security · CompTIA Security+

Security+ Domain: Governance, Risk, and Compliance

Security governance, risk management, and compliance concepts from the Security+ exam objectives.

40 cards · basic cards · AI-written, checked twice. Edit anything.

Study this set free Look inside first Get FlashKeepers for iPhone
What is the primary purpose of a risk assessment in security governance?
To identify, analyze, and evaluate security threats and vulnerabilities that could impact the organization.
Define risk mitigation.
The process of taking steps to reduce the severity or likelihood of a security risk.
What is risk acceptance?
A risk response strategy where an organization acknowledges a risk and chooses to tolerate it without taking corrective action.
What does HIPAA regulate?
Protected Health Information (PHI) in the healthcare industry; requires safeguards for patient data confidentiality, integrity, and availability.
What is PCI DSS primarily designed to protect?
Payment card data and credit cardholder information during storage, processing, and transmission.
What does GDPR stand for?
General Data Protection Regulation; EU regulation protecting personal data privacy and individual rights.
What is Sarbanes-Oxley (SOX) primarily concerned with?
Financial reporting accuracy and internal control procedures in publicly traded companies.
What does a security policy define?
Rules, procedures, and guidelines that govern security behavior and practices within an organization.
What is the purpose of a Business Continuity Plan (BCP)?
To establish procedures and resources that enable an organization to maintain critical functions during and after a disruptive event.
Define Recovery Time Objective (RTO).
The maximum acceptable amount of time that systems or services can be down before resuming normal operations.
Define Recovery Point Objective (RPO).
The maximum acceptable amount of data loss measured from the point of a system failure to the most recent backup.
What is a Disaster Recovery Plan (DRP)?
A documented set of procedures to recover IT systems and services after a major failure or disaster.
What is the goal of incident response?
To detect, respond to, and recover from security incidents in a structured manner to minimize impact and damage.
Name the four main phases of the incident response process.
Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activities.
What is a security audit?
An independent examination of an organization's security controls, policies, and practices to assess compliance and effectiveness.

25 more cards in the app