E025 Terms Questions with Verified Correct
Answers
cloud security
the policies, technologies, and controls implemented to protect data, applications, and
infrastructure in cloud computing environments
Cloud Security Alliance Security, Trust & Assurance Registry (CSA STAR)
Provides a publicly accessible registry of cloud providers' security certifications and
practices, aiming to enhance transparency and trust in cloud computing.
Identity and Access Management (IAM)
Frameworks for managing digital identities and controlling access to resources.
Federal Information Security Modernization Act (FISMA)
US Law that requires federal agencies and contractors to secure information systems and
establish minimum security requirements for protecting data.
Asymmetric Key Pairs (public/Private Keys)
Data encryption consists of a publicly shared key that encrypts data and a corresponding
private key that only the intended recipient possesses to decrypt that data.
California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA)
CCPA is a state law that gives consumers rights over personal information, including the
right to know, delete, and opt out of data sales. CPRA amended the CCPA with new
protections and established the California Privacy Protection Agency to enforce compliance.
ENISA (European Union Agency for Cybersecurity)
, supports the development of cybersecurity policies, enhances cooperation across EU member
states, and provides expertise in cybersecurity issues.
ISO/IEC 27002
Provides detailed guidance on implementing specific information security controls.
Complementary standard to ISO 27001
Key Management Service (KMS)
A managed service that provides a centralized and secure platform for the lifecycle of
encryption keys used to protect data across various cloud services and applications.
NIST SP 800-53
US Government standard that offers a catalog of security and privacy controls for federal
information systems and high-risk organizations.
ISO/IEC 27018
International Standard focuses on protecting personal data in the cloud. Part of the ISO/IEC
27000 series on Info security management
SOC 2
An auditing standard developed by AICPA that assesses how well a service organization
safeguards data based on trust service principles.
Hardware Security Module
A dedicated cryptographic processor that provides protection for cryptographic keys.
API Calls
Answers
cloud security
the policies, technologies, and controls implemented to protect data, applications, and
infrastructure in cloud computing environments
Cloud Security Alliance Security, Trust & Assurance Registry (CSA STAR)
Provides a publicly accessible registry of cloud providers' security certifications and
practices, aiming to enhance transparency and trust in cloud computing.
Identity and Access Management (IAM)
Frameworks for managing digital identities and controlling access to resources.
Federal Information Security Modernization Act (FISMA)
US Law that requires federal agencies and contractors to secure information systems and
establish minimum security requirements for protecting data.
Asymmetric Key Pairs (public/Private Keys)
Data encryption consists of a publicly shared key that encrypts data and a corresponding
private key that only the intended recipient possesses to decrypt that data.
California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA)
CCPA is a state law that gives consumers rights over personal information, including the
right to know, delete, and opt out of data sales. CPRA amended the CCPA with new
protections and established the California Privacy Protection Agency to enforce compliance.
ENISA (European Union Agency for Cybersecurity)
, supports the development of cybersecurity policies, enhances cooperation across EU member
states, and provides expertise in cybersecurity issues.
ISO/IEC 27002
Provides detailed guidance on implementing specific information security controls.
Complementary standard to ISO 27001
Key Management Service (KMS)
A managed service that provides a centralized and secure platform for the lifecycle of
encryption keys used to protect data across various cloud services and applications.
NIST SP 800-53
US Government standard that offers a catalog of security and privacy controls for federal
information systems and high-risk organizations.
ISO/IEC 27018
International Standard focuses on protecting personal data in the cloud. Part of the ISO/IEC
27000 series on Info security management
SOC 2
An auditing standard developed by AICPA that assesses how well a service organization
safeguards data based on trust service principles.
Hardware Security Module
A dedicated cryptographic processor that provides protection for cryptographic keys.
API Calls