WGU D320 QUESTIONS AND ANSWERS SURE A+
✔✔ISO 27701 - ✔✔Privacy extension to ISO 27001/27002. Establishes PIMS (Privacy
Information Management System). Closely linked to NIST CSF.
✔✔ISO/IEC 28000:2007 - ✔✔Security management systems for the supply chain.
✔✔ISO/IEC 31000:2018 - ✔✔International risk management principles and guidelines.
Industry-independent. Focuses on design, implementation, and management of risk
frameworks.
✔✔ISO/IEC 27037 - ✔✔Guide for collecting, identifying, and preserving electronic
evidence (digital forensics).
✔✔ISO/IEC 27042 - ✔✔Guide for digital evidence analysis (digital forensics).
✔✔ISO/IEC 27050 - ✔✔Overview and principles for eDiscovery.
✔✔NIST SP 800-37 - ✔✔Risk Management Framework (RMF) — 6-step lifecycle:
Categorize, Select, Implement, Assess, Authorize, Monitor.
✔✔NIST SP 800-53 - ✔✔Security and privacy controls for information systems. The
master control catalog used by FedRAMP and many compliance frameworks.
✔✔NIST SP 800-92 - ✔✔Guide to Computer Security Log Management. Covers log
generation, storage, analysis, and retention.
✔✔NIST SP 800-144 - ✔✔Guidelines on Security and Privacy in Public Cloud
Computing.
✔✔NIST SP 800-145 - ✔✔The NIST Definition of Cloud Computing. Defines 5 essential
characteristics, 3 service models, 4 deployment models.
, ✔✔SSAE 18 - ✔✔Statement on Standards for Attestation Engagements. Governs SOC
audits conducted within the United States.
✔✔ISAE 3402 - ✔✔International standard governing SOC audits conducted outside the
United States.
✔✔SOC 1 - ✔✔Report on controls relevant to financial reporting. Used as a component
of a financial audit. Restricted distribution.
✔✔SOC 2 - ✔✔Report on an organization's security controls based on Trust Services
Principles. Contains sensitive detail — NOT for public release. Restricted distribution.
✔✔SOC 3 - ✔✔Same scope as SOC 2 but summarized for public disclosure. Can be
posted on a website or shared freely.
✔✔SOC 2 — Five Trust Services Principles - ✔✔1. Security (mandatory), 2. Availability,
3. Processing Integrity, 4. Confidentiality, 5. Privacy. Security is the ONLY mandatory
principle.
✔✔MSA (Master Service Agreement) - ✔✔Overarching contract governing the entire
customer/provider relationship. Sets general terms: liability, payment, dispute resolution,
IP rights.
✔✔SLA (Service Level Agreement) - ✔✔Specific performance commitments — uptime,
response times, support tiers, and penalties/credits for missed commitments. Lives
under the MSA.
✔✔NDA (Nondisclosure Agreement) - ✔✔Legal contract where parties agree not to
disclose confidential information shared between them.
✔✔BPA (Business Partnership Agreement) - ✔✔Governs a formal business
partnership. Covers roles, responsibilities, profit sharing, decision-making, and exit
terms.
✔✔BAA (Business Associate Agreement) - ✔✔Required under HIPAA. Written
agreement with any third party handling PHI on behalf of a covered entity, requiring
HIPAA compliance.
✔✔Chain of Custody - ✔✔Documentation tracking evidence from acquisition to court —
who had access, where stored, what analysis performed. Provides nonrepudiation. Any
gap weakens evidence.
✔✔Nonrepudiation - ✔✔No party to a transaction can later deny they took part. Chain of
custody provides nonrepudiation for evidence.
✔✔ISO 27701 - ✔✔Privacy extension to ISO 27001/27002. Establishes PIMS (Privacy
Information Management System). Closely linked to NIST CSF.
✔✔ISO/IEC 28000:2007 - ✔✔Security management systems for the supply chain.
✔✔ISO/IEC 31000:2018 - ✔✔International risk management principles and guidelines.
Industry-independent. Focuses on design, implementation, and management of risk
frameworks.
✔✔ISO/IEC 27037 - ✔✔Guide for collecting, identifying, and preserving electronic
evidence (digital forensics).
✔✔ISO/IEC 27042 - ✔✔Guide for digital evidence analysis (digital forensics).
✔✔ISO/IEC 27050 - ✔✔Overview and principles for eDiscovery.
✔✔NIST SP 800-37 - ✔✔Risk Management Framework (RMF) — 6-step lifecycle:
Categorize, Select, Implement, Assess, Authorize, Monitor.
✔✔NIST SP 800-53 - ✔✔Security and privacy controls for information systems. The
master control catalog used by FedRAMP and many compliance frameworks.
✔✔NIST SP 800-92 - ✔✔Guide to Computer Security Log Management. Covers log
generation, storage, analysis, and retention.
✔✔NIST SP 800-144 - ✔✔Guidelines on Security and Privacy in Public Cloud
Computing.
✔✔NIST SP 800-145 - ✔✔The NIST Definition of Cloud Computing. Defines 5 essential
characteristics, 3 service models, 4 deployment models.
, ✔✔SSAE 18 - ✔✔Statement on Standards for Attestation Engagements. Governs SOC
audits conducted within the United States.
✔✔ISAE 3402 - ✔✔International standard governing SOC audits conducted outside the
United States.
✔✔SOC 1 - ✔✔Report on controls relevant to financial reporting. Used as a component
of a financial audit. Restricted distribution.
✔✔SOC 2 - ✔✔Report on an organization's security controls based on Trust Services
Principles. Contains sensitive detail — NOT for public release. Restricted distribution.
✔✔SOC 3 - ✔✔Same scope as SOC 2 but summarized for public disclosure. Can be
posted on a website or shared freely.
✔✔SOC 2 — Five Trust Services Principles - ✔✔1. Security (mandatory), 2. Availability,
3. Processing Integrity, 4. Confidentiality, 5. Privacy. Security is the ONLY mandatory
principle.
✔✔MSA (Master Service Agreement) - ✔✔Overarching contract governing the entire
customer/provider relationship. Sets general terms: liability, payment, dispute resolution,
IP rights.
✔✔SLA (Service Level Agreement) - ✔✔Specific performance commitments — uptime,
response times, support tiers, and penalties/credits for missed commitments. Lives
under the MSA.
✔✔NDA (Nondisclosure Agreement) - ✔✔Legal contract where parties agree not to
disclose confidential information shared between them.
✔✔BPA (Business Partnership Agreement) - ✔✔Governs a formal business
partnership. Covers roles, responsibilities, profit sharing, decision-making, and exit
terms.
✔✔BAA (Business Associate Agreement) - ✔✔Required under HIPAA. Written
agreement with any third party handling PHI on behalf of a covered entity, requiring
HIPAA compliance.
✔✔Chain of Custody - ✔✔Documentation tracking evidence from acquisition to court —
who had access, where stored, what analysis performed. Provides nonrepudiation. Any
gap weakens evidence.
✔✔Nonrepudiation - ✔✔No party to a transaction can later deny they took part. Chain of
custody provides nonrepudiation for evidence.