INMT 540 Exam1 Questions and Correct
Answers
Standard Vs Framework - Answer-Essentially a Standard is far more focused and specific focusing on a
method of how to do something whereas a Framework is a more general set of guidelines.
Framework - Answer-1) Provides guidelines on how to do something, often includes examples of best
practices•Are not mandated - you do not have to follow it
2) Useful in the absence of well defined or standard practices
3)An organization can evolve its methodology using a framework because frameworks are flexible and
allow for experimentation
4) Defines a system, not the method itself
Standard - Answer-1) Defined very well (one way of doing things) and to comply, you have to follow a
specific method
2) ISO has created and maintains a large number of standards. - Conformity to ISO means following
standard practices that are accepted in all parts of the world.
3) Generally accepted all over as the best method of doing something
COSO - Answer-1) it is a Framework
,2) is dedicated to providing thought leadership through the development of frameworks and guidance
on enterprise risk management, internal control and fraud deterrence.
3) joint commission made up of
a. American Accounting Association (AAA)
b. American Institute of CPA's (AICPA)
c. Financial Executives International (FEI)
d. IMA
e. Institute of Internal Auditors (IIA)
COBIT- (Control Objectives for Information and Related Technologies) - Answer-1) Framework
2) COBIT is a framework for the governance and management of enterprise information and technology,
aimed at the whole enterprise. COBIT defines the components and design factors to build and sustain a
best-fit governance system.
3) Affiliated with ISACA
ITIL (Information Technology Infrastructure Library) - Answer-1) Framework
2) ITIL is a widely accepted approach to IT service management (ITSM), which has been adopted by
individuals and organizations across the world. It provides a cohesive set of best practice, drawn from
the public and private sectors internationally.
ISO (International Organization for Standardization) - Answer-1) ISO/IEC 27001 is the best-known
standard in the family providing requirements for an information security management system (ISMS).
2) An organization/framework that has created and manages several standards
PCI Security Standards Council - Answer-1) Standard
2) (Think Credit Cards) The PCI Security Standards Council is a global forum for the ongoing
development, enhancement, storage, dissemination and implementation of security standards for
account data protection.
, HIPAA (Health Insurance Portability and Accountability Act) - Answer-A standard that protects medical
information.
GLBA (Gramm-Leach-Bliley Act) - Answer-1) Standard
2) The Gramm-Leach-Bliley Act requires financial institutions - companies that offer consumers financial
products or services like loans, financial or investment advice, or insurance - to explain their
information-sharing practices to their customers and to safeguard sensitive data.
Sarbanes-Oxley Act of 2002 (SOX) - Answer-1) Standard
2) Essentially put the SEC in charge of monitoring businesses and enforcing laws that prevent fraud.
3) Dr. Hollander mentioned J-SOX in class referring to the fact that Japan created their own version of
SOX
GDPR (General Data Protection Regulation) - Answer-Standard involving Data Protection in the EU
NIST (National Institute of Standards and Technology) - Answer-1) Neither a Framework or a Standard
more of an organization
2) Advancing the state-of-the-art in IT in such applications as cyber security and biometrics, NIST
accelerates the development and deployment of systems that are reliable, usable, interoperable, and
secure; advances measurement science through innovations in mathematics, statistics, and computer
science; and conducts research to develop the measurements and standards infrastructure for emerging
information technologies and applications.
SANS - Answer-(Listed under other on powerpoint) The most trusted source for information security
training, certification, and research.
Governance System (seven components) - Answer-1. Processes
2. Organizational Structure
Answers
Standard Vs Framework - Answer-Essentially a Standard is far more focused and specific focusing on a
method of how to do something whereas a Framework is a more general set of guidelines.
Framework - Answer-1) Provides guidelines on how to do something, often includes examples of best
practices•Are not mandated - you do not have to follow it
2) Useful in the absence of well defined or standard practices
3)An organization can evolve its methodology using a framework because frameworks are flexible and
allow for experimentation
4) Defines a system, not the method itself
Standard - Answer-1) Defined very well (one way of doing things) and to comply, you have to follow a
specific method
2) ISO has created and maintains a large number of standards. - Conformity to ISO means following
standard practices that are accepted in all parts of the world.
3) Generally accepted all over as the best method of doing something
COSO - Answer-1) it is a Framework
,2) is dedicated to providing thought leadership through the development of frameworks and guidance
on enterprise risk management, internal control and fraud deterrence.
3) joint commission made up of
a. American Accounting Association (AAA)
b. American Institute of CPA's (AICPA)
c. Financial Executives International (FEI)
d. IMA
e. Institute of Internal Auditors (IIA)
COBIT- (Control Objectives for Information and Related Technologies) - Answer-1) Framework
2) COBIT is a framework for the governance and management of enterprise information and technology,
aimed at the whole enterprise. COBIT defines the components and design factors to build and sustain a
best-fit governance system.
3) Affiliated with ISACA
ITIL (Information Technology Infrastructure Library) - Answer-1) Framework
2) ITIL is a widely accepted approach to IT service management (ITSM), which has been adopted by
individuals and organizations across the world. It provides a cohesive set of best practice, drawn from
the public and private sectors internationally.
ISO (International Organization for Standardization) - Answer-1) ISO/IEC 27001 is the best-known
standard in the family providing requirements for an information security management system (ISMS).
2) An organization/framework that has created and manages several standards
PCI Security Standards Council - Answer-1) Standard
2) (Think Credit Cards) The PCI Security Standards Council is a global forum for the ongoing
development, enhancement, storage, dissemination and implementation of security standards for
account data protection.
, HIPAA (Health Insurance Portability and Accountability Act) - Answer-A standard that protects medical
information.
GLBA (Gramm-Leach-Bliley Act) - Answer-1) Standard
2) The Gramm-Leach-Bliley Act requires financial institutions - companies that offer consumers financial
products or services like loans, financial or investment advice, or insurance - to explain their
information-sharing practices to their customers and to safeguard sensitive data.
Sarbanes-Oxley Act of 2002 (SOX) - Answer-1) Standard
2) Essentially put the SEC in charge of monitoring businesses and enforcing laws that prevent fraud.
3) Dr. Hollander mentioned J-SOX in class referring to the fact that Japan created their own version of
SOX
GDPR (General Data Protection Regulation) - Answer-Standard involving Data Protection in the EU
NIST (National Institute of Standards and Technology) - Answer-1) Neither a Framework or a Standard
more of an organization
2) Advancing the state-of-the-art in IT in such applications as cyber security and biometrics, NIST
accelerates the development and deployment of systems that are reliable, usable, interoperable, and
secure; advances measurement science through innovations in mathematics, statistics, and computer
science; and conducts research to develop the measurements and standards infrastructure for emerging
information technologies and applications.
SANS - Answer-(Listed under other on powerpoint) The most trusted source for information security
training, certification, and research.
Governance System (seven components) - Answer-1. Processes
2. Organizational Structure