qisp
Study online at https://quizlet.com/_i0nhxr
1. What are the AiSP's code of conduct values?: ans: honesty, fairness, integrity and diligence
2. Name 3 professional responsibilities: ans: eg. act within the law, report to appropriate authorities
and violations, act in the best interest of the employer
3. list 2 ethics in Information Security: ans: eg. to honour the confidentiality and not use computer
system or data for personal gain/unlawful purposes, to honour intellectual property rights
4. What motivates hackers to commit cyber-crimes?: ans: cash, challenge, hacktivism, re-
venge, subversion, infamy
5. What are the objectives of information securities?: ans: confidentiality, integrity, availability,
accountability, non-repudiation
6. how do you address the human element in risk monitoring?: ans: include a training
and awareness programme, communicate IS policies, standards and procedures
7. how can risk be treated?: ans: risk mitigation, risk avoidance, risk transference, risk acceptance
8. what are the 4 typical levels of confidentiality used by organisations?: ans:
confidential, restricted, internal, public information
9. name some possible issues of information classification: multiple classifications, interna
resistance, over-classfication, coverage, confidentiality, integrity, availabilty, accountability, non-repudation
10. cyber hygiene best practices?: ans: includes installing antivirus and malware software, using fire-
walls, restrict privileged access to unauthorized personnel, updating apps/web browsers/operating systems regularly,
keeping hard drives clean, changing passwords, review server and application port settings, conduct security awareness
training
11. why is the layered defence model effective?: the layers delay the intruders from gaining
access, as each layer is to waste the intruder's time from reaching his objective.
12. what are the objectives of a Business Impact Analysis?: ans: assist management in
understanding the impact associated with possible disruptions, identify and prioritise critical business processes/ap-
plications/systems, analyse the impact, determine recovery objectives
13. explain KMIP: ans: KMIP allows specific key management environments to communicate with other key
management systems outside the environments
14. What needs to be performed in a risk assessment?: ans: impact analysis, risk determina-
tion, controls recommendation
15. What is the basis of a zero-trust network?: ans: by default, nobody in the network is trusted
whether it be from inside or outside the network. verification is required from everyone gaining access, and access to
more secure resources may require stronger authentication.
1/3
Study online at https://quizlet.com/_i0nhxr
1. What are the AiSP's code of conduct values?: ans: honesty, fairness, integrity and diligence
2. Name 3 professional responsibilities: ans: eg. act within the law, report to appropriate authorities
and violations, act in the best interest of the employer
3. list 2 ethics in Information Security: ans: eg. to honour the confidentiality and not use computer
system or data for personal gain/unlawful purposes, to honour intellectual property rights
4. What motivates hackers to commit cyber-crimes?: ans: cash, challenge, hacktivism, re-
venge, subversion, infamy
5. What are the objectives of information securities?: ans: confidentiality, integrity, availability,
accountability, non-repudiation
6. how do you address the human element in risk monitoring?: ans: include a training
and awareness programme, communicate IS policies, standards and procedures
7. how can risk be treated?: ans: risk mitigation, risk avoidance, risk transference, risk acceptance
8. what are the 4 typical levels of confidentiality used by organisations?: ans:
confidential, restricted, internal, public information
9. name some possible issues of information classification: multiple classifications, interna
resistance, over-classfication, coverage, confidentiality, integrity, availabilty, accountability, non-repudation
10. cyber hygiene best practices?: ans: includes installing antivirus and malware software, using fire-
walls, restrict privileged access to unauthorized personnel, updating apps/web browsers/operating systems regularly,
keeping hard drives clean, changing passwords, review server and application port settings, conduct security awareness
training
11. why is the layered defence model effective?: the layers delay the intruders from gaining
access, as each layer is to waste the intruder's time from reaching his objective.
12. what are the objectives of a Business Impact Analysis?: ans: assist management in
understanding the impact associated with possible disruptions, identify and prioritise critical business processes/ap-
plications/systems, analyse the impact, determine recovery objectives
13. explain KMIP: ans: KMIP allows specific key management environments to communicate with other key
management systems outside the environments
14. What needs to be performed in a risk assessment?: ans: impact analysis, risk determina-
tion, controls recommendation
15. What is the basis of a zero-trust network?: ans: by default, nobody in the network is trusted
whether it be from inside or outside the network. verification is required from everyone gaining access, and access to
more secure resources may require stronger authentication.
1/3