NSVT Test 1
Study online at https://quizlet.com/_i09a96
1. Enclave: Computer Environment connected by one or more _____
2. Network Environment: Network Backbone Responsible for connecting system devices
3. Computer Environment: LAN
4. Threat: Object, person, or entity that is a danger to an information system
5. Types of threats: Environmental
Human Threats
6. Vulnerabilities: Weakness that can be exploited against an IS
7. Risk: Likelihood that a vulnerability can be exploited
8. MAC 1: Systems that are deemed vital to mission effectiveness and operational readiness
9. MAC 2: Systems that are deemed important to the support of military forces
10. MAC 3: Systems that are deemed necessary to the day-to-day functions of a command
11. DISA severity codes CAT I: Cause total loss of system information; must be immediately corrected
12. DISA severity codes CAT II: Very likely to provide intruder access; must be corrected within 90 days
13. DISA severity codes CAT III: Potential to allow system to be compromised; must be corrected within
180 days
14. DISA severity codes CAT IV: Potential to degrade security; must be corrected within one year
15. Information Assurance Vulnerability Alerts (IAVA): High priority
16. Information Assurance Vulnerability Bulletins (IAVB): Medium priority
17. Information Assurance Vulnerability Tech Advisories (IAVT): Low priority
18. Vulnerability Remediation Asset Manager (VRAM): A web-enabled network vulnerability
data repository and continuous monitoring visual analysis tool
19. Contingency Planning: Statement of actions to be taken before, during, and after a disaster or emer-
gency
20. Backup Plan: Used to prevent catastrophic loss of data and progress
21. Risk Management: The discipline of identifying and measuring security risks associated with Information
System (IS), and controlling and reducing those risks to an acceptable level
22. Risk Management Framework: Prepare
Categorize
Select
Implement
Assess
1/7
, NSVT Test 1
Study online at https://quizlet.com/_i09a96
Authorize
Monitor
23. Risk Assessment (Phase I) Step 1: System Characterization
24. Risk Assessment (Phase I) Step 2: Threat Identification
25. Risk Assessment (Phase I) Step 3: Vulnerability Identification
26. Risk Assessment (Phase I) Step 4: Risk Analysis
27. Risk Assessment (Phase I) Step 5: Control Recommendations
28. Risk Assessment (Phase I) Step 6: Results Documentation
29. High Risk Software: Not authorized for use without approval
30. Public Domain Software: Only the NAO may approve the use
31. Clearing: process of removing information from the system for continued use
32. Sanitizing: process of removing information to prevent data loss
33. Destruction: process of physically damaging media
34. Declassification: administrative process to make media no longer classified
35. Periods processing: sanitization procedures must only be met during a given period; not approved for
NSA-accredited systems
36. Overwriting media (continued) Preferred method:: Overwrite all locations using a pseu-
do-random pattern twice
37. Recovery plans: Contains all requirements and procedures for disasters or emergency events
38. Emergency Action Plans (EAP):
39. EAP Level 1: Non-failure Emergency Condition
40. EAP Level 2: Potential Failure Situation is Developing
41. Level 3: Failure is Imminent or Has Occurred
42. Targeted Monitoring: Unauthorized targeted monitoring of a particular person, machine, or group is
PROHIBITED
43. Configuration Management Process Step 1: Identify Change
44. Configuration Management Process Step 2: Evaluate Change Request
45. Configuration Management Process Step 3: Implementation Decision
46. Configuration Management Process Step 4: Implement Approved Change Request
47. Configuration Management Process Step 5: Continuous Monitoring
48. Computer Fraud and Abuse Act: Unauthorized access or access in excess of authorization became
a felony on classified information
2/7
Study online at https://quizlet.com/_i09a96
1. Enclave: Computer Environment connected by one or more _____
2. Network Environment: Network Backbone Responsible for connecting system devices
3. Computer Environment: LAN
4. Threat: Object, person, or entity that is a danger to an information system
5. Types of threats: Environmental
Human Threats
6. Vulnerabilities: Weakness that can be exploited against an IS
7. Risk: Likelihood that a vulnerability can be exploited
8. MAC 1: Systems that are deemed vital to mission effectiveness and operational readiness
9. MAC 2: Systems that are deemed important to the support of military forces
10. MAC 3: Systems that are deemed necessary to the day-to-day functions of a command
11. DISA severity codes CAT I: Cause total loss of system information; must be immediately corrected
12. DISA severity codes CAT II: Very likely to provide intruder access; must be corrected within 90 days
13. DISA severity codes CAT III: Potential to allow system to be compromised; must be corrected within
180 days
14. DISA severity codes CAT IV: Potential to degrade security; must be corrected within one year
15. Information Assurance Vulnerability Alerts (IAVA): High priority
16. Information Assurance Vulnerability Bulletins (IAVB): Medium priority
17. Information Assurance Vulnerability Tech Advisories (IAVT): Low priority
18. Vulnerability Remediation Asset Manager (VRAM): A web-enabled network vulnerability
data repository and continuous monitoring visual analysis tool
19. Contingency Planning: Statement of actions to be taken before, during, and after a disaster or emer-
gency
20. Backup Plan: Used to prevent catastrophic loss of data and progress
21. Risk Management: The discipline of identifying and measuring security risks associated with Information
System (IS), and controlling and reducing those risks to an acceptable level
22. Risk Management Framework: Prepare
Categorize
Select
Implement
Assess
1/7
, NSVT Test 1
Study online at https://quizlet.com/_i09a96
Authorize
Monitor
23. Risk Assessment (Phase I) Step 1: System Characterization
24. Risk Assessment (Phase I) Step 2: Threat Identification
25. Risk Assessment (Phase I) Step 3: Vulnerability Identification
26. Risk Assessment (Phase I) Step 4: Risk Analysis
27. Risk Assessment (Phase I) Step 5: Control Recommendations
28. Risk Assessment (Phase I) Step 6: Results Documentation
29. High Risk Software: Not authorized for use without approval
30. Public Domain Software: Only the NAO may approve the use
31. Clearing: process of removing information from the system for continued use
32. Sanitizing: process of removing information to prevent data loss
33. Destruction: process of physically damaging media
34. Declassification: administrative process to make media no longer classified
35. Periods processing: sanitization procedures must only be met during a given period; not approved for
NSA-accredited systems
36. Overwriting media (continued) Preferred method:: Overwrite all locations using a pseu-
do-random pattern twice
37. Recovery plans: Contains all requirements and procedures for disasters or emergency events
38. Emergency Action Plans (EAP):
39. EAP Level 1: Non-failure Emergency Condition
40. EAP Level 2: Potential Failure Situation is Developing
41. Level 3: Failure is Imminent or Has Occurred
42. Targeted Monitoring: Unauthorized targeted monitoring of a particular person, machine, or group is
PROHIBITED
43. Configuration Management Process Step 1: Identify Change
44. Configuration Management Process Step 2: Evaluate Change Request
45. Configuration Management Process Step 3: Implementation Decision
46. Configuration Management Process Step 4: Implement Approved Change Request
47. Configuration Management Process Step 5: Continuous Monitoring
48. Computer Fraud and Abuse Act: Unauthorized access or access in excess of authorization became
a felony on classified information
2/7