Doubts
Doubts
1. Framework - A framework is a particular set of rules, policies or processes which you use in order
to deal with risks or to decide what to do.
2. Information Security Parameters – CIA – Confidentiality, Integrity & Availability – These three are
the pillars of information security. And in order to identify or manage the information security
risk, we will be seeing whether that risk is having any impact on any of these three.
3. Confidentiality – Information should be accessible to only authorized people.
4. Integrity – Confidential information should not be altered or changed by unauthorized personnel.
5. Availability – Information should be available to all the authorized people at all times.
6. Governance is the process of making and enforcing decisions within an organization or society. It
includes rule-setting, decision-making, and enforcement mechanisms (policies and processes)
that guide the functioning of an organization or society.
7. RMF – Risk Management Framework –
a. The RMF Process comprises seven sequential steps. This includes the Prepare Step,
Categorize Step, Select Step, Implement Step, Assess Step, Authorize Step, and Monitor
Step.
8. Types of Risks & Risk Handling parameters – Accept, Transfer, Mitigate, Avoid
9.