Instiq

3Security management & evaluation

Practice questions →Glossary →
  • 3.1Risk management

    Covers information asset classification, the risk assessment procedure (risk identification, risk analysis, risk evaluation), the distinction between qualitative risk analysis and quantitative risk analysis, the selection criteria for risk treatment (transfer, avoidance, acceptance, reduction), residual risk and the risk matrix, and the approach defined in JIS Q 31000.

  • 3.2ISMS and controls

    Covers ISMS (Information Security Management System) as the organizational framework for information security management, the division of roles between JIS Q 27001, which defines requirements, and JIS Q 27002, which exemplifies controls, the three-tier structure of an information security policy—policy, standards, and procedures—the continuous-improvement PDCA cycle, and the Statement of Applicability produced for certification.

  • 3.3Incident response and organizations

    Covers the division of roles between CSIRT, which handles incidents within an organization, and SOC, which handles monitoring and detection; the flow of incident handling from detection to reporting (including triage); the roles of Japan's core organizations JPCERT/CC, NISC, and IPA; the bug bounty vulnerability-reward program; and inter-organization information-sharing frameworks such as J-CSIP.

  • 3.4Security technology evaluation

    Covers CVSS (Base, Temporal, and Environmental metrics) for quantifying vulnerability severity, the CVE vulnerability identifier, CWE for classifying vulnerability types, JVN, Japan's aggregator of vulnerability countermeasure information, ISO/IEC 15408 (Common Criteria) and EAL for evaluating security functionality, Japan's JISEC certification scheme, penetration testing, which actually attempts intrusion, and tamper resistance, hardware's resistance to analysis.

  • 3.5System audit and legal affairs

    Covers system audit (independence, audit procedures, audit trail) conducted from a position independent of the audited department, internal control, which ensures the soundness of business processes, and related laws such as the Act on Prohibition of Unauthorized Computer Access, the Act on the Protection of Personal Information, the Basic Act on Cybersecurity, and the Penal Code provisions on unauthorized creation of electromagnetic records (malware-related offenses).