Private key only known by you; public key is known to the
world
If you encrypt with one key you can only decrypt with the other
key (i.e. if you encrypt with private then you need to decrypt
with public and vice versa)
Can you do all 4 components of encryption? Correct Answer
Digital envelope and digital signature in same communication
CMMI Correct Answer Maturity of process (not effectiveness)
,DNS (Domain Name Server) Correct Answer Internet is two
networks (servers and domain name servers): Servers (home
addresses) vs DNS (post office)
Does Symmetric Key cryptography support non-repudiation?
Correct Answer No
Due Care Correct Answer Fiduciary responsibility,
governance, policy, oversight
Due Diligence Correct Answer Not related to governance
Examples of continuous monitoring? Correct Answer Audit
Hook & IPS
Front office Correct Answer Trader
How do you accommodate local regulation for a global
company? Correct Answer Modify policy to suit local
regulatory requirements
How do you apply Governance? Correct Answer Oversight
committees
How do you classify assets? Correct Answer Using an
Information/Data Classification Policy
How many symmetric key pairs are required for 6 people?
Correct Answer 15
, (N x (N-1)) / 2
Hybrid Cryptography Correct Answer Use Symmetric key
(fast) to encrypt a msg and then you use Asymmetric key to
encrypt Symmetric key and include it with the msg
If you don't have a hash then you don't have.... Correct Answer
Integrity
IPSEC Correct Answer When you log in remotely you need to
go through the Internet to reach the Intranet safe and sound. You
can make this public Internet a virtual private network through
encryption (i.e. VPN). You can either encrypt header (AH) or
payload (ESP). Which is more secure? Tunnel
Is IT Risk part of Op Risk? Correct Answer Yes
Middle office Correct Answer Risk Management
Primary risk management is conducted by who? Correct
Answer Risk management board
Quantitative RA formula? Correct Answer Annual Loss
Expectancy ($) = Single Loss Expectancy ($) X Annual Risk
Occurrence
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Classroom. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $11.49. You're not tied to anything after your purchase.