Tyscorpa Study resources Open the Academy

Acronyms - Security Program Management

Governance, the quantitative risk formula, the agreement types and the regulations - including which document covers which situation, which is what the exam actually asks.

SY0-701 Obj. 5.1 - 5.6 Security Program Management 20% of the exam

The risk metrics in the second table are only useful together, so each entry says where it sits in the calculation rather than defining it alone. The agreement types in the third are tested by scenario - which document covers this situation - rather than by expansion.

Governance and continuity

AcronymExpands toWhat it isWorth knowing
GRCGovernance, Risk and ComplianceThe three functions run as oneThey overlap because the same evidence serves all three. Run separately, an organisation collects it three times and gives three answers about one control.
BIABusiness Impact AnalysisWhat the consequence is of a process stoppingThe recovery objectives come out of it. An organisation that starts from what its backups can achieve has documented a capability rather than set a requirement.
BCPBusiness Continuity PlanHow the organisation keeps functioning during disruptionIncludes manual workarounds, premises and communications. Recovering every system correctly while nobody knows what to do for six hours is still a failure.
DRPDisaster Recovery PlanHow the technology is restoredThe subset of continuity that restores systems. Recovery order comes from dependencies, not from how important a system feels.
COOPContinuity of Operations PlanThe continuity plan under its government name
CISOChief Information Security OfficerThe executive accountable for the security programmeAccountability does not transfer. A function can be outsourced and the answer for it cannot.
ISMSInformation Security Management SystemThe documented system of policy, roles, risk process and reviewWhat ISO 27001 certifies. The certificate is for the system, not for any particular control being present.
ITILInformation Technology Infrastructure LibraryThe service management framework change management comes fromWhere the change advisory board, the request for change and the maintenance window originate.
COBITControl Objectives for Information and Related TechnologiesA governance framework aimed at the board rather than the engineerAnswers whether IT serves the business, where NIST CSF and ISO 27001 answer whether it is secure.
CBTComputer-Based TrainingSelf-paced training modulesCovers the syllabus and evidences completion. It changes behaviour far less than simulated phishing and role-based practice, which is the point most awareness questions turn on.

Risk metrics

AcronymExpands toWhat it isWhere it sits
AVAsset ValueWhat the thing is worthFirst term of the chain.
EFExposure FactorThe proportion destroyed by one eventAV x EF = SLE.
SLESingle Loss ExpectancyWhat one occurrence costsSLE x ARO = ALE.
AROAnnual Rate of OccurrenceHow many times a year it is expectedOften less than one, which is normal. It is the weakest input in the calculation and frequently a guess.
ALEAnnualised Loss ExpectancyThe expected annual cost of the risk left untreatedWhat the cost of a control is compared against. A precise-looking figure can rest on three estimates.
RTORecovery Time ObjectiveHow long the service may be downLooks forward from the failure. Met by standby capacity and restore speed.
RPORecovery Point ObjectiveHow much data may be lost, expressed as timeLooks backward from the failure. Met by copy frequency. A design can satisfy one of these and fail the other completely.
MTDMaximum Tolerable DowntimeThe point past which the damage cannot be recovered fromRTO is set below it deliberately, leaving margin.
MTTRMean Time To RepairHow long the fixing takes on averageFeeds the RTO the organisation can honestly commit to.
MTBFMean Time Between FailuresHow often a repairable system failsBetween implies repair. A non-repairable item gets mean time to failure instead, which is what drive figures actually are.
KRIKey Risk IndicatorSomething measurable that moves before the risk doesWhat turns a register from a record into something that reacts between reviews.
ROIReturn on InvestmentWhat the spending returnsApplied to a control it becomes ROSI, where the return is a loss that did not happen.
ROSIReturn on Security InvestmentThe reduction in ALE set against the cost of the controlA control costing more than the ALE it removes is not a security decision, it is a bad one - which is why the calculation is done before the purchase.

Agreements and third parties

AcronymExpands toWhat it isWorth knowing
SLAService Level AgreementCommitted performance, and the credits owed when it is missedCommits the provider to a number. It does not commit them to a security posture unless that is written in as well.
MOUMemorandum of UnderstandingA statement of intentNot legally binding, which is the whole point of the distinction.
MOAMemorandum of AgreementA more formal commitment than an MOU
MSAMaster Service AgreementThe umbrella terms for an ongoing relationshipIndividual pieces of work are ordered under it by a statement of work, so the terms are negotiated once.
SOWStatement of WorkWhat will be delivered, when, and for how much
NDANon-Disclosure AgreementAn obligation not to reveal confidential information
BPABusiness Partners AgreementHow partners divide revenue, liability and responsibility
ISAInterconnection Security AgreementGoverns a direct technical connection between two organisationsThe clause most often left out is how the connection is terminated when the relationship ends.
CAIQConsensus Assessments Initiative QuestionnaireThe standard cloud vendor security questionnaireA self-assessment, so it is the weakest evidence in the hierarchy - useful as a filter rather than as assurance.
CCMCloud Controls MatrixThe control framework the CAIQ maps to
CSACloud Security AllianceThe body that publishes the CCM and the CAIQ
QSAQualified Security AssessorThe assessor PCI DSS requires at higher merchant levels
SAQSelf-Assessment QuestionnaireHow a smaller merchant validates PCI DSS complianceThe requirements are identical whichever route is used. Only the evidence differs.
CDECardholder Data EnvironmentEverything that stores, processes or transmits card dataScope is the whole game. Segmentation that genuinely isolates the CDE takes the rest of the network out of the audit.
PTESPenetration Testing Execution StandardA methodology for how an engagement is run and reportedWhat makes a test repeatable rather than dependent on the individual tester. OSSTMM and the OWASP Testing Guide serve the same purpose.

Standards, regulations and privacy

AcronymExpands toWhat it isWorth knowing
SOC 2System and Organization Controls 2An audit report on a service provider's controlsNothing to do with a security operations centre. Type I is a point in time; Type II covers a period, which is why customers ask for Type II.
ISO 27001International Organization for Standardization 27001The certifiable information security management standardCertification requires a management system and a justified selection of controls, not every control applied.
CSFCybersecurity FrameworkThe NIST framework organising security activity into functionsGovern, Identify, Protect, Detect, Respond, Recover. Voluntary, and adopted far outside the US federal sector.
PCI DSSPayment Card Industry Data Security StandardRequirements for handling payment card dataApplies at any volume. Transaction count decides how compliance is validated, not whether it applies. Contractual rather than statutory, published by the PCI Security Standards Council (SSC) rather than by a legislature.
GDPRGeneral Data Protection RegulationThe EU data protection regulation72 hours to notify the supervisory authority of a qualifying breach, counted from becoming aware of it.
HIPAAHealth Insurance Portability and Accountability ActUS protection of health information
SOXSarbanes-Oxley ActUS financial reporting controlsWhy change management and separation of duties are audited in systems that never touch money directly.
GLBAGramm-Leach-Bliley ActUS financial institution customer data protection
DPIAData Protection Impact AssessmentRequired before high-risk processing beginsAssesses harm to the data subject, not cost to the organisation, which is the opposite direction from an ordinary risk assessment. Done beforehand, or it documents a decision already taken.
DPOData Protection OfficerThe role accountable for privacy compliance
PIIPersonally Identifiable InformationData that identifies a person on its own or combinedCombined is the hard part. Fields that identify nobody alone identify one person together, which is why removing the name is not anonymisation.
PHIProtected Health InformationHealth data tied to an identifiable person, under HIPAA
SSNSocial Security NumberThe US national identifierA permanent identifier that cannot be reissued, which is why its exposure is treated more seriously than a card number that can be replaced.
CCPACalifornia Consumer Privacy ActState privacy law with GDPR-like rightsApplies by where the consumer is, not by where the company is - which is how a business with no California presence ends up in scope.
HITECHHealth Information Technology for Economic and Clinical Health ActAdded breach notification and stronger penalties to HIPAA
DPAData Processing AgreementThe contract binding a processor to the controller's instructionsThe controller stays accountable for the processor's handling, so this is where that responsibility is written down.
PIAPrivacy Impact AssessmentThe broader assessment a DPIA is the high-risk form of
RTBFRight To Be ForgottenThe data subject's right to erasureRuns straight into backups and immutable storage, which is why the answer is usually a documented retention period rather than a deletion on demand.
PIMSPrivacy Information Management SystemISO 27701, the privacy extension to an ISMS
FISMAFederal Information Security Modernization ActSecurity requirements for US federal systemsWhere NIST SP 800-53 becomes mandatory rather than advisory.

The bodies and the documents they publish

AcronymExpands toWhat it isWorth knowing
NISTNational Institute of Standards and TechnologyThe US body behind the CSF, the SP 800 series and FIPSPublishes guidance, not law. It becomes binding through FISMA for federal systems and through contracts for everybody else.
SPSpecial PublicationThe NIST document series security guidance lives inSP 800-53 is the federal control catalogue, 800-171 covers controlled information at contractors, 800-61 is incident handling and 800-37 is the risk management framework.
ISOInternational Organization for StandardizationThe international standards body27001 certifies the management system, 27002 is the guidance on controls, 27701 covers privacy and 22301 covers business continuity.
RFCRequest for CommentsThe document series internet protocols are defined inDespite the name these are the specifications themselves, not proposals.
DISADefense Information Systems AgencyThe US defence body that publishes the STIGs
CISACybersecurity and Infrastructure Security AgencyThe US agency that publishes the KEV catalogue and advisoriesCollides with the CISA certification, which is Certified Information Systems Auditor. Unrelated.
PreviousThird-Party Risk & Vendor Management

Test yourself on this

Reading is the easy half. The Academy has 1,360 exam-style questions, including performance-based ones, and it keeps pulling from whichever domain you keep getting wrong. Free to create an account.

Open the Academy