Transcription of Concepts (10) - Sunflower CISSP
{{id}} {{{paragraph}}}
Concepts (10) CIA DAD - NEGATIVE - (disclosure alteration and destruction) Confidentiality - prevent unauthorized disclosure, need to know, and least privilege. assurance that information is not disclosed to unauthorized programs, users, processes, encryption, logical and physical access control, Integrity - no unauthorized modifications, consistent data, protecting data or a resource from being altered in an unauthorized fashion Availability - reliable and timely, accessible, fault tolerance and recovery procedures, WHEN NEEDED IAAA requirements for accountability Identification - user claims identity, used for user access control Authentication - testing of evidence of users identity Accountability - determine actions to an individual person Authorization - rights and permissions granted Privacy - level of confidentiality and privacy protections Risk (12) Not possible to get rid of all risk. Get risk to acceptable/tolerable level Baselines minimum standards ISO 27005 risk management framework Budget if not constrained go for the $$$ Responsibilities of the ISO (15) Written Products ensure they are done CIRT implement and operate Security Awareness provide leadership Communicate risk to higher management Report to as high a level as possible Security is everyone s responsibility Control Frameworks (17) Consistent approach & applic
Incident – an event that has potential to do harm Breach – incident that results in disclosure or potential disclosure of data Data Disclosure –unauthorized acquisition of personal information Event –Threat events are accidental and intentional exploitations of vulnerabilities. Laws (28) ITAR, 1976. Defense goods, arms export control act
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}