Transcription of Concepts (10) - Sunflower-CISSP.com
{{id}} {{{paragraph}}}
Concepts (10) CIA DAD - NEGATIVE - (disclosure alteration and destruction) Confidentiality - prevent unauthorized disclosure, need to know, and least privilege. assurance that information is not disclosed to unauthorized programs, users, processes, encryption, logical and physical access control, Integrity - no unauthorized modifications, consistent data, protecting data or a resource from being altered in an unauthorized fashion Availability - reliable and timely, accessible, fault tolerance and recovery procedures, WHEN NEEDED IAAA requirements for accountability Identification - user claims identity, used for user access control Authentication - testing of evidence of users identity Accountability - determine actions to an individual person Authorization - rights and permissions granted Privacy - level of confidentiality and privacy protections Risk (12) Not possible to get rid of all risk. Get risk to acceptable/tolerable level Baselines minimum standards ISO 27005 risk management framework Budget if not constrained go for the $$$ Responsibilities of the ISO (15) Written Products ensure they are done CIRT implement and operate Security Awareness provide leadership Communicate risk to higher management Report to as high a level as possible Security is everyone s responsibility Control Frameworks (17) Consistent approach & application Measurable way to determine
security plan, and identify sensitive systems on govt. agencies. 1991 US Federal Sentencing Guidelines - Responsibility on senior management with fines up to $290 million. Invoke prudent man rule. Address both individuals and organizations 1996 US Economic and Protection of Propriety Information Act - industrial and corporate espionage
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}