2.0 Compliance and Operational Security Flashcards
What is Access Control?
Access control is the ability to permit or deny the privileges that users have when accessing resources on a network or computer.
What processes are included in access control?
What processes that are included in access control are Identification, Authentication, Authorization, and Auditing.
What is MAC?
Mandatory Access Control (MAC) uses labels or attributes for both users and objects.
What is DAC?
Discretionary Access Control (DAC) assigns access directly to users based on the discretion of the owner.
What is RBAC?
Role Based Access Control (RBAC) allows access based on a role in an organization, not individual users.
What is the principle of least privilege?
The principle of least privilege states that users or groups are given only the access they need to do their job and nothing more.
What is need to know?
Need to know describes the restriction of data that is highly sensitive.
What is separation of duties?
Separation of duties is the concept of having more than one person required to complete a task.
What is job rotation?
Job rotation is a technique where users are cross-trained in multiple job positions, and where responsibilities are regularly rotated between personnel.
What is defense-in-depth?
Defense-in-depth is an access control method which implements multiple access control methods instead of relaying on a single method?
What is creeping privileges?
Creeping privileges occurs when a user’s job position changes and their previous access privileges are not removed or modified.
What is a regulation?
A regulation is a requirement published by a government or other licensing body that must be followed.
What is a procedure?
A procedure is a step-by-step process outlining how to implement a specific action.
What is a baseline?
A baseline dictates the settings and security mechanisms that must be imposed on a system in order to comply with required security standards.
What is a guideline?
A guideline is a recommendation to use when a specific standard or procedure does not exist.