2.3 : Protecting Stored Information and Backup Flashcards

1
Q

In what form does Information systems stored information

A

Primarily in the form of databases and flat files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How Stored information are protected

A
  • Access Controls

* Access logging

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

protection of backup media

A

Always encrypt backup media so data it contained can not be easily retrieved by third party if the media is lost

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Where to store backup Media

A

For disaster protection, backup media should be stored at a location away from the original data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security of the off-site storage facility

A

Should be as good as the security in the original location, so that protected information is not more vulnerable at the off-site facility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Why should the organization occasionally test backup media and data restoration software?

A

To make sure that data is actually being backed up onto the backup media and that it an be retrieved.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Inventory of backup Media

A

A periodic inventory of all backup media, including media at the off-site location should be performed. The result of each inventory should be recorded and any anomalies corrected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Loss of one or more media backup during an inventory

A
  • If lost media is encrypted, document it.

* If the lost media is not encrypted, it should be considered as a security incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a patch Management

A

IT operational process whereby security and functionality patches are OBTAINED, TESTED, and INSTALLED on information systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the purpose of a patch Management

A

To keep systems running on currently supported vendor software and to ensure that all known security vulnerabilities are closed and software defects fixed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What need to take place after an organization chooses to install only the most important patches and not all patches

A

A security analyst will need to perform a risk analysis each time a security patch is released so that a formal determination of need can be established.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is recommended of patches before installing them

A

Organization should first test patches on test environments prior to installing them on production systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly