8 Security Domains Flashcards
Security and Risk Management
Focuses on:
1. Defining security goals and obj
2. Risk mitigation
3. Compliance
4. Business Continuity
5. Legal regulations
Security Goals and Objectives
Define to reduce critical assets and data
Risk Mitigation
Having the right procedures in place to quickly reduce the impact of risks like breaches
Compliance
Way for the org to enforce security norms and standards
Business Continuity
Ability to maintain operations and productivity in the face of disaster with adequate recovery plans
Legal Regulations
The rules for how to behave as it relates to security
Asset Security
Securing digital and physical assets, including storage, maintenance, and destruction of data
Destroy Hardrives
To block access to critical data
Security Architecture and Engineering
Shared Responsibility
Everyone tries to reduce risk
Identity and Access Management
Identification
Someone provides identifying information
Authentication
Checking to see if information matches what’s in the system for access
Authorization
Deciding what access a person should have based on their role
Accountability
Monitoring user action