Asset Management Flashcards
any data, device, or other component of value to an organization
Asset
the process of organizing assets by relevant categories
Classification
US Federal government asset classification system
FIPS 199
standard that requires that information and information systems be categorized as low, medium or high security based on confidentiality, integrity and availability criteria
FIPS 199
US National Security Definitions of confidentiality
Top Secret
Secret
Confidential
Controlled Unclassified Information
Unclassified
formal determination of level of subject access
Security clearance
Private sector classification schema
No hard definition, should be codified in a policy and standards
Private Sector Classification process
- Define classifications
- Identify and categorize data sets and systems
- Assign Classification Labels
- Publish Handling Standards
- Train Users
- Enforce Standards
Asset sensitivity generally relates to this characteristic
Content
Asset criticality generally relates to this characteristic
Operational Value
Applied to subjects and is a formal determination of level of trust
Security clearance