Chapter 11 - Security Operations Flashcards
Due Care vs Due Diligence
Due Care is keeping things maintained and due diligence is “look before you leap”
Security Accountability
Checking audit logs and enabling audit logs
Clipping Level
How many errors trigger an action or discipline
Operational Assurance
Ensure the product architecture and features are implemented securely
Life-Cycle Assurance
Ensure design, testing and configuration management is in place
What to look out for?
Unusual Occurrences
Deviation from Standard
Asset Management
IO Controls
Transactions should be timestamped and recorded
Input Validation
Output should only reach intended requester
System Hardening
Lock that door, configure a password, SSL enable.. etc
Licensing
Business Software Assurance (BSA) will get you if you dont license and pirate corporate software
Acceptable Use Policy
This is used to control what users can install and use on the technology the company provides
Change Control
Used to document system changes
Sanitized data
Contents deleted
Purging data
Contents deleted, and zeroization or degaussing occurs on the media
Data Remanence
Residual data left over after sanitizing or purging
Object Reuse
Giving a hard drive away to your grandma