Chapter 13: Security Flashcards
Asset
An employee, contractor, or any physical, technological, or intellectual possession.
Compartmentalization
The isolation or segregation of assets from threats using architectural design or countermeasures, including physical barriers.
Countermeasures
The procedures, technologies, devices, or organisms (dogs, humans) put into place to deter, delay, or detect damage from a threat.
Layering
The use of many layers of barriers, other countermeasures, or a mixture of both is used to provide the maximum level of detterance and delay
Threats
The agents by which damage, injury, loss, or death can occur; threats are commonly classified as originating from temperature extremes, liquids, gases, projectiles, organisms, movement, or energy anomalies.
Vulnerability
A physical, procedural, or technical weakness that creates an opportunity for injury, death, or loss of an asset.
What is a data center security plan?
The security plan is a document providing the framework, policies, and procedures to establish security for data center staff, contractors, and visitors along with the ITE, network technology, telecom assets, and the sites and buildings that house them.
What should be included in the data center security plan?
- Physical Security
- IT/ cyber security
- Disaster recovery plan
- Emergency operation
Give three examples of regulatory and legal documents affecting the operation of the data center.
- Sarbanes-Oxley
- Industry-specific standards
- Federal Information Processing Standards (FIPS)
- Health Insurance Portability and Accountability Acts (HIPAA)
- National Association of Security Dealers Conduct Rules 3010, 3013, and 3110
__________ is the isolation or segregation of assets from threats using architectural design or countermeasures, including physical barriers.
Compartmentalization
What is CPTED?
The crime-reducing concepts and strategies of Crime Prevention Through Environmental Design (CPTED)
What are the three underlying principles of CPTED?
- Natural access control
- Natural surveillance
- Territorial enforcement
Regarding CPTED, what is a private space type?
Spaces that are restricted from most pedestrians, including unauthorized employees. Typical private areas might include print rooms, call centers, private manager offices, a bank vault, a surgery site, and the executive floor of an office tower.
Identify one way proper lighting may be a security measure.
- It prevents concealment for unauthorized access to the data center site or buildings
- It protects the safety of pedestrians, vehicles, and assets
What are the three types of physical access control?
Type 1: What a person has (keys, cards)
Type 2: What a person knows (passwords)
Type 3: What is person is (fingerprints, iris recognition)