Chapter 16 Flashcards
1
Q
Operational security
A
- Need to know - Limit access to and knowledge of info
- Least privilege - Limit access to and actions to info/data
- Segregation (or separation) of duties
- Two-person control - e.g. split knowledge, or use 2 keys, etc.
- Job rotation
- Mandatory vacations
2
Q
Asset management
A
Inventory assets
Track assets
Secure and protect assets
3
Q
Software assets - inventory and track licenses; protect from being stolen
A
4
Q
MTTF - time to failure if will not repair
MTBF - time between failures if will repair
A
5
Q
Change Management
A
Primary goal - ensure changes do not cause outages
Process:
1. Request change
2. Review change
3. Approve change
4. Test change
5. Schedule & implement
6. Document
6
Q
Patch Managementf
A
Process:
1. Evaluate patch
2. Test
3. Approve
4. Deploy
5. Verify deployment