Chapter 2 – Design Requirements Flashcards

1
Q

Business Requirements Analysis

A

inventory of all assets; valuation of each asset (BIA, data owners determine value; head of department); determination of critical paths (made by senior management; SPOFs), processes, and assets; clear understanding of risk appetite (set by senior management)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

SPOFs (Single Points of Failure) methods

A

Quantitative, Qualitative, and Risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Quantitative Risk Assessment

A

use specific numerical values such as 1,2, and 3; employ a set of methods, principles, or rules for assessing risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Qualitative Risk Assessment

A

use nonnumerical categories that are relative in nature; high, medium, and low; employ a set of methods, principles, or rules for assessing risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk

A

likelihood an impact will be realized; can be reduced, never eliminated; orgs can accept a level of risk that allows operations to continue in a successful manner; legal and defensible to accept risks higher than the norm/greater than your competitors (except risk to health and human safety, must be addressed to industry standard/regulatory scheme)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

four main ways to address risk

A

Avoidance, Acceptance, Transference, Mitigation, and Residual Risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Security Considerations for Cloud IaaS

A

customer has the most responsibility and authority; provider is responsible for building, land, connectivity, power, and hardware assets; makes auditing difficult because they cannot set up network monitoring for policy and regulatory compliance, but customers can collect and review event logs from the software (OS too)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Security Considerations for Cloud PaaS

A

same as IaaS but provider controls the OSs; customer can still monitor and review software events because the programs running on the OS belongs to them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Security Considerations for Cloud SaaS

A

customer only supplies and process data; security controls are limited because provider supplies all needs of customer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly