Chapter 4 - Security Life Cycles Flashcards
The Information Life Cycle
The information Life Cycle must be managed in a way that supports the assurance or security of the information in the lifecycles.
Generation, Creation, or Acquisition
- How the information comes into the business
Utilization
- Often last the longest - how it is used stored, shared
Disposal
- How to dispose of information once it has services its purpose - could mean deleting or archiving
Plan-Do-Check-Act (PDCA)
Plan-Do-Check-Act helps to ensure that systems are continuously evaluated and improved.
Plan - pre implementation due dil
Do - Implement
Check - monitor and measure performance
Act - Take corrective actions
Commercial-Off-The-Shelf (COTS)
COTS are commercial off the shelf products some concerns on security may be that there are bugs in them or cheap copies with malware on them are sold elsewhere for a discounted price.