Chapter 6 - Roles And Responsibilities Flashcards
What does the cop had to consider if he builds a facility in a rural setting?
Ensure creating robust, redundant utility connections for connectivity and power services
What needs to be considered when building a dc?
Proximity to customer, attractiveness for personnel, natural disasters
Cool ensuring secure hardware components
Need to consider BIOs Installation (Firmware flashed into professor) , proper installation of virtualization tools and TSM (treuester platform standard = dictates how processor can be used for cryptographic functions)
What does provider has to consider regarding physical plant
Secure hardware components, hardware configuration, hardware logging, computer contingent composition (Muli tenancy vs exclusive host), Renoir Admin access
Cp responsibility secure logical framework elements
Secure virtual os installation ( including virtualization management tools), secure configuration for virtualize elements
Cp responsibilities secure networking
Firewalls, ids/ips (Monitor Network), honeypots, vulnerability assessment (only known are detected, attacks on unkown = zero-day attacks), communication protection (data in transit via encryption, vpn, strong authentication)
What are the shared responsibilities by service type?
IaaS: Secure infrastructure
PaaS: Platform Security (cc Updates and patches Apps and cp must make sure that app and Security functions properly afterwards)
SaaS: Application security (cp for app and cc for access)
Shared responsibilities is, middleware our applications
Establish hardening by implementing a Baseline configuration to have the same setup on all machines
How can shared responsibilities for data access take place?
Cc does it himself (logs onto machine)
Cp takes this task and only verifies with cc
Casb takes over the task, verifies with cc and logs onto machine
Who created the SSAE of which SOC ist part of?
AICPA (American Institute of certified public accountants)
What Are the the soc report categories?
SOC 1: financial (type one and two)
SOC 2: organization controls
SOC 2 type 1: how control is designed in the organization
SOC 2 type 2: how controls are implemented and maintained (most useful!!)
SOC 3: Seal of approval