Day 3 -12/24/2018 Flashcards
Governance vs Management
Governence (board of directors) - financial/stakeholders/compliance
E D M
evaluate
direct
monitor
Management -administrative daily tasks as guided by Governence (PBRM) PLAN BUILD RUN Monitor
SCA
SCA
security control assessment
to evaluate security infratructure against a baseline
NIST 800-53A
LAst step of Risk Ana,ysis
Risk Analysis
cobit vs coso
Control objectives , security goals for IT where
in COSO its for full organizations
itil ,SDTOC
best practices for it services management 5 service management publications >strategy >design >transition >operation >continual improvement
OCTAVE
operationally critical threat asset and vulnerability evaluation
> identfy threats
> identify vulnerabilities
> risk analysis and mitigation
purpose of exit interview
> to review the formal restrictions
> reminder about NDA
Risk related all works done by management
bu safeguards or countermeasures are decided by sr management
prevent collusion
> seperation > job rotation >job responsibilities
Quantitive risk analysis procedures
> asset valuation AV
threat identification of each , for each threat calculate EF and SLE
Frequency of risk. ARO
derive loss potential ALE
research countermeasures for each threat
perform a cost benefit analysis