Domain 1 - part 2 Flashcards
composite of various standards regulations and statutory requirements from around the world. covering a variety of subjects related to IT and data security.
CSA star cloud security
global/worldwide Focused on policy and controls recognized globally. Know for information security management system.
ISO 27001/2 - -Security control framework - 27001 I S M S policy and 02 controls
Best practices managed by A l e x o s British government and a private firm. How an org IT e n v should enhance and benefit its business goals. Mapped to I S O 20000 standard
I TIL
realm of the security practitioner security controls are applied
Mitigate
Business decision not a security practice. Usually made by senior management
Avoid
converse of avoidance, management may opt for conducting the business function that is associated with the risk without any further action on the org part.
Accept
the practice of paying another party accept full financial impact of the harm
Transfer-Risk Response
formula to calculate SLE
S LE=(AV)(E F) s l eave + f
formula to calculate ALE
ALE=(S LA)(A R O)
mitigate - controls that mitigate the effects or risks of the loss of the primary controls. physical locks that still function if an electronic access control system loses power, or personnel trained to use fire extinguishers hoses in the event a sprinkler system does not activate
compensate
remediation - controls that react to a situation in order to perform remediation or restoration. Include fire suppression systems, intrusion prevention systems, and incident response teams. Tape backups
corrective
recognize - controls that recognize hostile or anomalous activity. These can include motion sensors, guards, dogs, and intrusion detection systems.
detective
reduce - controls that reduce the likelihood someone will choose to perform a certain activity. These can include notification, cameras, and noticeable presence of other controls.
deterrent
Mandates - controls that impose mandates or requirements. can include policies, standards, signage, or notification, and are often combined with training.
directive
prohibit - Controls that prohibits a certain activity. Walls and fences they prohibit people from entering an area in an unauthorized manner.
preventive