Domain 2: Security Ops and Administration Flashcards
ISO 27001:2013
Spec for evaluating the performance of an Information Security Management System. Uses Deming Cycle (PDCA), Six Sigma (Define, measure, analyze, improve, control)
ISO 27002:3013
Provides organizational InfoSec standards and management practices which takes into consideration the orgs information risk appetite. Popular
Security Development Lifecycle (SDL)
SW dev process proposed by MS.
Automated Configuration Management
Centralized method to make changes
Configuration Identification
Baselines
Functional Policies
Address specific issues or concerns of the org. BYOD, AV use, remote wipe, etc.
Organizational Policies
Wide scope policy written by someone very high up. Should have specifics
Operational Policies
aka System Specific Policy. Clear direction on operational topics.
QAT
Quality Acceptance Testing. Performed by IT Quality team.
UAT
User team tests SW against specific scenarios or business cases.
Release coordinator
Communicates issues, problems, and concerns and coordinates the services of the help desk group to facilitate SW deployment.
Waterfall dev process
One step leads to the next until project is completed
Agile dev
Items are developed quickly, tested, and made available. Increases releases.
BRD
Business Requirements Document. Specific design parameters.
Intangible assets
Data, information, and IP