Domain 5: Protection of Information Assets Flashcards
In regards to the security baseline, what should the auditor first ensure?
The IS auditor should ensure the sufficiency of the baseline to address the security requirements of the organisation. Other aspects can be determined after.
What are the four types of power failure?
Blackout, Brownout, “sags, spikes and surges” and Electromagnetic interference
What is a brownout?
Where power has severely reduced voltage. Can strain devices and lead to permanent device damage.
What is the purpose of surge and spike devices?
Surge and Spike devices help to protect against high-voltage power bursts.
What are sags, spikes and surges?
Sag is a rapid decrease in voltage level. Surge and Spike is a rapid increase in voltage level
What is the most effective control to protect against short-term reduction in power?
A power line conditioner
What is a wet-based sprinkler?
A sprinkler where water remains in the system piping, considered more effective and reliable but is at risk of water damage if pipes leak.
What is a dry pipe sprinkler?
Dry pipe sprinklers rely on a pump to send the water into the system. This is less effective and reliable but does not have the risk of water leaks.
What is a Halon system?
Halon gas starves the fire by removing oxygen from the air, because of this - all humans should be evacuated prior to releasing halon gas.
What are two alternatives to Halon gas?
FM-200 is one alternative and is the most commonly use fire suppression gas. Argonite is another alternative.
What is the most effective control to protect against the long-term unavailability of electrical power?
An alternative power supply
What is the most effective control to protect against high-voltage power burst?
A surge device
What is the risk of carbon dioxide and Halon gas?
Suffocation in a closed room as both reduce oxygen in the atmosphere
What is the most effective control when dealing with site visitors?
Escorting visitors
What is the safest gas to be used as a fire extinguisher?
FM-2000
What is the greatest concern for an IS auditor reviewing the fire safety arrangements?
The use of a carbon dioxide based fire extinguisher in a human accessed room
What is Mandatory Access Control? (MAC)
Control rules are goverened by an approved policy.
What is Discretionary Access Control? (DAC)
Control access can be activated or modified by the data owner as per their discretion
What are the 4 steps for implementing logical access?
- Prepare inventory of resources, 2. Classify the resources, 3. Labelling of resources and 4. Create an access control list
What is Degaussing? (demagnetizing)
It is a process used to erase or destroy magnetic information stored on magnetic media such as hard drives, floppy disks, magnetic tapes, and credit cards.
What are the three authentication factors that can be used for granting access?
Something you know (password), something you have (one-time password) and something you are (biometrics)
What is non repudiation?
Protection against an individual who falsely denies having performed a certain action
Why is considering security and performance parameters most important when reviewing system controls?
As it helps to ensure that the objectives are alligned with the business objectives
What is a good method to prevent unauthrosied access to critical databases?
Blocking access after a specificed number of failed logins. This is preventive solution rather than detective
What is the greatest risk for SSO?
Greater impact of password leakage as only password is used to access many services. Enable 2/MFA.
What is False Acceptance Rate? (FAR)
The rate of acceptance of a false person. For example, if biometrics allows access to an unauthroised person, this is false acceptance.
What is False rejection rate? (FRR)
The rate of rejection of the correct person. For example, if biometrics rejects an authorised person, this is false rejection.
What is Cross error rate (CER) otherwise known as equal error rate (EER)?
This is the rate that FAR and FRR are equal. A biometric system with the lowest CER or EER is the most effective system.