Lesson 17: Explaining Organizational and Physical Security Concepts Flashcards
Define configuration management
Identifying and documenting all the infrastructure and devices installed at a site
What are the different aspects of configuration management?
- Service assets
- Configuration Item (CI)
- Baseline Document
- Configuration management system
Define a service asset
Things, processes, or people that contribute to the delivery of an IT service. Each asset must be identified by some sort of label.
Define a configuration item (CI)
An asset that requires specific management procedures for it to be used to deliver the service. CIs are defined by their attributes.
Define a baseline document
Approved or authorized state of a CI; This allows auditing processes to detect unexpected or unauthorized change. A baseline can be a configuration baseline (the ACL applied to a firewall, for instance) or a performance baseline.
What is a configuration baseline?
Settings for services and policy configuration for a network appliance or for a server operating in a particular application role.
Define a configuration management system (CMS)
A Configuration Management System (CMS) is the tools and databases that collect, store, manage, update, and present information about CIs.
Define change management
Process for approving, preparing, supporting, and managing new or updated business processes or technologies.
Summarize a standard change management process
The need or reasons for change and the procedure for implementing the change is captured in a Request for Change (RFC) document and submitted for approval. The RFC will then be considered at the appropriate level and affected stakeholders will be notified.
What is the purpose of a request for change (RFC) document?
To have the pending changes in writing and allows for approval at appropriate level.
Define a standard operating procedure (SOP)
Documentation of best practice and work instructions to use to perform a common administrative task.
Define an audit report
Detailed and specific evaluation of a process, procedure, organization, job function, or system, in which results are gathered and reported to ensure that the target of the audit is in compliance with the organization’s policies, regulations, and legal responsibilities.
What is the difference between an audit report and an assessment report?
An audit report focuses on identifying and documenting assets, an assessment report evaluates the configuration and deployment of those assets, such as deviation from baseline configuration or performance.
What is system life cycle?
Method to track the life cycle phases of one or more hardware, service, or software systems.
What are the types of physical network diagrams?
- Floor plan
- Wiring Diagram
- Distribution Frame
- Wireless Site Survey
What is the purpose of a distribution frame diagram?
A port location diagram identifies how wall ports located in work areas are connected back to ports in a distribution frame or patch panel and then from the patch panel ports to the switch ports.
What are the two types of distribution frames?
- Intermediate Distribution Frame (IDF)
- Main Distribution Frame (MDF)
Define an Intermediate Distribution Frame (IDF)
Passive wiring panel providing a central termination point for access layer switches that serve a given area, such as a single office floor. Each IDF has a trunk link to the MDF.
Define a Main Distribution Frame (MDF)
Passive wiring panel providing a central termination point for cabling. A MDF distributes backbone or “vertical” wiring through a building and connections to external access provider networks.
What are types of logical network diagrams
- Physical layer
- Data link layer (L2)
- IP Layer (L3)
- Application layer (L4)
What information would be included in a physical layer (L1) logical diagram
Asset IDs and cable links
What information would be included in a data link layer (L2) logical diagram?
Interconnections between switches and routers, with asset IDs (or the management IP of the appliance), interface IDs, and link-layer protocol and bandwidth
What information would be included in a logical network (L3) diagram?
IP addresses of router interfaces (plus any other static IP assignments) and firewalls, plus links showing the IP network ID and netmask, VLAN ID (if used), and DHCP scopes.
What information would be included in a logical application layer (L4) diagram?
Server instances and TCP/UDP ports in use. You might also include configuration information and performance baselines.
Define an incident response plan (IRP)
Procedures and guidelines covering appropriate priorities, actions, and responsibilities in the event of security incidents.
Define an incident
When security is breached or there is an attempted breach
What are the main goals during incident response?
- Protect confidential data and minimize impact
- Preserve evidence
- Follow-up analysis to prevent reoccurrence
What is the main conflict when planning incident response?
Protecting data and minimizing impact while preserving evidence for analysis against efficiency and business continuity.
Define a disaster recovery plan (DRP)
Documented and resourced plan showing actions and responsibilities to be used in response to critical incidents.