Managing Security Operations Flashcards
Need to Know
Only people with legit need to access data/info can
Lease Privilege
Subjects only granted privileges needed to do their work tasks and no more
Entitlement
Amount of privileges granted to users, usually when provisioning an account (least privilege)
Aggregation
Number of privileges a user collects (least privilege)
Transitive trust
Least privilege. All subdomains of a non-transitive trust can access objects in the other domain.
separation of privilege
applies sep duties to apps, processes
Segregation of duties
Sep of duties + least privilege. Related to SOX Act of 2002
2-person rule
takes 2 people to do critical task
Job Rotation
deterrent + less dependent on a single person
Monitor special privileges
Good to do
Managing the Info Life Cycle
Marking Data
Handling Data
Storing Data
Destroying data
SLAs
Performance expectations for outside vendor