Managing Security Operations Flashcards

1
Q

Need to Know

A

Only people with legit need to access data/info can

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Lease Privilege

A

Subjects only granted privileges needed to do their work tasks and no more

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Entitlement

A

Amount of privileges granted to users, usually when provisioning an account (least privilege)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Aggregation

A

Number of privileges a user collects (least privilege)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Transitive trust

A

Least privilege. All subdomains of a non-transitive trust can access objects in the other domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

separation of privilege

A

applies sep duties to apps, processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Segregation of duties

A

Sep of duties + least privilege. Related to SOX Act of 2002

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

2-person rule

A

takes 2 people to do critical task

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Job Rotation

A

deterrent + less dependent on a single person

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Monitor special privileges

A

Good to do

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Managing the Info Life Cycle

A

Marking Data
Handling Data
Storing Data
Destroying data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SLAs

A

Performance expectations for outside vendor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly