Midterm 2 Chapter 11 Flashcards
Who is responsible fore security?
Managment
Management must take responsibility for:
- Policy development
- Effective communication of these policies
- Design of appropriate control policies
- Monitoring of the system and, if necessary, take corrective actions
Can the COSO structure be overlaid on the security model?
Yes
Time Based Model of Security
P>D+C
Preventative is greater than the sum of detective plus corrective
P
The time it takes an attacker to break through the various controls that protect the company’s information system assets (we want these to be high)
D
The time it takes for the company to detect that an attack has occurred (we want these to be low)
C
The time it takes to respond to and stop the attack (we want these to be low)
What is the problem with symmetric encryption?
I have to give the key to you somehow - if the key is dropped or lost, anyone with access to it can have access to any of the codes
What is asymmetric encryption based on?
Prime number factering