Organizational and Security Concepts Flashcards
Service Assets
- Things processses or people that contribute to delivery of services
- Each must identifies with label
CI
Configuration Item
- Asset that requires specific management procedrues to be used to deliver service
- Defined by their attributes
Baseline
- Documents approved state of a CI
- Allows auditing to detect changes
- Can be performance or configuration
CMS
Configuration Management System
- Tools and Databases that collect, store manage and present information about CIs
- Might be spreadsheet for smalled orgs or applications for larger
Change Management Process
- Minimized risk of unscheduled downtime
- Changes are made in planned and conrolled way
- Changes can be reactive or proactive
- Also categorized by level of risk
- Reason for change and procedure is captued in Request for Change (RFC) document
SOP
- Sets out principal goals and concsiderations, like budget, security, customer contact standards for performing a task
- Identifies responsibility and authorization for performing it.
- May contain detailed steps for completing a task
Audit Report
- Identifies and records assets
- Many software suites available to assist with asset tracking
- ## Often would contain info on type, model, serial number, asset Id, location, users etc.
Assessment Report
- Evaluates configuration and deployment of assets
- Records deviations from baseline
- Used to recommend improvements and goals
Floor Plan
- Diagram of wiring and port locations
Wiring Diagram
- shows information on terminations of RJ45 and RJ-48C jacks
- Could also include fiber optic
Port location Diagram
- identifies how wall ports connect to ports on patch panel or dist frame and then to switch ports
MDF
Main Distribution Frame
- Location ofr Distribution/core internal switching
- Terminates trunk lines form multiple IDFs (Intermediate Distribution Frames)
- Also where WAN circuits terminate
IDF
Intermediate Distrubiton Frame
- Termination for access layer switches that serve a given area
- Each has trunk link to MDF
Rack
- Specially configured steel shelving system for patch panels, switches and server devices
Rack Diagram
- Records positions of each appliance in Rack
- Should also record key configruation information for each item
- You should identify which powers are UPSs
Incident Response Plan
- Sets out procedures and guidelines for dealing with security incident
- Multiple Aims are present at once
- Protecting confidential data and minimizing impact
- Preserving evidence for prosecuting perpetrators
- Follow up and lessons to prevent reoccurence
DRP
Disaster recovery Plan
- Address large scale performance or security incidents
- Focuses on switches to fail over systems or restoring backups
Should address:
- Identify scenarios for natural and non-natural disasters and options for protecting systems
- Identify tasks, resources and responsibilities when responding to distaster
- Train staff in response procedures
BCP
Business Continuity Plan
- Collection of processes and resources to enable org to maintain business operations in face of adverse event
- Focuses on Business Impact Analysis (BIA) to identify mission-critical functions
- Supporting those processes with resilient systems
Security Policy
- Establishes duty for each employee to ensure CIA
Onboarding
- Welcoming a new employee to org
- Background Check
- Identify and Access management (IAM) Creating accounts and privileges for employee
- Asset allocation
- Training and policies
Offboarding
- IAM, Disabling user accounts and privileges
- Retrieving company assets
- Returning personal assets and removing any org data from user devices
Password Policy
- Rules on how users can set up passwords
- Can be system enforced
AUP
Acceptable Use Policy
- Permitted uses of product or service
- May also state prohibited uses
- Could apply to employees or vendors
BYOD
Bring your own device
- Often users must install enterprise management software on devices
DLP
Data Loss Prevention
- Products that scan content in structured formats (databases) or unstructured formats (email, word docs)
- Blocks or alerts when confidential material is being used inappropriately
SLA
Service Level Agreement
- Agreement on detailed terms of how an ongoing service is provided
- Can be contractual or less formal between departments
NDA
non-disclosure agreement
- Protects information assets
- Between org and employees and between vendors as well
MOU
Memorandum of Understanding
- Preliminary agreement to express interest to work together
- Usually informal and not binding
- Usually include confidentiality agreements