SABSA Flashcards

1
Q

What are the layers in the SABSA model.

A
Contextual (Business's)
Conceptual (Architect's)
Logical (Designer's)
Physical (Builder's)
Component (Tradesman's)
Security Service Management (Service manager's)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What questions are normally asked?

A
What are you trying to do?
Why are you doing this?
How are you going to do it?
Who is involved?
Where are you doing it?
When are you doing it?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does the SABSA model provide x2 way traceability?

A

Completeness: verifying that every business requirement has been met from the Contextual layer and down.

Business justification: moving from Security Service Management and up, to determine whether every component is justified.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the horizontal layers of the SABSA matrix?

A

These are the SABSA layers: Contextual through to Security Service Management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the vertical slices in the SABSA matrix

A

These are the x5 W and x1 H questions, which are represented as:

  1. Assets (What)
  2. Motivations (Why)
  3. Process (How)
  4. People (Who)
  5. Location (Where)
  6. Time (When)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the SABSA lifecycle?

A

It is a loop that consists of:

  1. Strategy and planning
  2. Design
  3. Implement
  4. Manage and measure.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the SABSA Business Attributes profile?

A

This is a way of defining attributes (abstracted requirements) and grouping them. SABSA refers to it as: ‘allowing a unique set of business requirements to be translated, standardised and normalised.’ These include statements such as: ‘Authenticated, Annually Appraised, Educated, Capacity Managed’, etc. SABSA provides some examples of these attributes; however, it is down to the Enterprise as to whether they wish to make their own or not.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is meant by the ‘duality’ of risk?

A

The SABSA framework asserts that risk management should also include opportunity management. Therefore, risks and opportunities should be managed together, to maximise the benefit to the organisation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly