Section 11.99 Standards Flashcards

Objectives 5.1 Summarise elements of effective security governance. Objectives 5.4 Summarise elements of effective security compliance

1
Q

Standards

A

Provides a framework for implementing security measures, ensuring that all aspects of an organisation’s security posture are addressed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Password Standards

A

Define password complexity and management

■ Include length, character types, regular changes, and password reuse rules

■ Emphasise password hashing and salting for security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Access Control Standards

A

Determine who has access to resources within an organization

Include access control models like:
● Discretionary Access Control (DAC)
● Mandatory Access Control (MAC)
● Role Based Access Control (RBAC)

■ Enforce principles of least privilege and separation of duties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Physical Security Standards

A

Cover physical measures to protect assets and information

■ Include controls like perimeter security, surveillance systems, and access control mechanisms

■ Address environmental controls and secure areas for sensitive information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Encryption Standards

A

Ensure data remains secure and unreadable even if accessed without authorisation

■ Include encryption algorithms like AES, RSA, and SHA-2

■ Depends on the use case and balance between security and performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly