Week 2B Flashcards
1
Q
Main steps Enterprise Information Security
A
- Criticality of business activities
- Operational conditions
- Risk analysis
- Enterprise security requirements
- Security architecture
- Gap and risk analysis
- Management of remaining risks
2
Q
Types of Security Assets
A
- Data-related
- Operation-related
- Person-related
- Control-related
3
Q
Criticality Classification of Business Functions
A
- Critical functions
- Essential functions
- Necessary functions
- Desirable functions
4
Q
Examples of operating conditions
A
- Protect against cash register operating errors
- Protect purchases of customer
- Protect personal information of employees and customers
- Protect integrity of registration of the inventory
- Protect integrity of payments
- Payment chain must be available
5
Q
Enterprise security requirements - Classification Aspects
A
Confidentiality, Integrity, Availability, Auditability, Nonrepudiation
6
Q
Security architecture - classification of security measures
A
Prediction
Prevention
Response
Detect
7
Q
Four types of security measures
A
Process/Procedural
Screening/Awareness
Physical
Information Technology