Domain 7: Security Operations Flashcards
Continuity Planning Subtasks (5)
Strategy Development, Provisions and Processes ,Plan Approval, Plan Implementation, Training and Education
Strategy Devlopment
Bridges gap btwn BIA and Continuity Planning in BCP - determines which risks are acceptable which must be mitigated
Provisions and Processes
specific procedures and mechanisms that will mitigate the risk deemed unacceptable
Three Categories of assets in BCP Provisions and Processes
People, Buildings/Facilities, Infrasctructure
Important Components of a Written BCP (11)
Continuity Planning Goals, Statement of Importance, Statement of Priorities, Statement of Organizational Responsibility, Statement of Urgency and Timing, Risk Assessment, Risk Acceptance/Mitigation, Vital Records Program, Emergency Response Guidelines, Maintenance, Testing and Exercise
Importance of a Written BCP (3)
Historical Benefit, Sanity Check, Reference document
Entitlement
amount of privileges granted to users
Aggregation
amount of privileges that users collect over time
Transitive Trust
extends the trust between two security domains to all their sub domains
Common methods for managing security in the information life cycle
Marking Data, Handling data, storing Data, Destroying Data
SLA
Service level agreement - agreement between and org and vendor that stipulated performance expectations
MOU
documents the intent of two entities to work together toward a common goal
ISA
info on how the two parties establish, maintain, and disconnect the connection
Virtual Machines
run as guest OSs on physical servers
SDNs
Software Defined Networks - uses simple network devices other than routers and switches
VSANs
Virtual Storage Area Networks - virtual dedicated high speed network that hosts multiple storage devices
What is the primary software component in virtualization?
Hypervisor
Hypervisor
managers the VMs, virtual data storage, and virtual network components
Cloud Computing
on demand access to computing resources from almost anywhere
SaaS
Software as a Service - fully functional applications (Google Docs), Consumes do not manage or control any assets
PaaS
Platform as a Service - computing platform (hw, OS, application), consumers manager the applications and maybe some config settings
IaaS
Infrastructure as a Service - servers, storage, networking resources, consumers install OS and applications and perform all maintenance
What are the 4 cloud models?
Public, Private, Hybrid, and Community
Public Cloud Model
assets available for any consumer to rent or lease