CISSP Study Guide
Authentication (Ans- proof and verification of information
Identification (Ans- identity verification
Confidentiality (Ans- Protection from unauthorized viewing
Availability (Ans- Maintaining system usability
Permissive (Ans- allow by default
Restrictive (Ans- deny by default
Defense in depth (Ans- layered defense
Asset valuation (Ans- what are you trying to protect
Determining users (Ans- need and level of access user entitlement
Policy (Ans- documented, discrete standards and guidelines for determining access to organizational information
- / 2
Separation of Duties (Ans- users are not given oversight of an entire process (cost-benefit)
Least privilege (Ans- only have permissions they need
Need to know (Ans- only have access to data they needs
Compartmentalization (Ans- Isolating groups and information (The more people that know, the greater security risk)
Security Domain (Ans- common processes and controls distinct from other areas
Network access control (Ans- ensures a system is configured in accordance with current policies
Remote access (Ans- virtual private network
System access (Ans- smartcards, tokens, userID and password
Application access (Ans- monitor user sessions, inactivity time-outs, validating data entry
Malware Control (Ans- Antivirus, file integrity checks, IPS
Malware encryption (Ans- supports confidentiality and authentication, hashing, assists in session validation
- / 2