โ Must-know
Further detail
๐ Identification is how users claim their identities, authentication tests evidence of identity, authorization grants rights and permissions, accountability uses audit trails and logs, and privacy concerns the level of confidentiality and privacy protection.
CIA: confidentiality, integrity, availability
๐ Information classification focuses protection and control on data that needs it most because not all data has the same value to an organization, and it can support privacy-law and regulatory compliance.
The private-sector classification terms are:
The classification procedure identifies the administrator or custodian, specifies classification and labeling criteria, classifies data by its owner subject to supervisor review, documents exceptions, specifies controls for each level, defines declassification or custody-transfer procedures, and creates an enterprise awareness program.
๐ The information owner determines the required classification and delegates protection duties to the custodian, while the custodian protects the information and the user routinely uses it for work.
Identify, classify, control, declassify, educate
๐ Standards specify technologies uniformly and are compulsory, guidelines provide flexible non-compulsory recommendations, and procedures contain the detailed steps for performing a specific task.
Policy โ standard/guideline โ procedure
๐ Security awareness training is necessary because people are often the weakest link in a security chain, employees must protect enterprise information assets, and operators need secure job-function skills.
โ Must-know
Further detail
๐ Risk decisions must consider what can happen, how severe the impact could be, how often it could happen annually, how certain the answers are, what mitigation is possible, its annualized cost, and whether it is cost-effective.
Threat โ impact โ frequency โ uncertainty โ mitigation
โ Must-know
๐ Formula โ Single Loss Expectancy is the monetary loss for each occurrence of a threatened event and satisfies .
๐ Formula โ Annualized Loss Expectancy is the expected annual loss and satisfies .
Further detail
๐ Formula โ The value of a safeguard satisfies .
SLE ร ARO = ALE
โ Must-know
Further detail
๐ Natural disruptive events include fires, explosions, hazardous material spills, earthquakes, storms, floods, and utility failures, while man-made events include bombings, sabotage, strikes, employee unavailability, and communications infrastructure failures.
Scope โ BIA โ continuity strategy โ approval
โ Must-know
Further detail
โ Must-know
๐ Plan approval and implementation requires senior management approval, enterprise-wide awareness, training for personnel with specific duties, maintenance responsibilities, regular audits, and prevention of multiple plan versions.
Further detail
๐ DRP objectives include organized crisis decisions, reduced confusion, protection from major computer-service failure, reduced service-delivery delays, tested standby-system reliability, and reduced disaster-time decision-making by personnel.
Hot sites are ready immediately; cold sites require equipment
โ Must-know
๐ A hot site is a fully configured facility available immediately, a cold site provides space and utilities but no resident hardware, and a warm site provides facilities and utilities while applications or workstations may require configuration and setup.
๐ Electronic vaulting transfers backup data off-site, remote journaling processes transactions in parallel at an alternate site, and database shadowing duplicates database sets across multiple servers.
DRP testing verifies recovery-procedure accuracy, identifies deficiencies, trains personnel for emergency duties, and verifies the alternate site's processing capability.
The five DRP test types are:
๐ The recovery team activates recovery procedures and restores critical functions at the alternate site, the salvage team restores the primary site, and normal operations resume when processing returns from the alternate site to the primary site.
Further detail
Other alternate processing services include:
DRP maintenance builds maintenance and audit procedures into the organization so the plan remains current and its state is reported regularly.
Other recovery issues include:
Checklist โ walk-through โ simulation โ parallel โ full interruption
| Dimension | BCP | DRP |
|---|---|---|
| Primary purpose | Continue business during an emergency | Recover from an emergency |
| Main components | Scope initiation, BIA, plan development | Recovery process, testing, procedures |
| Main concern | Protect and resume critical business processes | Restore services with minimum impact |
| Element | Function | Compulsion |
|---|---|---|
| Policy | General, high-level direction | Required foundation |
| Standard | Uniform technology requirements | Compulsory |
| Guideline | Flexible recommendations | Not compulsory |
| Procedure | Detailed task steps | Operational instruction |
Test your knowledge on Information Security and Continuity Planning with 32 multiple-choice questions with detailed corrections.
1. What is the primary purpose of information security within an organization?
2. Which set correctly identifies the three basic requirements of information security?
Memorize the key concepts of Information Security and Continuity Planning with 63 interactive flashcards.
What does information security protect in an organization?
An organization's valuable resources.
What are the three basic information security requirements?
Availability, integrity, and confidentiality.
What does availability assure in information security?
That authorized users can access a system whenever needed.
Import your course and AI generates sheets, quizzes and flashcards in 30 seconds.
Sheet generator