What is the main purpose of data classification and who is responsible for doing it?
To identify what data is considered sensitive and requires protection. The data owners are responsible.
Which of these is the strongest wireless encryption method: WEP, WPA, WPA2
Access to services is determined by the position (or role) a user occupies in the organization.
They can be used to guarantee compatibility between products. They provide a template for companies to use so they don’t have to reinvent the wheel. They help customers evaluate an organization’s efforts towards securing data.
Law enforcement has an on-going issue with encryption methods because they believe it keeps them from seeing information they need to protect the public.
Identification
Authentication
Authorization
Accountability
It is the Greek word for “equal” and was chosen as the name for a set of standards created by several different countries using different languages.
- Need to have a defined security policy.
- User education is critical.
- Must keep up with patches and upgrades on OS and applications.
- Firewalls are the front line of defense.
- Encryption is critical for protecting data.
- Must have on-going monitoring.
Confidentiality
Authentication
Integrity
Non-repudiation
Authentication answers the question “Is this person who they say they are”. Authorization answers the question “What does this person have access to?”
.
ISO 17799 and its successor ISO 27002 provide organizations with best practice recommendations for ___________?
Security professionals need to know how the various laws impact their organization and what they must do from an IT perspective to be compliant.
standards
procedures
baselines
guidelines
Sally would use Bob’s public key (which anyone has access to) to encrypt the message. Then Bob would use his private key (which only he has access to) to decrypt the message.
MFA requires the user to prove their identity by using multiple types of factors. Factors types include 1) something you know, 2) something you have, and 3) something you are.
An audit checks whether the security controls work as expected. Another purpose is to build customer confidence.
It is the process of running digital media through a magnetic field for the purpose of removing any data stored on that media.
They act as a trusted third party to vouch for the validity and ownership of public keys/certificates.
They provide added security for superuser accounts (aka administrator accounts) that have elevated privileges on certain computers.
Risk Assessment
Security policy
Organization of information security
Asset management
Human resources security
Physical and environmental security
Communications and operations management
Access control
Information systems acquisition development and
maintenance
Information security incident management
Business continuity management
Compliance