-
Authority + Responsibility + Accountability
-
Confidentiality
- Protection of information in a system
- For: military, government, commercial
-
Rainbow series
- Trusted Computer System Evaluation Criteria
- Trusted Network Interpretation
- Password Management Guideline
-
Methods
- Encryption
- Strict access control
- Data classification
- Extensive personnel training
-
Integrity
- Protection of system data from unauthorized changes
- For: government, commercial
-
Methods
-
Need-to-know access
- Users can only access what they need
- Max control, min restrictions
- Integrity models
- Prevent unauthorized users to make modifications
- Prevent authorized users to make improper modifications
- Maintain internal and external consistency of data and programs
- Separation of duties
- Job rotation
-
Availability
- System is accessible whenever needed
-
Methods
-
Physical
- Fire control, backup storage
-
Technical
- Fault-tolerance hardware
-
Administrative
- Policies, contingency plan
-
Human/staff
- Human is the weakest element in any security solution
-
Employ steps
- Create job description
- Separation of duties
- Job responsibilities
- Job rotation
- Screening and background checks
- Create employment agreement
- Employee termination
-
Roles
- Data owner
- User
- Security professional
- Senior manager
- Auditor
-
Management
-
Change
- Standardize methods and procedures to handle changes properly
- Implement changes in a monitored and orderly manner
- Formalized testing process
- All changes can be reversed
- Users are informed of changes
- The effect of changes are systematically analyzed
-
Configuration
-
Establishing and maintaining consistency
- Functional attributes
- Physical attributes
-
Management of security features and assurances
- Control of changes made to hardware, software,
firmware, documentation
-
Asset
- Join financial, contractual and inventory functions to
support life cycle management and strategic decision making
-
Incident
- Activities of an organization to identify, analyze and correct hazards
-
Topic
-
Asset valuation
- Cost
- Value
- Calculating safeguards
-
Threats
- Natural
- Incident
- Physical
-
Risks
-
Scenarios
- Threat-oriented
- Safeguards
- Rating
- Handle