Featured

Day 3 - Security governance principles | 100 Days of CISSP | Domain 1 - Security & Risk Management



Published
Day 3 of #100DaysOfCISSP
Domain 1 - Security & Risk Management
Today's topic: Security governance principles

* Least privilege: minimum necessary access
* Need to know: Even if you have access, if you do not need to know, then you should not access the data.
* Non - repudiation: a user cannot deny having performed a certain action
* Subject & Object: subject manipulates the object

Governance vs. Management
Governance - C level executives
Management - plans, builds, runs, monitors activities in alignment with the direction (set by governance)

Governance standards
PCI - DSS
OCTAVE
COBIT
COSO
ITIL
FRAP

Control Frameworks
ISO 27000 series

Defence in depth (layered defence/onion defence):
We implement multiple overlapping security controls to protect an asset (data).

100 Days of CISSP
Day 1 - CIA Triad: https://youtu.be/j1DVvYco5JU
Day 2 - IAAA: https://youtu.be/UQvXL79maus

With ❤️,
Nalaemton Selvaraj
#cswithnalaemton
Category
Management
Be the first to comment