Isc2 Cissp 1 16 1 Security and Risk Management Key Points
Isc2 Cissp 1 16 1 Security and Risk Management Key Points
Isc2 Cissp 1 16 1 Security and Risk Management Key Points
Objectives:
Understand and identify the key points and items from Domain 1 that need to be
mastered as part of your preparation to take and pass the CISSP exam.
External Resources:
2. CIA Triad
3. What is Governance?
6. Intellectual Property
8. Collection Limitation
9. Data Quality
13. Openness
a. Administrative - INTERNAL
b. Criminal - conducted by law enforcement
c. Civil - present a case in a civil trial
d. Regulatory - government agency
e. Industry standards - Electronic Discovery (eDiscovery) used to facilitate
the processing of electronic information for disclosure
12. Identification
13. Preservation
14. Collection
15. Processing
16. Review
17. Analysis
18. Production
19. Presentation
a. separation of duties
b. least privilege
c. need to know
d. job rotation
Control Categories
• Physical
• Administrative
• Logical (Technical)
Control Types
1. Directive
2. Deterrent
3. Preventive
4. Compensating
5. Detective
6. Corrective
7. Recovery
18. Prepare
19. Categorize
20. Select
21. Implement
22. Assess
23. Authorize
24. Monitor
Methodologies:
STRIDE
DREAD
(Risk_DREAD = (DAMAGE + REPRODUCIBILITY + EXPLOITABILITY + AFFECTED USERS + DISCOVERABILITY) / 5
Process for Attack Simulation and Threat Analysis (PASTA)
Trike
Visual, Agile, and Simple Threat modeling (VAST)