Name the 5 Architecture Measurement Categories
Give this one a try later!
Completeness (Do we have everything?)
Assurance (does it work properly?)
Compliance (Do we maintain upkeep and follow rules?)
Performance (do components work well together?)
Justification and Significance (does the system have business value?)
Define Implicit Security Services
Give this one a try later!
, Are implicit within the domain, they secure the domain from within
Define Controls and Enablers
Give this one a try later!
Controls - protect from negative consequences
Enablers - Enhance for positive consequences
List the main parts of a multi tiered control strategy
Give this one a try later!
Deterrence
Prevention
Containment
Detection and Notification
Recovery and Restoration
Name an example of a type of policy that applies at the conceptual layer
Give this one a try later!
Enterprise wide information security policy
How are performance targets used within attributes for risk?
,Give this one a try later!
Performance targets within attributes provide the threshold for "acceptable
risk"
Overall, SABSA is a:
Give this one a try later!
methodology
ICT stands for:
Give this one a try later!
Information and Communication Technology
List the subsystems of a Control System
Give this one a try later!
The Control System itself - that exerts control
The Monitoring and Measurement sub system - measures the state that is in
turn affected by the actions of the control subsystem
The Decision Subsystem - that makes decisions based upon the
measurements provided by the measurement sub system
, Positive impact is expressed as
Give this one a try later!
Increase in attribute performance
increase in attribute performance threshold to higher/greater target (loftier
goals)
Systems engineering is:
Give this one a try later!
A rational approach to decision making, related to the solution of complex
problems in engineering planning, design, and operation.
managing complexity
top down
structured thinking
peer review
It is not possible to define the security architecture of logical, physical , and
component level assets until:
Give this one a try later!
The assets themselves have been defined
Define security service & security service types
Give this one a try later!
Completeness (Do we have everything?)
Assurance (does it work properly?)
Compliance (Do we maintain upkeep and follow rules?)
Performance (do components work well together?)
Justification and Significance (does the system have business value?)
Define Implicit Security Services
Give this one a try later!
, Are implicit within the domain, they secure the domain from within
Define Controls and Enablers
Give this one a try later!
Controls - protect from negative consequences
Enablers - Enhance for positive consequences
List the main parts of a multi tiered control strategy
Give this one a try later!
Deterrence
Prevention
Containment
Detection and Notification
Recovery and Restoration
Name an example of a type of policy that applies at the conceptual layer
Give this one a try later!
Enterprise wide information security policy
How are performance targets used within attributes for risk?
,Give this one a try later!
Performance targets within attributes provide the threshold for "acceptable
risk"
Overall, SABSA is a:
Give this one a try later!
methodology
ICT stands for:
Give this one a try later!
Information and Communication Technology
List the subsystems of a Control System
Give this one a try later!
The Control System itself - that exerts control
The Monitoring and Measurement sub system - measures the state that is in
turn affected by the actions of the control subsystem
The Decision Subsystem - that makes decisions based upon the
measurements provided by the measurement sub system
, Positive impact is expressed as
Give this one a try later!
Increase in attribute performance
increase in attribute performance threshold to higher/greater target (loftier
goals)
Systems engineering is:
Give this one a try later!
A rational approach to decision making, related to the solution of complex
problems in engineering planning, design, and operation.
managing complexity
top down
structured thinking
peer review
It is not possible to define the security architecture of logical, physical , and
component level assets until:
Give this one a try later!
The assets themselves have been defined
Define security service & security service types