100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Summary

Summary Security Architecture and Risk Management

Rating
-
Sold
-
Pages
10
Uploaded on
16-10-2024
Written in
2022/2023

The Advanced Cybersecurity and Risk Management notes are from the University of Phoenix Advance Cybersecurity Certification course - these notes will assist you in understand different aspects and domains of Information Security. The notes will guide you through the process of understanding each domain to prepare you for future certification exams.

Show more Read less
Institution
Cyber Security Specialist
Course
Cyber Security Specialist









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Cyber Security Specialist
Course
Cyber Security Specialist

Document information

Uploaded on
October 16, 2024
Number of pages
10
Written in
2022/2023
Type
Summary

Subjects

Content preview

Advanced Cybersecurity Course

Discussion - Secure Architecture

Security models and architectures are designed to fortify networks to
discourage or deter attackers from targeting them, but no network is
completely without vulnerabilities.



Name and explain 3 common flaws that can be found with
secure architectures. What are some ways to mitigate these potential
weaknesses?



1. Lack of Policy and Security Awareness Training

a. Some organizations fail to provide a high level policy that
address security at the critical levels of the business. I believe
the biggest failure rather, is the lack of Security Awareness
training and ensuring the work force has not only reviewed all
the Security components, but fully understand them as well.

b. A way to mitigate is to 1: ensure that all policies are up-to-date
and in a readable and understandable format. 2: Enable Security
Awareness training at the Director or VP level using the top-down
approach - get them to make this task important and
accountable; and make it as important to their employees.

2. Insider Threats

a. Often overlooked insider threats are a very common theme in an
organization. While we have security controls in place to enforce
least privilege and are able to monitor the network, who is
monitoring the employees behavior?

i. This takes a new wrinkle with so many employees now
working remote, but the mitigation is still the same - still
using a top-down approach, the organizational leaders
from Manager up to VP must ensure they are monitoring
the heartbeat and pulse of their people.

3. Principle of Least Privilege




1

, a. I have seen this more than I care to recall, but many
organizations do not adhere to this principle. Too often
organizations get lazy and bulk load users into systems or
applications giving them too much access. Creation and
maintenance of roles in a system can be a lot of work, but it can
also be automated.

b. The mitigation for ensuring users receive only enough privileges
to do their duty should include, robust role based controls and
corporate LDAP authentication, logging of the system to track
ingress/egress of users and their activity, as well as a true annual
audit of the system, the controls in place, information
classification, and who has access against who should have
access.

1 - CIA

 Confidentiality - the concept of the measures used to ensure the
protection of the secrecy of data, objects, or resources

o Prevent or minimize unauthorized access to data

o Encryption - access controls - steganography

 Sensitivity - refers to the quality of information to prevent harm or
damage

 Discretion - the act of a decision to control disclosure to minimize harm
or damage

 Criticality - level to which information is mission critical - the higher the
level of criticality the more likely the need to maintain confidentiality

 Concealment - act of hiding or preventing disclosure

 Secrecy - the act of keeping something a secret

 Privacy - keeping confidential information that is PI or might cause
harm, embarrassment, or disgrace to someone

 Seclusion - involves storing something in an out-of-the-way location

 Isolation - act of keeping something separated



Integrity - concept of protecting the reliability and correctness of data


2
$5.99
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached

Get to know the seller
Seller avatar
jimb6056

Also available in package deal

Thumbnail
Package deal
Cybersecurity and Risk Management
-
30 2024
$ 179.70 More info

Get to know the seller

Seller avatar
jimb6056 (self)
View profile
Follow You need to be logged in order to follow users or courses
Sold
0
Member since
1 year
Number of followers
0
Documents
37
Last sold
-

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions