Need 600+ words with no plagiarism and 2+ schoarly references in APA Format.

profilepandufirebolt
ch02-2.pptx

Chapter 2 Personnel Security and Risk Management Concepts

Personnel Security Policies

and Procedures

Personnel Management

Candidate Screening and Hiring

Employment Agreements and Policies

Onboarding and Termination Processes

Vendor, Consultant, and Contractor Agreements and Controls

Compliance Policy Requirements

Privacy Policy Requirements

overview

Personnel Management

Job descriptions, position descriptions

Separation of duties

Job responsibilities

Job rotation

Cross-training

Collusion

Candidate Screening and Hiring

Based on job description

Background checks

Reference checks

Education verification

Security clearance validation

Online background checks

Employment Agreements and Policies

Non-disclosure agreement

Non-compete agreement

Audit job descriptions, work tasks, privileges, and responsibilities

Mandatory vacations

Onboarding and Termination Processes

Onboarding vs. offboarding

Maintain control and minimize risks

Exit interview

Terminate access

Return company property

Vendor, Consultant, and Contractor Agreements and Controls

Define the levels of performance, expectation, compensation, and consequences

Service-level agreement (SLA)

Risk reduction and risk avoidance

Compliance Policy Requirements

Conforming to or adhering to rules, policies, regulations, standards, or requirements

Maintain high levels of quality, consistency, efficiency, and cost savings

Privacy Policy Requirements

Active prevention of unauthorized access to information that is personally identifiable

Freedom from unauthorized access to information deemed personal or confidential

Freedom from being observed, monitored, or examined without consent or knowledge

Legislative and regulatory compliance issues

HIPAA, SOX, FERPA, GLB, DPD, and GDPR

PCI-DSS

Security Governance

Maintain business processes while striving toward growth and resiliency

Third-party governance

Auditing security objectives, requirements, regulations, and contractual obligations

Compliance

Documentation review

Authorization to operate (ATO)

Understand and Apply Risk Management Concepts

Risk Terminology

Identify Threats and Vulnerabilities

Risk Assessment/Analysis

Risk Responses

Countermeasure Selection and Implementation

Types of Controls

Security Control Assessment

Monitoring and Measurement

Asset Valuation and Reporting

Continuous Improvement

Risk Frameworks

overview

Risk Terminology

Asset

Asset valuation

Threats

Vulnerability

Exposure

Risk

Safeguard, security control, countermeasure

Attack, breach

Identify Threats and Vulnerabilities

Inventory all threats for each asset

Threat agents

Threat events

Include non-IT sources

Risk Assessment/Analysis

Quantitative analysis

Qualitative analysis

overview

Quantitative Analysis

AV

EF

SLE = AV * EF

ARO

ALE = SLE * ARO

Cost benefit:

ALE before – ALE after – annual cost safeguard (ACS) = value of the safeguard to the company

Qualitative Analysis

Brainstorming

Delphi technique

Storyboarding, scenarios

Focus groups

Surveys

Questionnaires

Checklists

One-on-one meetings

Interviews

Risk Responses

Reduce or mitigate

Assign or transfer

Accept

Deter

Avoid

Reject or ignore

Total risk vs. residual risk

threats × vulnerabilities × asset value = total risk

total risk – controls gap = residual risk

Countermeasure Selection

Costs and benefits

Reduce attack benefit

Solve a real problem

Not dependent upon secrecy

Testable

Uniform protection

No dependencies

Tamperproof

Countermeasure Implementation

Administrative

Logical/technical

Physical

Defense in depth

Types of Controls

Deterrent

Preventive

Detective

Compensating

Corrective

Recovery

Directive

Security Control Assessment

Formal evaluation of a security infrastructure’s individual mechanisms against a baseline or reliability expectation

Ensure the effectiveness

Evaluate the quality and thoroughness

Identify relative strengths and weaknesses of security infrastructures

NIST SP 800-53A “Guide for Assessing the Security Controls in Federal Information Systems”

Monitoring and Measurement

Quantified, evaluated, or compared

Native/internal monitoring or external monitoring

Measuring the effectiveness

Asset Valuation and Reporting

Used to justify protections

Tangible value

Intangible value

Used in cost/benefit analysis

Helps select safeguards

Defines level of risk

Risk reporting

Internal or to relevant/interested third parties

Continuous Improvement

Security is always changing

Needs to be integrated into deployed security solutions

Risk analysis is a “point in time” metric

As threats change, so must security

Risk Frameworks 1/3

Guideline or recipe for how risk is to be assessed, resolved, and monitored

NIST SP 800-37

Risk Management Framework (RMF)

1. Categorize 2. Select

3. Implement 4. Assess

5. Authorize 6. Monitor

Risk Frameworks 2/3

Risk Frameworks 3/3

Operationally Critical Threat, Asset, And Vulnerability Evaluation (OCTAVE)

Factor Analysis Of Information Risk (FAIR)

Threat Agent Risk Assessment (TARA)

Establish and Maintain a Security Awareness, Education, and Training Program

Security requires changes in user behavior

Seek policy compliance

Awareness

Training

Education

Manage the Security Function

Security governance

Risk assessment

Craft security policy

Cost effective

Measurable security

Resource management

Conclusion

Read the Exam Essentials

Review the Chapter

Perform the Written Labs

Answer the Review Questions