Need 600+ words with no plagiarism and 2+ schoarly references in APA Format.
Chapter 2 Personnel Security and Risk Management Concepts
Personnel Security Policies
and Procedures
Personnel Management
Candidate Screening and Hiring
Employment Agreements and Policies
Onboarding and Termination Processes
Vendor, Consultant, and Contractor Agreements and Controls
Compliance Policy Requirements
Privacy Policy Requirements
overview
Personnel Management
Job descriptions, position descriptions
Separation of duties
Job responsibilities
Job rotation
Cross-training
Collusion
Candidate Screening and Hiring
Based on job description
Background checks
Reference checks
Education verification
Security clearance validation
Online background checks
Employment Agreements and Policies
Non-disclosure agreement
Non-compete agreement
Audit job descriptions, work tasks, privileges, and responsibilities
Mandatory vacations
Onboarding and Termination Processes
Onboarding vs. offboarding
Maintain control and minimize risks
Exit interview
Terminate access
Return company property
Vendor, Consultant, and Contractor Agreements and Controls
Define the levels of performance, expectation, compensation, and consequences
Service-level agreement (SLA)
Risk reduction and risk avoidance
Compliance Policy Requirements
Conforming to or adhering to rules, policies, regulations, standards, or requirements
Maintain high levels of quality, consistency, efficiency, and cost savings
Privacy Policy Requirements
Active prevention of unauthorized access to information that is personally identifiable
Freedom from unauthorized access to information deemed personal or confidential
Freedom from being observed, monitored, or examined without consent or knowledge
Legislative and regulatory compliance issues
HIPAA, SOX, FERPA, GLB, DPD, and GDPR
PCI-DSS
Security Governance
Maintain business processes while striving toward growth and resiliency
Third-party governance
Auditing security objectives, requirements, regulations, and contractual obligations
Compliance
Documentation review
Authorization to operate (ATO)
Understand and Apply Risk Management Concepts
Risk Terminology
Identify Threats and Vulnerabilities
Risk Assessment/Analysis
Risk Responses
Countermeasure Selection and Implementation
Types of Controls
Security Control Assessment
Monitoring and Measurement
Asset Valuation and Reporting
Continuous Improvement
Risk Frameworks
overview
Risk Terminology
Asset
Asset valuation
Threats
Vulnerability
Exposure
Risk
Safeguard, security control, countermeasure
Attack, breach
Identify Threats and Vulnerabilities
Inventory all threats for each asset
Threat agents
Threat events
Include non-IT sources
Risk Assessment/Analysis
Quantitative analysis
Qualitative analysis
overview
Quantitative Analysis
AV
EF
SLE = AV * EF
ARO
ALE = SLE * ARO
Cost benefit:
ALE before – ALE after – annual cost safeguard (ACS) = value of the safeguard to the company
Qualitative Analysis
Brainstorming
Delphi technique
Storyboarding, scenarios
Focus groups
Surveys
Questionnaires
Checklists
One-on-one meetings
Interviews
Risk Responses
Reduce or mitigate
Assign or transfer
Accept
Deter
Avoid
Reject or ignore
Total risk vs. residual risk
threats × vulnerabilities × asset value = total risk
total risk – controls gap = residual risk
Countermeasure Selection
Costs and benefits
Reduce attack benefit
Solve a real problem
Not dependent upon secrecy
Testable
Uniform protection
No dependencies
Tamperproof
Countermeasure Implementation
Administrative
Logical/technical
Physical
Defense in depth
Types of Controls
Deterrent
Preventive
Detective
Compensating
Corrective
Recovery
Directive
Security Control Assessment
Formal evaluation of a security infrastructure’s individual mechanisms against a baseline or reliability expectation
Ensure the effectiveness
Evaluate the quality and thoroughness
Identify relative strengths and weaknesses of security infrastructures
NIST SP 800-53A “Guide for Assessing the Security Controls in Federal Information Systems”
Monitoring and Measurement
Quantified, evaluated, or compared
Native/internal monitoring or external monitoring
Measuring the effectiveness
Asset Valuation and Reporting
Used to justify protections
Tangible value
Intangible value
Used in cost/benefit analysis
Helps select safeguards
Defines level of risk
Risk reporting
Internal or to relevant/interested third parties
Continuous Improvement
Security is always changing
Needs to be integrated into deployed security solutions
Risk analysis is a “point in time” metric
As threats change, so must security
Risk Frameworks 1/3
Guideline or recipe for how risk is to be assessed, resolved, and monitored
NIST SP 800-37
Risk Management Framework (RMF)
1. Categorize 2. Select
3. Implement 4. Assess
5. Authorize 6. Monitor
Risk Frameworks 2/3
Risk Frameworks 3/3
Operationally Critical Threat, Asset, And Vulnerability Evaluation (OCTAVE)
Factor Analysis Of Information Risk (FAIR)
Threat Agent Risk Assessment (TARA)
Establish and Maintain a Security Awareness, Education, and Training Program
Security requires changes in user behavior
Seek policy compliance
Awareness
Training
Education
Manage the Security Function
Security governance
Risk assessment
Craft security policy
Cost effective
Measurable security
Resource management
Conclusion
Read the Exam Essentials
Review the Chapter
Perform the Written Labs
Answer the Review Questions