Please enable JavaScript.
Coggle requires JavaScript to display documents.
Security governance through principles and policies (CAP 1) (evaluate and…
Security governance through principles and policies (CAP 1)
Understand and apply concepts of CIA
IAAAA
Accounting
Auditing
Authorization
Authentication
Identification
CIA
Integrity
Availability
Confidentiality
protection mechanisms
layering
abstraction
data hiding
encryption
evaluate and apply security governance principles
security management planning
strategic plan
tactical plan
operational plan
Data classification
government
Unclassified
sensitive but unclassified
Top secret
Secret
Confidential
commercial
public
sensitive
confidential/private
organizational roles and responsabilities
senior manager
security professional
data owner
data custodian
user
auditor
security control frameworks
COBIT
Principle 1: Meeting stakeholder needs
Principle 2: covering the enterprise end-to-end
Principle 3: Applying a single itegrated framework
Principle 4: enabling a Holistic approach
Principle 5: separating governance from management
Develop, document and implement security policy, standards, procedures and guidelines
policy
organizational security pplicy
issue-specific security policy
system-specific security policy
policy
regulatory policy
advisory policy
informative policy
principles
standards
baseline
guidelines
Understand and apply threat modeling concepts and methodologies
STRIDE
spoofing
tampering
repudiation
information
denial of service
elevation of privilege
PASTA (threat modeling strategy)
stage 1: definition of objectives for the analysis of risks
stage 2: definition of the technical scope
stage 3: application
stage 4: threat analysis
stage 5: weakness and vulnerability analysis
stage 6: attack modeling and simulation
stage 7: risk analysis and management
threat modeling steps
identify threats
potential attacks diagram
reduction analysis
prioritization and response
apply risk based management concepts to supply chain