Name 4 “Access Control” Levels/Layers:
(1) Data Level
(2) Application Level
(3) O/S Level
(4) Network Level
What are “Access Controls” at the “Data Level”?
What are “Access Controls” at the “Application Level”?
What are “Access Controls” at the “O/S Level”?
What are “Access Controls” at the “Network Level”?
Name examples of Firewalls Controls at the “Network Level”?
(1) Patch vulnerabilities with due diligence
(2) Encrypt data at rest or in transit if sensitive or if high risk of interception in communications
(3) Put a second firewall between network and back-end systems to filter access to critical systems like financial reporting systems
What is the 3 minimum Policies requirements for “Data Backup”?
(1) Regular backups of data
(2) Offsite storage of data
(3) Testing of recovery
What are some considerations to “Data Backup”?
(1) Backup manual or auto (more reliable),
- At specific time
- With specific criteria
- Test or observe
- Operation (walk-through)
(2) Backup can be physical like tape or disk or remote server
(3) Backup procedures should minimize risk or recovery by using multiple backups
- Traditional grandfather-father-son method illustrates risk minimizing process
(4) Store backup at a reasonable distance from entity
(5) Test recovery of data at least once a yr
What are some items included in a thorough BCP (Business Continuation Plan) or DRP (Disaster recovery Plan)
● Written plan
● Predefined ranked list of apps in order of optimal restoration
● Recovery team, w/ roles and responsibilities ID’d
● Backup facility, including building, power, desks
● Backup of:
- infrastructure/platform
- O/S(s)
- Computers and workstations
- Supplies (checks, invoices, paper)
- Technical and operational manuals
● Backup copy of all apps
● Reliable, relatively current backup of data
● Formal, structured test of the full plan
● Regular test of the plan (at least once a yr)
What is an “Incident Response Plan” and what is involved?
What is involved in Testing a “Contingency Plan”?
(1) Test plans before needed and thorough
(2) Test should include all relevant aspects of the plan
(3) Perform w/ realism in mind
(4) Test often enough
to be highly reliable
- At least once a yr
What factors should be considered at the “Operating System” Level?
What factors should be considered at the “Network” Level?