The concept that no single individual has complete authority or control of a critical system is known by which term?
Separation of duties
What 3 advantages does separation of duties provide?
The concept involving regularly transferring key personnel into different positions or departments within an organisation is otherwise known as what?
Job rotation
What are 3 advantages of job rotation?
What are 4 advantages of mandatory vacations?
What is the concept of “Need-to-know”?
What is the principle of “Least Privilege”?
persons should have the capability to perform only the tasks that are required to perform their primary jobs and nothing more.
What is the difference between the concepts of “Need-to-know” and “Least Privilege”?
“Need to know” is concerned with access control whereas “Least privilege” is concerned with functionality.
How can the “accumulation or privileges” occur?
When an employee moves to another role within the same organisation, but previous access rights are not revoked.
What is the main benefit of server virtualisation?
Reduces single point of failure as a virtual server can be replicated or moved from one physical server to another.
What things should be considered for systems regarding single points of failure?
What things should be considered for networks regarding single points of failure?
What is a telecoms hotel?
The facility that houses equipment belonging to many different telecoms providers
What things should be considered for processes regarding single points of failure?
4 key elements of handling sensitive information:
When a system failure occurs, in which type of environment may access be lost?
Fail-soft or fail-closed
When a system failure occurs, in which type of environment will access be open to all?
Fail-open
When a system crash occurs, what term is used to describe the system when access has been restored?
Fail-back
What term is used to describe strategic and tactical errors that an organisation can face whether by performing an action or failure to perform an action?
Errors & Omissions (E&O)
What is Errors & Omissions liability otherwise known as in legal terms?
Professional Liability
What term is used to describe software that typically damages or disables, takes control of, or steals information from a computer system?
Malware
Name 9 common types of malware:
Which type of malware uses pop-up advertising programs?
Adware
Which type of malware uses malicious code that allows an attacker to bypass normal authentication to allow an attacker to gain access to a compromised system?
Backdoor