opexxx icon

CISSP_Notes.txt

opexxx | PRO | 08/23/23 04:44:03 PM UTC (Edited) | 0 ⭐ | 731 👁️ | Never ⏰ | [CISSP, ISC2]
text |

14.58 KB

|

None

|

0 👍

/

0 👎

Always assume Discretionary Access Control (DAC) 
 Always assume a large company (100+) 
 Don’t get wrapped up in US Law (in many countries, in some countries = ignore US law) 
 Example: Reasonable expectation of privacy while using business systems. In US, there is usually no expectation of privacy. In EU, there is an expectation of privacy by law. 
 If they don’t tell you budget is a concern, assume budget is not concern and go with the Cadillac answer 
 Don’t forget about Physical Security (a lot of times a lock and key could be the best answer), Don't forget about availability 
 Take breaks! If you don’t know what a question is asking, try taking a break. 
 When the test asks about 'senior management': Unless told otherwise, assume they mean CEO, CFO, and board of directors. 
 When we talk about accounting, we're talking about writing log entries and holding people accountable. 
 When talking about auditing, we're talking about reading those log entries. 
 When trying to decide between different answers, 1 answer will appeal to sys admin, 1 will appeal to manager. Pick the manager. 
 i.e. if you have multiple answers and 1 says 'do what policy says' that’s going to be the answer. 
 If you come across a question and you think it's an easy win, read it again. It's probably a trick. 
 Be aware of "Answer Bias" 
 If you read a multiple choice question, you have a bias towards A or B and bias against C or D. 
 Overcome by reading answers first, and questions second. 
       General Axioms: 
 Number 1 goal is to protect life 
 Building is on fire, they want you to run into building to get backup tapes. 
 Always assume getting people out of the building is first priority even when stated otherwise. 
 Everyone is responsible for security 
 Janitor with no login is responsible too. After he sweeps server room, he must lock the door behind him. 
 Senior Management is ultimately Responsbile for security 
 CISO is accountable, but senior management is responsible. 
 Senior management writes the security policy, CISO uses that to do their job. 
 If there is a breach CISO is fired, senior management puts another CISO in place. 
 Never spend more for a control than what you are protecting. (Single loss expectancy  * Annual rate of occurance) 
 $500 car that you pay $1500 a year on to protect. Not a good investment. 
 We don’t accept risk, only senior management can accept risk. We advise on what risks to accept. 
 Can't transfer ultimate responsibility, just some of the fallout i.e. financial responsibility 
 If you're reading a network question and it covers layer 1-4, recheck the model. 
 Training and awareness are mandatory. This includes cross-training. 
 Cross-training 
 Staffing for resilience 
 Paper is a media. 
 Consider paper the same way you would a hard drive.  
 Patterns are bad (Cryptography) 
 Senior Management can do whatever they want. 
 Our job is to make sure when they make the decision, they have a basic understanding of the risks. As long as they do, they can make whatever decision they want. 
 IT Security supports the business, not vice versa. 
 If it wasn't this way, we'd just get rid of half the things they do. 
 An attack on availability could be just slowing down the system, rather than knocking it out. 
 Making a system run at degraded speed is a successful attack 
 Digital signatures don't do shit for confidentiality. Only integrity and non-repudiation. 
 No single control can be considered perfect. 
 Does this mean you need multiple or that you should assume each one is inherently flawed? 
 eCommerce = Encryption. 
 If they mention eCommerce, they want you to be aware of you handling credit cards. 
 PCI 
 Requirement 4 = protect data in transit 
 Best way to protect data in transit? Encryption. 
 No way to inspect an encrypted payload 
   Users = Subjects 
 Subject 
 Anything that wants to get to an object. 
   Before a subject can get to an object, it should have a 'referee' i.e. something that grants or denies access. 
 Security kernel 
 Contains rules that allow the referee to make decisions.  
 Audit file 
 Keeps a protected log of all subjects, what objects they accessed and preferably reasoning from the kernel  
     Is this a reference monitor? 
 Can it block a subject from getting to an object? 
 Yes: It is a reference monitor 
 No: it is not a reference monitor. 
   Complete Mediation 
 Even if you've been through the reference monitor a million times and were granted access a million times. You should not circumvent the reference monitor as at a minimum, you want an audit file which the reference monitor will generate. 
  Covert Channel 
 Anything that circumvents a reference monitor. 
 Confidentiality 
 Keeping secrets secret. 
 Enemy of Confidentiality is Disclosure 
 How do you protect confidentiality? 
 Encryption 
 Logical Access control 
 Physical Access Control 
   Integrity 
 Can you trust the data? 
 Has the data been changed? 
 Was it correct when it was collected? 
 Enemy of Integrity is Alteration 
 How do you provide Integrity 
 Hashing 
 Goals of integrity: 
 Stop unauthorized changes from unauthorized subject 
 Threat agents 
 Stop unauthorized changes from authorized subject 
 Mistakes and errors 
 Maintain data consistency  
   Availability 
 Data is available to authorized users when they need it. 
 Enemy of availability is Destruction or downtime 
     D.A.D.D. 
 Enemies of CIA 
 Disclosure 
Alteration 
Destruction/Downtime 
   Risk Appetite 
 How much risk is senior management comfortable taking on in the organization? 
     CISO 
 Manage security infrastructure 
 Metrics - If you can't measure it, you can't improve it. 
 Advise Senior management on security risks 
   Metrics 
 Comes from 2 places 
 Measurement Variation 
 Don’t change the way you're measuring. Stay consistent to see trends over time. 
 Process variation 
 The actual variation that is happening in the process 
     Policy 
 Brief, high-level statement 
 "Policy should never be longer than 2 pages" 
 Don't leave policy up for interpretation.  
 e.g. "We will be HIPAA compliant." 
   Standards 
 "Bulleted list" 
   Procedures 
 "Numbered list" 
   Baselines 
 Minimum security configuration for different systems. 
 Senior management is responsible for establishing baselines. 
 Baseline info may be collected from vendors, open standards, etc. 
   Scoping 
 Go through everything a baseline talks about, decide what works and what doesn’t. 
 Armed guards are too much for us, but security cameras is a good fit. 
 Tailoring 
 Make the baseline specific to your business. 
 16 cameras, 8 inside, 8 outside. 
     Guidelines 
 Generalized ideas on how management would expect something to be completed that may not have a set of standards/procedures/baselines in existence 
     Governance leads into Compliance leads into Assurance 
   Due Dilligence 
 Making the rules 
 What would any reasonably prudent person do? "Prudent person rule" 
 An individual should make every effort to complete his or her responsibilities in an accurate and timely manner 
 Due Care 
 Everyone following the rules 
  Superficial Security Frameworks: 
   ITIL - Information Technology Infrastructure Library 
 Continual Service Improvement 
   COSO - Committee of sponsoring organizations 
 All about financial Fraud 
   COBIT - Control objectives for Information and related Technologies 
 Developed by ISACA 
 Auditors use this to define what controls you should have 
         Real Security Frameworks 
   ISO 27000 
 ISO/IEC 27000 
 General Overview 
   Information security management systems 
 Overview and vocabulary 
   ISO/IEC 27001  
 Actual standard, includes ISMS and Requirements 
   Information technology - Security Techniques - Information security management systems 
 Requirements. The 2013 release of the standard specifies an information security management system in the same formalized, structured and succinct manner as other ISO standards specify other kinds of management systems. 
   ISO/IEC 27002  
 Listing of example controls that could be used to meet 27001 requirements 
   Code of practice for information security controls 
 essentially a detailed catalog of information security controls that might be managed through the ISMS 
   ISO/IEC 27003 
 Information security management system implementation guidance 
   ISO/IEC 27004  
 Guidelines for metrics 
 Information security management 
 Monitoring, measurement, analysis and evaluation 
   ISO/IEC 27005  
 Information security risk management 
 (NIST SP800-39) 
   ISO/IEC 27006   
 Requirements for bodies providing audit and certification of information security management systems 
   ISO 22301 
 Information technology -- Security techniques -- Guidelines for information and communication technology readiness for business continuity 
   NIST SP-800 
 US Specific 
 Not as heavily placed into the CISSP test any more as the test is meant to be 'international' 
       Compliance Frameworks 
   PCI-DSS 
 Actual Standard: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf 
 Review requirements 1-12 and Appendix A 
   Only applies to organizations that do business directly with members of the PCI council. (i.e. VISA, MasterCard, Discover, etc.) 
   PCI is not a law, it is a contract. 
   PAN - Primary Account Number 
 Credit Card Number, Expiration Date, CVV 
   Tokenization 
 Replace confidential information with placeholders for identification ("tokens") 
 e.g. replace the credit card number of "0000-0000-0000-000" with "Token-CreditCard-1" 
   QSA - Qualified Security Assessor 
 PCI Auditors 
    Business Impact Analysis: BIA
========================
 Gather Info 
 What all things do you do? 
 Identify what's critical 
 Map relationships between critical items and dependencies 
 "Doing the math" 
 Calculate "MTD" Maximum Tolerable Downtime 
 Calculate "RTO" - recovery time objective 
 Amount of time required to recover 
 Can be split into 2 parts. 
 Part 1 - RTO "amount of time to order a part" 
 Part 2 -  'WRT' Work Recovery Time "amount of time to install the ordered parts 
 Calculate "RPO" - Recovery Point objective 
 If a problem is encountered, how much date/time are you able to lose? i.e. If you backups are every 24 hours, your RPO should say you're willing to lose up to 24 hours of data if you were to restore to the last backup. 
 Perform Cost/Benefit analysis  
 Develop continuity plans 
 Perform cost/benefit analysis 
    usiness Continuity - Disaster Recovery - Incident Response 
   Means different things in practice, for this week and this week, consider these as completely separate islands. 
     Business continuity. 
 Critical Business functions, plans to get them back online fast enough. 
   Disaster recovery 
 When an incident is SO BAD that you had to 'move' 
   Incident Response 
     What's considered critical? 
 Whatever senior management says is critical 
 Whatever keeps the cash register ringing 
   What's considered not critical 
 Anything that doesn’t stop the cash register from ringing. 
     Business  Continuity Plan 
 Perform "BIA" - business impact assessment 
 No discussion of probability. Only impact 
 BIA Plans -> pick an output 
 Put plans into place 
    Risk Assessments 
 3 main steps 
 Identification 
 Risk analysis 
 Risk assessment 
 Qualitative Assessment 
 Measurement of impact and likelihood. 
 Low -> Medium -> High 
      Quantitative Risk Assessment 
 Annualized Loss Expectency (ALE) = Annual Rate of Occurance (ARO) * Single Loss Expectancy (SLE) 
 Single Loss Expectancy (SLE) = Asset Value (AV) * Exposure Factor (EF) 
   ALE = ARO * (AV*EF) 
     Terms: 
 Annualized Rate of Occurance (ARO) 
 How many times per year a risk is expected to be realized. 
 Single Loss Expectancy 
 Amount of money expected to be lost when a risk is realized. 
 Asset Value 
 In real life to determine value of an asset, hire a consultant 
 "Test will likely give you the asset value" 
 Exposure Factor 
 Percentage of the asset's value that would be compromised if a risk is realized 
     Example: 
 Building burns to the ground. 
   ARO = .01 (likely to happen once every 100 years) 
 AV = 200,000 (building, all items inside, land the building sits on) 
 EF = 75% (only 75% because 25% of the asset's value is land, which would not be affected by the building burning down) 
   SLE = 200,000 * 0.75 = 150,000 
 ALE = .01 * 150,000 = $1,500 
     If insurance guy comes back saying fire insurance is $1000/year 
 In scenario you are paying $1000 to save $1500.  
 ROI = (Amount your saving - cost of control)/cost of control 
 ROI = (1500-1000)/1000 
 ROI = 50% 
  Risk Treatments 
   Acceptance 
 Accept the risk as a cost of doing business without necessarily doing anything 
   Avoidance 
 Don't do the ting that causes risk 
 look for alternatives to achieve same goal 
   Transference 
 Pay someone else to be liable for the financial impact 
 Ultimate responsibility stays with senior management 
   Mitigation  
 Invest in solutions to address the risk and hopefully prevent it. 
 Address probability or impact 
 Safeguards 
 Reduces probability 
 Countermeasures 
 Reduces impact 
   Risk Rejection 
 Stick your head in the sand 
 If you don’t know that you've been breached, due care is not required. 
     Control Types "3 slice pie" : 
 Administrative 
Policy/Rules 
  Technical/Logical 
Software 
  Physical 
If you can touch it 
   Control Categories"7 slice pie" 
   ----- pre-incident ------ 
   Directive 
 Policies on work computer, supervisor instruction 
 Safeguard 
   Deterrent 
 Discourages you from trying 
 Safeguard 
   Preventative 
 Stops you even if you try 
 Safeguard 
   ------ post incident ------- 
   Detective 
 Can alert you if an incident occurs 
 Countermeasure 
   Corrective 
 First containment and/or eradication 
 Stops the bleeding 
 Countermeasure 
   Recovery 
 Resumes normal operation 
 Countermeasure 
   Compensating 
 Put in place in the absence of another control 

Comments