Domain 2 · 10% of the exam
Asset Security
Security professionals must understand the importance of asset security and the different measures that can be used to protect assets throughout their life cycle. This includes not only technical controls but also physical security measures, disaster recovery planning, and privacy considerations.
Progress saved on this device
22 lessons · 87 slides · 39 min read
Learning objectives
- Identify, classify, and categorize information assets.
- Explain the importance of treating information as an asset.
- Differentiate the IT asset management lifecycle from the data security lifecycle.
- Relate the data states of in use, in transit, and at rest to the data lifecycle.
- Relate the different roles that people and organizations have with respect to data.
- Describe the different security control types and categories.
- Explain the use of data security standards and baselines to meet organizational compliance requirements.
Key topics
- Provision Information & Assets Securely
- Information & Asset Handling
- Manage Data Life Cycle
- Appropriate Asset Retention
- Data Security Controls & Compliance
Lessons
- 01Data Remanence - DefinitionData remanence is defined as the residual data remaining on some sort of object after the data has been deleted or erased.1 min
- 02Data RetentionInformation and data should be kept only for as long as it is required, no more, and no less. For various types of data, certain industry standards, laws and regulations define retention periods, when such external requirements are not set, it is the…1 min
- 03Data in TransitData in transit refers to data that is actively being transmitted from one location to another, typically across a network or the internet.2 min
- 04Data in Transit - Description of Risk and RecommendationsThe risks associated with data in motion are the same as those associated with data at rest. These include:2 min
- 05Data MaintenanceThroughout its life cycle, data is accessed, viewed, processed, or used in various ways. Maintaining the confidentiality, integrity and availability of the data is key in maintaining the data and its intended purposes. Data maintenance requires…1 min
- 06Baseline (USGCB) and Baseline Security System ISKEF00001 min
- 07Scoping and TailoringWhen choosing to implement security frameworks, baselines, or standards, organizations may decide to implement only specific parts through the process of scoping and tailoring.2 min
- 08Data at RestData at rest refers to information that is not being actively processed or transmitted and that is stored on a persistent storage medium.1 min
- 09Standards SelectionOrganizations use security standards to assess security programs and risks, improve defenses, and meet regulatory requirements across various industries and jurisdictions.1 min
- 10Generally Accepted PrinciplesThis section introduces some generally accepted principles that address information security from a high-level viewpoint that can provide comprehensive guidance to organizations.2 min
- 11Information Asset InventoryData or information assets are considered intangible sets of ideas, numbers, values, or relationships that are the lifeblood of the digital organization.4 min
- 12Link and End-to-End EncryptionData are encrypted on a network using either link or end-to-end encryption. In general, link encryption is performed by service providers, such as a data communications provider on a frame relay network. Link encryption encrypts all the data along a…1 min
- 13Data CollectionData collection is the first step in the data life cycle. This step includes the creation and acquisition of new content and the update of existing content.1 min
- 14End of Life and End of SupportEnd of life and end of support for IT systems is generally discussed in terms of the hardware, software, and business processes that have to be either decommissioned, replaced, or taken on as technological orphans and supported with in-house resources.2 min
- 15Data LocationWAZ TVRZ TAW/1 min
- 16Case Study - Facebook and Cambridge AnalyticaCase studyThe Cambridge Analytica scandal, which unfolded in 2018, marked a significant privacy breach with global ramifications. At the core of the incident was the unauthorized access and exploitation of personal data from approximately 87 million Facebook users.2 min
- 17Possible Responses (Case Study - Facebook and Cambridge Analytica)Case study answersPossible Responses (Case Study: Facebook and Cambridge Analytica)1 min
- 18The Data Security Life CycleAll ideas, data, information, or knowledge can be thought of as going through six major sets of activities throughout its lifetime.4 min
- 19Case Study - SolarwindsCase studyThe Solar Winds cyberattack, discovered in December 2020, was a sophisticated supply chain attack that targeted the Solar Winds Orion software, a widely used IT infrastructure monitoring and management tool.2 min
- 20Classification and CategorizationOnce we have an inventory of assets, understanding the value of those assets becomes the next step as it will drive asset classification, which, in turn, will drive the protection of those assets throughout their life cycle.2 min
- 21Information Asset OwnershipAn information asset is data with value to the organization, and identifying an asset owner ensures accountability for protection and proper maintenance.2 min
- 22Data Classification and Categorization PolicyA data classification and categorization policy is a formal set of guidelines for categorizing data, defining handling procedures, and assigning roles and responsibilities.3 min
