Domain 2 · 10% of the exam
Asset Security
Security professionals must understand the importance of asset security and the different measures that can be used to protect assets throughout their life cycle. This includes not only technical controls but also physical security measures, disaster recovery planning, and privacy considerations.
Learning objectives
- Identify, classify, and categorize information assets.
- Explain the importance of treating information as an asset.
- Differentiate the IT asset management lifecycle from the data security lifecycle.
- Relate the data states of in use, in transit, and at rest to the data lifecycle.
- Relate the different roles that people and organizations have with respect to data.
- Describe the different security control types and categories.
- Explain the use of data security standards and baselines to meet organizational compliance requirements.
Key topics
- Provision Information & Assets Securely
- Information & Asset Handling
- Manage Data Life Cycle
- Appropriate Asset Retention
- Data Security Controls & Compliance
Lessons
Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.
- 01Data Remanence - DefinitionData remanence is defined as the residual data remaining on some sort of object after the data has been deleted or erased.2 slides · 1 min read
- 02Data RetentionInformation and data should be kept only for as long as it is required, no more, and no less. For various types of data, certain industry standards, laws and regulations define retention periods, when such external requirements are not set, it is the…4 slides · 1 min read
- 03Data in TransitData in transit refers to data that is actively being transmitted from one location to another, typically across a network or the internet.5 slides · 2 min read
- 04Data in Transit - Description of Risk and RecommendationsThe risks associated with data in motion are the same as those associated with data at rest. These include:3 slides · 2 min read
- 05Data MaintenanceThroughout its life cycle, data is accessed, viewed, processed, or used in various ways. Maintaining the confidentiality, integrity and availability of the data is key in maintaining the data and its intended purposes. Data maintenance requires…3 slides · 1 min read
- 06Baseline (USGCB) and Baseline Security System ISKEF00002 slides · 1 min read
- 07Scoping and TailoringWhen choosing to implement security frameworks, baselines, or standards, organizations may decide to implement only specific parts through the process of scoping and tailoring.3 slides · 2 min read
- 08Data at RestData at rest refers to information that is not being actively processed or transmitted and that is stored on a persistent storage medium.3 slides · 1 min read
- 09Standards SelectionOrganizations use security standards to assess security programs and risks, improve defenses, and meet regulatory requirements across various industries and jurisdictions.2 slides · 1 min read
- 10Generally Accepted PrinciplesThis section introduces some generally accepted principles that address information security from a high-level viewpoint that can provide comprehensive guidance to organizations.5 slides · 2 min read
- 11Information Asset InventoryData or information assets are considered intangible sets of ideas, numbers, values, or relationships that are the lifeblood of the digital organization.5 slides · 4 min read
- 12Link and End-to-End EncryptionData are encrypted on a network using either link or end-to-end encryption. In general, link encryption is performed by service providers, such as a data communications provider on a frame relay network. Link encryption encrypts all the data along a…4 slides · 1 min read
- 13Data CollectionData collection is the first step in the data life cycle. This step includes the creation and acquisition of new content and the update of existing content.3 slides · 1 min read
- 14End of Life and End of SupportEnd of life and end of support for IT systems is generally discussed in terms of the hardware, software, and business processes that have to be either decommissioned, replaced, or taken on as technological orphans and supported with in-house resources.3 slides · 2 min read
- 15Data LocationWAZ TVRZ TAW/3 slides · 1 min read
- 16Case Study - Facebook and Cambridge AnalyticaCase studyThe Cambridge Analytica scandal, which unfolded in 2018, marked a significant privacy breach with global ramifications. At the core of the incident was the unauthorized access and exploitation of personal data from approximately 87 million Facebook users.4 slides · 2 min read
- 17Possible Responses (Case Study - Facebook and Cambridge Analytica)Case study answersPossible Responses (Case Study: Facebook and Cambridge Analytica)3 slides · 1 min read
- 18The Data Security Life CycleAll ideas, data, information, or knowledge can be thought of as going through six major sets of activities throughout its lifetime.9 slides · 4 min read
- 19Case Study - SolarwindsCase studyThe Solar Winds cyberattack, discovered in December 2020, was a sophisticated supply chain attack that targeted the Solar Winds Orion software, a widely used IT infrastructure monitoring and management tool.5 slides · 2 min read
- 20Classification and CategorizationOnce we have an inventory of assets, understanding the value of those assets becomes the next step as it will drive asset classification, which, in turn, will drive the protection of those assets throughout their life cycle.9 slides · 2 min read
- 21Information Asset OwnershipAn information asset is data with value to the organization, and identifying an asset owner ensures accountability for protection and proper maintenance.3 slides · 2 min read
- 22Data Classification and Categorization PolicyA data classification and categorization policy is a formal set of guidelines for categorizing data, defining handling procedures, and assigning roles and responsibilities.4 slides · 3 min read
