前往小程序,Get更优阅读体验!
立即前往
首页
学习
活动
专区
工具
TVP
发布
社区首页 >专栏 >CISSP考试指南笔记:5.8 物理/逻辑访问的控制

CISSP考试指南笔记:5.8 物理/逻辑访问的控制

作者头像
血狼debugeeker
发布2021-03-02 10:51:19
2970
发布2021-03-02 10:51:19
举报
文章被收录于专栏:debugeeker的专栏

Access Control Layers


Administrative controls:

  • Policy and procedures
  • Personnel controls
  • Supervisory structure
  • Security-awareness training
  • Testing

Physical controls:

  • Network segregation
  • Perimeter security
  • Computer controls
  • Work area separation
  • Data backups
  • Cabling
  • Control zone

Technical controls:

  • System access
  • Network architecture
  • Network access
  • Encryption and protocols
  • Auditing

Administrative Controls


The first piece to building a security foundation within an organization is a security policy. It is management’s responsibility to construct a security policy and delegate the development of the supporting procedures, standards, and guidelines; indicate which personnel controls should be used; and specify how testing should be carried out to ensure all pieces fulfill the company’s security goals. These items are administrative controls and work at the top layer of a hierarchical access control model.

Personnel Controls

Personnel controls indicate how employees are expected to interact with security mechanisms and address noncompliance issues pertaining to these expectations.

Supervisory Structure

Management must construct a supervisory structure in which each employee has a superior to report to, and that superior is responsible for that employee’s actions.

Security-Awareness Training

A company’s security depends upon technology and people, and people are usually the weakest link and cause the most security breaches and compromises.

Testing

All security controls, mechanisms, and procedures must be tested on a periodic basis to ensure they properly support the security policy, goals, and objectives set for them.

剩余内容请看本人公众号debugeeker, 链接为CISSP考试指南笔记:5.8 物理/逻辑访问的控制

本文参与 腾讯云自媒体同步曝光计划,分享自作者个人站点/博客。
原始发表:2021/02/23 ,如有侵权请联系 cloudcommunity@tencent.com 删除

本文分享自 作者个人站点/博客 前往查看

如有侵权,请联系 cloudcommunity@tencent.com 删除。

本文参与 腾讯云自媒体同步曝光计划  ,欢迎热爱写作的你一起参与!

评论
登录后参与评论
0 条评论
热度
最新
推荐阅读
目录
  • Access Control Layers
  • Administrative Controls
    • Personnel Controls
      • Supervisory Structure
        • Security-Awareness Training
          • Testing
          领券
          问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档