Introduction |
|
1 | (2) |
|
Part I Security Architecture |
|
|
|
Chapter 1 Ensuring a Secure Network Architecture |
|
|
3 | (70) |
|
|
3 | (1) |
|
|
3 | (1) |
|
Intrusion Detection System (IDS)/Network Intrusion Detection System (NIDS)/Wireless Intrusion Detection System (WIDS) |
|
|
3 | (3) |
|
Intrusion Prevention System (IPS)/Network Intrusion Prevention System (NIPS)/Wireless Intrusion Prevention System (WIPS) |
|
|
6 | (1) |
|
Web Application Firewall (WAF) |
|
|
6 | (2) |
|
Network Access Control (NAC) |
|
|
8 | (1) |
|
|
9 | (1) |
|
Persistent/Volatile or Non-persistent Agent |
|
|
9 | (1) |
|
|
9 | (1) |
|
Virtual Private Network (VPN) |
|
|
10 | (1) |
|
Domain Name System Security Extensions (DNSSEC) |
|
|
11 | (1) |
|
Firewall/Unified Threat Management (UTM)/Next-Generation Firewall (NGFW) |
|
|
11 | (1) |
|
|
12 | (2) |
|
Next-Generation Firewalls (NGFWs) |
|
|
14 | (1) |
|
|
15 | (4) |
|
|
19 | (1) |
|
Network Address Translation (NAT) Gateway |
|
|
19 | (1) |
|
|
20 | (1) |
|
|
21 | (1) |
|
|
21 | (1) |
|
Forward/Transparent Proxy |
|
|
21 | (1) |
|
|
22 | (1) |
|
Distributed Denial-of-Service (DDoS) Protection |
|
|
22 | (1) |
|
|
22 | (1) |
|
|
23 | (2) |
|
Additional Route Protection |
|
|
25 | (1) |
|
|
26 | (1) |
|
|
26 | (1) |
|
|
27 | (1) |
|
|
27 | (1) |
|
|
27 | (1) |
|
|
28 | (1) |
|
|
28 | (1) |
|
|
28 | (1) |
|
|
29 | (1) |
|
Disclosure of Information |
|
|
30 | (1) |
|
|
30 | (1) |
|
Application Programming Interface (API) Gateway/Extensible Markup Language (XML) Gateway |
|
|
30 | (1) |
|
|
30 | (1) |
|
Switched Port Analyzer (SPAN) Ports |
|
|
31 | (1) |
|
|
31 | (1) |
|
Virtual Private Cloud (VPC) |
|
|
32 | (1) |
|
|
32 | (1) |
|
|
32 | (1) |
|
Security Information and Event Management (SIEM) |
|
|
33 | (2) |
|
File Integrity Monitoring (FIM) |
|
|
35 | (1) |
|
Simple Network Management Protocol (SNMP) Traps |
|
|
36 | (1) |
|
|
36 | (1) |
|
Data Loss Prevention (DLP) |
|
|
37 | (2) |
|
|
39 | (1) |
|
|
39 | (1) |
|
|
40 | (1) |
|
Local Area Network (LAN)/Virtual Local Area Network (VLAN) |
|
|
40 | (3) |
|
|
43 | (1) |
|
|
44 | (1) |
|
|
44 | (1) |
|
|
45 | (1) |
|
|
45 | (1) |
|
VPC/Virtual Network (VNET) |
|
|
45 | (1) |
|
|
46 | (1) |
|
|
47 | (1) |
|
|
47 | (2) |
|
|
49 | (1) |
|
Access Control Lists (ACLs) |
|
|
49 | (1) |
|
|
49 | (1) |
|
|
49 | (1) |
|
De-perimeterizarion/Zero Trust |
|
|
49 | (1) |
|
|
50 | (1) |
|
|
50 | (1) |
|
|
50 | (2) |
|
Outsourcing and Contracting |
|
|
52 | (1) |
|
Wireless/Radio Frequency (RF) Networks |
|
|
53 | (1) |
|
|
53 | (1) |
|
|
54 | (2) |
|
|
56 | (2) |
|
Merging of Networks from Various Organizations |
|
|
58 | (1) |
|
|
59 | (1) |
|
|
59 | (1) |
|
|
59 | (1) |
|
|
60 | (1) |
|
|
61 | (1) |
|
|
61 | (1) |
|
|
61 | (1) |
|
Software-Defined Networking (SDN) |
|
|
62 | (1) |
|
|
63 | (1) |
|
|
64 | (1) |
|
|
64 | (2) |
|
|
66 | (1) |
|
|
66 | (2) |
|
|
68 | (1) |
|
Complete Tables and Lists from Memory |
|
|
69 | (1) |
|
|
69 | (4) |
|
Chapter 2 Determining the Proper Infrastructure Security Design |
|
|
73 | (12) |
|
|
73 | (1) |
|
|
73 | (1) |
|
|
74 | (1) |
|
|
74 | (1) |
|
High Availability/Redundancy |
|
|
74 | (1) |
|
|
75 | (1) |
|
Course of Action Orchestration |
|
|
75 | (1) |
|
|
76 | (1) |
|
|
76 | (1) |
|
|
76 | (1) |
|
|
76 | (1) |
|
|
76 | (1) |
|
Security Orchestration, Automation, and Response (SOAR) |
|
|
77 | (1) |
|
|
77 | (1) |
|
|
77 | (1) |
|
|
78 | (1) |
|
|
79 | (1) |
|
|
79 | (1) |
|
|
80 | (1) |
|
|
81 | (1) |
|
|
81 | (1) |
|
|
81 | (1) |
|
Complete Tables and Lists from Memory |
|
|
81 | (1) |
|
|
82 | (3) |
|
Chapter 3 Securely Integrating Software Applications |
|
|
85 | (40) |
|
|
85 | (1) |
|
|
85 | (1) |
|
Create Benchmarks and Compare to Baselines |
|
|
85 | (1) |
|
|
86 | (1) |
|
Secure Design Patterns/Types of Web Technologies |
|
|
87 | (1) |
|
|
87 | (1) |
|
|
88 | (1) |
|
|
89 | (1) |
|
|
90 | (1) |
|
|
90 | (1) |
|
|
90 | (1) |
|
Application Vetting Processes |
|
|
90 | (1) |
|
|
91 | (1) |
|
|
91 | (1) |
|
|
92 | (1) |
|
Sandboxing/Development Environment |
|
|
92 | (1) |
|
Validating Third-Party Libraries |
|
|
93 | (1) |
|
|
93 | (1) |
|
|
94 | (1) |
|
Interactive Application Security Testing (IAST) vs. Dynamic Application Security Testing (DAST) vs. Static Application Security Testing (SAST) |
|
|
95 | (1) |
|
Interactive Application Security Testing (IAST) |
|
|
95 | (1) |
|
Static Application Security Testing (SAST) |
|
|
95 | (1) |
|
Dynamic Application Security Testing (DAST) |
|
|
95 | (1) |
|
|
95 | (1) |
|
|
95 | (3) |
|
|
98 | (1) |
|
|
98 | (1) |
|
|
99 | (1) |
|
|
99 | (1) |
|
|
100 | (1) |
|
Considerations of Integrating Enterprise Applications |
|
|
100 | (1) |
|
Customer Relationship Management (CRM) |
|
|
100 | (1) |
|
Enterprise Resource Planning (ERP) |
|
|
100 | (1) |
|
Configuration Management Database (CMDB) |
|
|
101 | (1) |
|
Content Management System (CMS) |
|
|
101 | (1) |
|
|
101 | (1) |
|
|
101 | (1) |
|
|
101 | (1) |
|
Service-Oriented Architecture (SOA) |
|
|
102 | (1) |
|
Enterprise Service Bus (ESB) |
|
|
103 | (1) |
|
Integrating Security into Development Life Cycle |
|
|
103 | (1) |
|
|
103 | (1) |
|
|
103 | (1) |
|
|
104 | (1) |
|
|
104 | (1) |
|
|
104 | (1) |
|
|
105 | (2) |
|
Validation and Acceptance Testing |
|
|
107 | (1) |
|
|
107 | (1) |
|
|
107 | (2) |
|
|
109 | (1) |
|
|
109 | (1) |
|
|
109 | (2) |
|
|
111 | (1) |
|
Security Implications of Agile Software Development |
|
|
112 | (1) |
|
Security Implications of the Waterfall Model |
|
|
113 | (1) |
|
Security Implications of the Spiral Model |
|
|
114 | (1) |
|
|
114 | (2) |
|
Continuous Integration/Continuous Delivery (CI/CD) Pipelines |
|
|
116 | (1) |
|
|
117 | (1) |
|
Open Web Application Security Project (OWASP) |
|
|
117 | (1) |
|
Proper Hypertext Transfer Protocol (HTTP) Headers |
|
|
117 | (2) |
|
|
119 | (1) |
|
|
119 | (1) |
|
|
120 | (1) |
|
Complete Tables and Lists from Memory |
|
|
121 | (1) |
|
|
121 | (4) |
|
Chapter 4 Securing the Enterprise Architecture by Implementing Data Security |
|
|
|
|
125 | (1) |
|
|
125 | (1) |
|
Blocking Use of External Media |
|
|
125 | (1) |
|
|
126 | (1) |
|
Remote Desktop Protocol (RDP) Blocking |
|
|
126 | (1) |
|
Clipboard Privacy Controls |
|
|
127 | (1) |
|
Restricted Virtual Desktop Infrastructure (VDI) Implementation |
|
|
128 | (1) |
|
Data Classification Blocking |
|
|
128 | (1) |
|
|
129 | (1) |
|
|
129 | (1) |
|
Digital Rights Management (DRM) |
|
|
129 | (1) |
|
Network Traffic Decryption/Deep Packet Inspection |
|
|
130 | (1) |
|
|
130 | (1) |
|
Data Classification, Labeling, and Tagging |
|
|
130 | (1) |
|
|
130 | (1) |
|
|
130 | (1) |
|
|
131 | (1) |
|
|
131 | (1) |
|
|
131 | (1) |
|
|
131 | (1) |
|
|
132 | (1) |
|
|
132 | (1) |
|
Encrypted vs. Unencrypted |
|
|
132 | (1) |
|
|
132 | (1) |
|
|
132 | (1) |
|
|
133 | (1) |
|
|
133 | (1) |
|
|
133 | (1) |
|
|
133 | (1) |
|
Data Inventory and Mapping |
|
|
133 | (1) |
|
Data Integrity Management |
|
|
134 | (1) |
|
Data Storage, Backup, and Recovery |
|
|
134 | (4) |
|
Redundant Array of Inexpensive Disks (RAID) |
|
|
138 | (5) |
|
|
143 | (1) |
|
|
143 | (1) |
|
|
144 | (1) |
|
Complete Tables and Lists from Memory |
|
|
144 | (1) |
|
|
144 | (5) |
|
Chapter 5 Providing the Appropriate Authentication and Authorization Controls |
|
|
149 | (36) |
|
|
149 | (1) |
|
Password Repository Application |
|
|
149 | (1) |
|
End - User Password Storage |
|
|
149 | (1) |
|
On Premises vs. Cloud Repository |
|
|
150 | (1) |
|
|
150 | (1) |
|
Privileged Access Management |
|
|
151 | (1) |
|
|
151 | (1) |
|
|
151 | (2) |
|
|
153 | (1) |
|
|
153 | (1) |
|
|
153 | (1) |
|
|
154 | (1) |
|
|
154 | (1) |
|
|
155 | (1) |
|
|
156 | (1) |
|
|
156 | (1) |
|
|
156 | (1) |
|
|
156 | (1) |
|
Security Assertion Markup Language (SAML) |
|
|
157 | (1) |
|
|
158 | (1) |
|
|
159 | (1) |
|
Mandatory Access Control (MAC) |
|
|
160 | (1) |
|
Discretionary Access Control (DAC) |
|
|
160 | (1) |
|
Role-Based Access Control |
|
|
161 | (1) |
|
Rule-Based Access Control |
|
|
161 | (1) |
|
Attribute-Based Access Control |
|
|
161 | (1) |
|
|
162 | (1) |
|
Remote Authentication Dial-in User Service (RADIUS) |
|
|
162 | (1) |
|
Terminal Access Controller Access Control System (TACACS) |
|
|
163 | (1) |
|
|
164 | (1) |
|
Lightweight Directory Access Protocol (LDAP) |
|
|
164 | (1) |
|
|
165 | (1) |
|
|
166 | (1) |
|
|
166 | (1) |
|
Extensible Authentication Protocol (EAP) |
|
|
167 | (1) |
|
Multifactor Authentication (MFA) |
|
|
168 | (1) |
|
|
169 | (1) |
|
|
169 | (1) |
|
|
170 | (1) |
|
Physiological Characteristics |
|
|
170 | (1) |
|
Behavioral Characteristics |
|
|
171 | (1) |
|
|
172 | (1) |
|
|
173 | (1) |
|
|
174 | (1) |
|
|
174 | (1) |
|
|
175 | (1) |
|
HMAC-Based One-Time Password (HOTP) |
|
|
175 | (1) |
|
Time-Based One-Time Password (TOTP) |
|
|
175 | (1) |
|
|
176 | (2) |
|
JavaScript Object Notation (JSON) Web Token (JWT) |
|
|
178 | (1) |
|
Attestation and Identity Proofing |
|
|
179 | (2) |
|
|
181 | (1) |
|
|
181 | (4) |
|
Chapter 6 Implementing Secure Cloud and Virtualization Solutions |
|
|
185 | (18) |
|
|
177 | (3) |
|
|
180 | (1) |
|
|
180 | (5) |
|
Virtualization Strategies |
|
|
185 | (1) |
|
Type 1 vs. Type 2 Hypervisors |
|
|
186 | (1) |
|
|
186 | (1) |
|
|
187 | (1) |
|
|
187 | (1) |
|
|
188 | (1) |
|
Application Virtualization |
|
|
189 | (1) |
|
|
189 | (1) |
|
Provisioning and Deprovisioning |
|
|
189 | (1) |
|
|
190 | (1) |
|
|
190 | (1) |
|
Deployment Models and Considerations |
|
|
190 | (1) |
|
|
191 | (1) |
|
|
191 | (1) |
|
|
191 | (1) |
|
|
191 | (1) |
|
|
191 | (1) |
|
|
192 | (1) |
|
|
192 | (1) |
|
|
193 | (1) |
|
|
193 | (1) |
|
|
193 | (1) |
|
|
193 | (1) |
|
|
193 | (1) |
|
|
193 | (1) |
|
|
194 | (1) |
|
|
194 | (1) |
|
Software as a Service (SaaS) |
|
|
194 | (1) |
|
Platform as a Service (PaaS) |
|
|
194 | (1) |
|
Infrastructure as a Service (IaaS) |
|
|
195 | (1) |
|
Cloud Provider Limitations |
|
|
196 | (1) |
|
Internet Protocol (IP) Address Scheme |
|
|
196 | (1) |
|
|
196 | (1) |
|
Extending Appropriate On-premises Controls |
|
|
196 | (1) |
|
|
196 | (1) |
|
Object Storage/File-Based Storage |
|
|
197 | (1) |
|
|
197 | (1) |
|
|
198 | (1) |
|
|
198 | (1) |
|
|
198 | (1) |
|
|
199 | (1) |
|
|
199 | (1) |
|
|
199 | (1) |
|
Complete Tables and Lists from Memory |
|
|
200 | (1) |
|
|
200 | (3) |
|
Chapter 7 Supporting Security Objectives and Requirements with Cryptography and Public Key Infrastructure (PKI) |
|
|
203 | (16) |
|
Privacy and Confidentiality Requirements |
|
|
203 | (1) |
|
|
204 | (1) |
|
|
204 | (1) |
|
Compliance and Policy Requirements |
|
|
204 | (1) |
|
Common Cryptography Use Cases |
|
|
205 | (1) |
|
|
205 | (1) |
|
|
205 | (1) |
|
Data in Process/Data in Use |
|
|
205 | (1) |
|
Protection of Web Services |
|
|
206 | (1) |
|
|
206 | (1) |
|
|
207 | (2) |
|
|
209 | (1) |
|
Elliptic Curve Cryptography |
|
|
209 | (1) |
|
|
209 | (1) |
|
|
209 | (1) |
|
|
209 | (1) |
|
|
210 | (1) |
|
|
210 | (1) |
|
|
210 | (1) |
|
|
211 | (1) |
|
|
211 | (1) |
|
|
211 | (1) |
|
|
212 | (1) |
|
|
212 | (1) |
|
|
212 | (1) |
|
Other Tunneling Protocols |
|
|
213 | (1) |
|
Enterprise and Security Automation/Orchestration |
|
|
213 | (1) |
|
|
214 | (1) |
|
|
214 | (1) |
|
|
214 | (1) |
|
Complete Tables and Lists from Memory |
|
|
214 | (1) |
|
|
215 | (4) |
|
Chapter 8 Managing the Impact of Emerging Technologies on Enterprise Security and Privacy |
|
|
219 | (12) |
|
|
219 | (1) |
|
|
220 | (1) |
|
|
220 | (1) |
|
|
220 | (1) |
|
|
221 | (1) |
|
Secure Multiparty Computation |
|
|
221 | (1) |
|
Private Information Retrieval |
|
|
221 | (1) |
|
Secure Function Evaluation |
|
|
221 | (1) |
|
Private Function Evaluation |
|
|
221 | (1) |
|
|
221 | (1) |
|
|
222 | (1) |
|
Virtual/Augmented Reality |
|
|
223 | (1) |
|
|
224 | (1) |
|
Passwordless Authentication |
|
|
224 | (1) |
|
|
225 | (1) |
|
|
225 | (1) |
|
Natural Language Processing |
|
|
225 | (1) |
|
|
226 | (1) |
|
|
226 | (1) |
|
|
227 | (1) |
|
|
227 | (1) |
|
|
227 | (1) |
|
Complete Tables and Lists from Memory |
|
|
227 | (1) |
|
|
228 | (3) |
|
Part II Security Operations |
|
|
|
Chapter 9 Performing Threat Management Activities |
|
|
231 | (20) |
|
|
231 | (1) |
|
|
231 | (1) |
|
|
231 | (1) |
|
|
232 | (1) |
|
|
232 | (1) |
|
|
232 | (1) |
|
|
232 | (1) |
|
|
233 | (1) |
|
|
233 | (1) |
|
Advanced Persistent Threat (APT)/Nation-State |
|
|
233 | (1) |
|
|
234 | (1) |
|
|
234 | (1) |
|
|
234 | (1) |
|
|
235 | (1) |
|
|
235 | (1) |
|
|
235 | (1) |
|
|
235 | (1) |
|
|
235 | (1) |
|
|
235 | (1) |
|
|
235 | (1) |
|
|
236 | (1) |
|
Capabilities/Sophistication |
|
|
236 | (1) |
|
|
237 | (1) |
|
Intelligence Collection Methods |
|
|
237 | (1) |
|
|
237 | (1) |
|
|
237 | (1) |
|
|
238 | (1) |
|
Open-Source Intelligence (OSINT) |
|
|
238 | (1) |
|
|
238 | (1) |
|
Intelligence Collection Methods |
|
|
239 | (1) |
|
|
239 | (1) |
|
|
239 | (3) |
|
|
242 | (1) |
|
Human Intelligence (HUMINT) |
|
|
243 | (1) |
|
|
243 | (1) |
|
MITRE Adversarial Tactics, Techniques, & Common Knowledge (ATT&CK) |
|
|
243 | (2) |
|
ATT&CK for Industrial Control System (ICS) |
|
|
245 | (1) |
|
Diamond Model of Intrusion Analysis |
|
|
245 | (1) |
|
|
246 | (1) |
|
|
246 | (1) |
|
|
246 | (1) |
|
|
247 | (1) |
|
Complete Tables and Lists from Memory |
|
|
247 | (1) |
|
|
248 | (3) |
|
Chapter 10 Analyzing Indicators of Compromise and Formulating an Appropriate |
|
|
|
|
251 | (1) |
|
|
251 | (1) |
|
|
251 | (1) |
|
|
252 | (1) |
|
|
252 | (1) |
|
|
252 | (1) |
|
|
253 | (1) |
|
|
254 | (1) |
|
|
254 | (1) |
|
|
255 | (1) |
|
|
256 | (1) |
|
|
256 | (1) |
|
|
257 | (1) |
|
|
257 | (1) |
|
|
257 | (1) |
|
|
258 | (1) |
|
|
259 | (1) |
|
Notification Severity/Priorities |
|
|
260 | (1) |
|
|
261 | (2) |
|
|
263 | (2) |
|
|
265 | (1) |
|
|
265 | (2) |
|
|
267 | (1) |
|
|
267 | (1) |
|
|
267 | (1) |
|
|
268 | (1) |
|
|
268 | (1) |
|
Scripts/Regular Expressions |
|
|
268 | (1) |
|
|
268 | (1) |
|
|
269 | (1) |
|
|
269 | (1) |
|
Complete Tables and Lists from Memory |
|
|
270 | (1) |
|
|
270 | (5) |
|
Chapter 11 Performing Vulnerability Management Activities |
|
|
275 | (18) |
|
|
275 | (1) |
|
Credentialed vs. Non-credentialed |
|
|
275 | (1) |
|
|
276 | (1) |
|
|
277 | (1) |
|
|
278 | (1) |
|
Security Content Automation Protocol (SCAP) |
|
|
278 | (1) |
|
Extensible Configuration Checklist Description Format (XCCDF) |
|
|
278 | (1) |
|
Open Vulnerability and Assessment Language (OVAL) |
|
|
279 | (1) |
|
Common Platform Enumeration (CPE) |
|
|
279 | (1) |
|
Common Vulnerabilities and Exposures (CVE) |
|
|
279 | (1) |
|
Common Vulnerability Scoring System (CVSS) |
|
|
279 | (3) |
|
Common Configuration Enumeration (CCE) |
|
|
282 | (1) |
|
Asset Reporting Format (ARF) |
|
|
282 | (1) |
|
Self-assessment vs. Third-Party Vendor Assessment |
|
|
283 | (1) |
|
|
283 | (1) |
|
|
284 | (1) |
|
Automated Patch Management |
|
|
284 | (1) |
|
|
284 | (1) |
|
|
285 | (1) |
|
|
286 | (1) |
|
|
287 | (1) |
|
Information Sharing and Analysis Centers (ISACs) |
|
|
287 | (1) |
|
|
287 | (1) |
|
|
287 | (1) |
|
|
287 | (1) |
|
|
288 | (1) |
|
Complete Tables and Lists from Memory |
|
|
288 | (1) |
|
|
288 | (5) |
|
Chapter 12 Using the Appropriate Vulnerability Assessment and Penetration Testing Methods and Tools |
|
|
293 | (22) |
|
|
293 | (1) |
|
Static Analysis/Dynamic Analysis |
|
|
293 | (1) |
|
|
293 | (1) |
|
|
294 | (1) |
|
|
294 | (1) |
|
|
294 | (1) |
|
Wireless Vulnerability Scan |
|
|
295 | (1) |
|
|
295 | (1) |
|
Software Composition Analysis |
|
|
296 | (1) |
|
|
296 | (1) |
|
|
297 | (1) |
|
|
297 | (1) |
|
|
298 | (1) |
|
|
298 | (1) |
|
|
298 | (1) |
|
|
299 | (1) |
|
|
300 | (2) |
|
|
302 | (1) |
|
|
302 | (2) |
|
|
304 | (1) |
|
|
304 | (2) |
|
|
306 | (1) |
|
|
307 | (1) |
|
|
308 | (1) |
|
|
308 | (1) |
|
|
308 | (1) |
|
Invasive vs. Non-invasive |
|
|
308 | (1) |
|
|
308 | (1) |
|
|
309 | (1) |
|
Corporate Policy Considerations |
|
|
310 | (1) |
|
|
310 | (1) |
|
Physical Security Considerations |
|
|
310 | (1) |
|
Rescan for Corrections/Changes |
|
|
310 | (1) |
|
|
310 | (1) |
|
|
310 | (1) |
|
|
311 | (1) |
|
Complete Tables and Lists from Memory |
|
|
312 | (1) |
|
|
312 | (3) |
|
Chapter 13 Analyzing Vulnerabilities and Recommending Risk Mitigations |
|
|
315 | (32) |
|
|
315 | (1) |
|
|
315 | (1) |
|
|
315 | (1) |
|
|
316 | (2) |
|
|
318 | (1) |
|
|
318 | (1) |
|
|
319 | (1) |
|
|
319 | (1) |
|
Security Misconfiguration |
|
|
319 | (1) |
|
|
320 | (1) |
|
|
321 | (1) |
|
|
321 | (1) |
|
Weak Cryptography Implementations |
|
|
321 | (1) |
|
|
322 | (1) |
|
Weak Cipher Suite Implementations |
|
|
322 | (1) |
|
Software Composition Analysis |
|
|
322 | (1) |
|
Use of Vulnerable Frameworks and Software Modules |
|
|
323 | (1) |
|
|
323 | (1) |
|
|
323 | (1) |
|
|
324 | (1) |
|
Code Injections/Malicious Changes |
|
|
324 | (1) |
|
End of Support/End of Life |
|
|
324 | (1) |
|
|
324 | (1) |
|
Inherently Vulnerable System/Application |
|
|
325 | (1) |
|
Client-Side Processing vs. Server-Side Processing |
|
|
325 | (1) |
|
JSON/Representatdonal State Transfer (REST) |
|
|
326 | (1) |
|
|
326 | (1) |
|
|
327 | (1) |
|
|
327 | (1) |
|
Hypertext Markup Language 5 (HTML5) |
|
|
327 | (1) |
|
Asynchronous JavaScript and XML (AJAX) |
|
|
327 | (2) |
|
Simple Object Access Protocol (SOAP) |
|
|
329 | (1) |
|
Machine Code vs. Bytecode or Interpreted vs. Emulated Attacks |
|
|
329 | (1) |
|
|
330 | (1) |
|
Cross-site Scripting (XSS) |
|
|
331 | (1) |
|
Cross-site Request Forgery (CSRF) |
|
|
331 | (1) |
|
|
332 | (1) |
|
|
332 | (3) |
|
|
335 | (1) |
|
Structured Query Language (SQL) |
|
|
335 | (2) |
|
|
337 | (1) |
|
|
337 | (1) |
|
|
337 | (1) |
|
Virtual Machine (VM) Hopping |
|
|
337 | (1) |
|
|
337 | (1) |
|
Border Gateway Protocol (BGP) Route Hijacking |
|
|
338 | (1) |
|
|
339 | (1) |
|
Denial-of-Service (DoS)/DDoS |
|
|
339 | (1) |
|
|
339 | (1) |
|
|
340 | (1) |
|
|
340 | (1) |
|
|
340 | (1) |
|
|
340 | (1) |
|
|
341 | (1) |
|
|
341 | (1) |
|
|
341 | (1) |
|
|
341 | (1) |
|
|
341 | (1) |
|
|
341 | (1) |
|
|
342 | (1) |
|
Complete Tables and Lists from Memory |
|
|
343 | (1) |
|
|
343 | (4) |
|
Chapter 14 Using Processes to Reduce Risk |
|
|
347 | (20) |
|
|
347 | (1) |
|
|
347 | (1) |
|
Developing Countermeasures |
|
|
347 | (1) |
|
|
347 | (1) |
|
|
348 | (1) |
|
|
348 | (1) |
|
Dynamic Network Configurations |
|
|
348 | (1) |
|
|
348 | (1) |
|
|
348 | (1) |
|
|
349 | (1) |
|
|
349 | (1) |
|
|
349 | (1) |
|
|
350 | (1) |
|
Log Collection and Curation |
|
|
350 | (1) |
|
Database Activity Monitoring |
|
|
350 | (1) |
|
|
351 | (1) |
|
|
352 | (1) |
|
|
352 | (1) |
|
|
352 | (1) |
|
|
352 | (1) |
|
|
353 | (1) |
|
|
353 | (1) |
|
Allow List vs. Block List |
|
|
354 | (1) |
|
Time of Check vs. Time of Use |
|
|
354 | (1) |
|
|
355 | (1) |
|
|
355 | (1) |
|
|
355 | (1) |
|
|
356 | (1) |
|
|
357 | (1) |
|
|
357 | (1) |
|
|
358 | (1) |
|
|
358 | (1) |
|
Types of Lighting Systems |
|
|
358 | (1) |
|
|
359 | (1) |
|
|
359 | (1) |
|
|
359 | (2) |
|
Open Spaces vs. Confined Spaces |
|
|
361 | (1) |
|
|
361 | (1) |
|
|
361 | (1) |
|
Natural Territorial Reinforcement |
|
|
361 | (1) |
|
|
362 | (1) |
|
|
362 | (1) |
|
|
362 | (1) |
|
Complete Tables and Lists from Memory |
|
|
363 | (1) |
|
|
363 | (4) |
|
Chapter 15 Implementing the Appropriate Incident Response |
|
|
367 | (18) |
|
|
367 | (1) |
|
|
367 | (1) |
|
|
367 | (1) |
|
|
367 | (1) |
|
|
367 | (1) |
|
|
367 | (1) |
|
|
368 | (1) |
|
Incident Response Process |
|
|
368 | (1) |
|
|
369 | (1) |
|
|
369 | (1) |
|
|
370 | (1) |
|
|
370 | (1) |
|
|
371 | (1) |
|
|
371 | (1) |
|
|
371 | (1) |
|
|
371 | (1) |
|
|
371 | (1) |
|
|
372 | (1) |
|
|
372 | (1) |
|
Specific Response Playbooks/Processes |
|
|
373 | (1) |
|
|
373 | (1) |
|
|
373 | (1) |
|
|
373 | (1) |
|
|
374 | (1) |
|
Non-automated Response Methods |
|
|
374 | (1) |
|
Automated Response Methods |
|
|
374 | (1) |
|
|
374 | (1) |
|
|
375 | (1) |
|
|
375 | (2) |
|
|
377 | (1) |
|
|
377 | (1) |
|
|
377 | (1) |
|
|
378 | (1) |
|
|
378 | (1) |
|
|
378 | (1) |
|
|
379 | (1) |
|
|
379 | (1) |
|
|
379 | (1) |
|
|
379 | (1) |
|
|
380 | (1) |
|
|
380 | (5) |
|
Chapter 16 Forensic Concepts |
|
|
385 | (14) |
|
Legal vs. Internal Corporate Purposes |
|
|
385 | (1) |
|
|
385 | (1) |
|
|
385 | (1) |
|
|
385 | (1) |
|
|
385 | (1) |
|
|
386 | (1) |
|
|
387 | (1) |
|
|
388 | (1) |
|
|
388 | (1) |
|
|
388 | (1) |
|
|
389 | (1) |
|
|
389 | (1) |
|
|
389 | (1) |
|
|
389 | (1) |
|
|
390 | (1) |
|
|
390 | (1) |
|
Hardware/Embedded Device Analysis |
|
|
391 | (1) |
|
|
391 | (1) |
|
|
391 | (1) |
|
|
391 | (1) |
|
|
392 | (1) |
|
|
392 | (2) |
|
|
394 | (1) |
|
|
394 | (1) |
|
|
394 | (1) |
|
|
394 | (1) |
|
|
395 | (1) |
|
Complete Tables and Lists from Memory |
|
|
395 | (1) |
|
|
395 | (4) |
|
Chapter 17 Forensic Analysis Tools |
|
|
399 | (20) |
|
|
399 | (1) |
|
|
399 | (1) |
|
|
400 | (1) |
|
|
401 | (1) |
|
|
401 | (1) |
|
|
401 | (1) |
|
|
401 | (1) |
|
GNU Project Debugger (GDB) |
|
|
401 | (1) |
|
|
402 | (1) |
|
|
402 | (1) |
|
|
402 | (1) |
|
|
402 | (1) |
|
|
402 | (1) |
|
|
403 | (1) |
|
|
403 | (1) |
|
|
403 | (1) |
|
|
403 | (1) |
|
|
403 | (1) |
|
|
404 | (1) |
|
|
405 | (1) |
|
Dynamically vs. Statically Linked |
|
|
405 | (1) |
|
|
405 | (1) |
|
Forensic Toolkit (FTK) Imager |
|
|
405 | (1) |
|
|
406 | (1) |
|
|
407 | (1) |
|
|
407 | (1) |
|
|
407 | (1) |
|
Live Collection vs. Post-mortem Tools |
|
|
407 | (1) |
|
|
407 | (2) |
|
|
409 | (1) |
|
|
409 | (1) |
|
|
410 | (1) |
|
|
410 | (1) |
|
|
410 | (1) |
|
|
411 | (1) |
|
|
411 | (1) |
|
|
412 | (1) |
|
|
413 | (1) |
|
|
413 | (1) |
|
|
414 | (1) |
|
Complete Tables and Lists from Memory |
|
|
414 | (1) |
|
|
414 | (5) |
|
Part III Security Engineering and Cryptography |
|
|
|
Chapter 18 Applying Secure Configurations to Enterprise Mobility |
|
|
419 | (18) |
|
|
419 | (1) |
|
|
419 | (1) |
|
|
419 | (1) |
|
|
420 | (1) |
|
|
421 | (1) |
|
|
421 | (1) |
|
|
421 | (1) |
|
|
421 | (1) |
|
|
422 | (1) |
|
|
422 | (1) |
|
|
422 | (1) |
|
|
423 | (1) |
|
Wi-Fi Protected Access (WPA2/3) |
|
|
423 | (1) |
|
|
423 | (1) |
|
|
424 | (1) |
|
|
424 | (1) |
|
Near-Field Communication (NFC) |
|
|
424 | (1) |
|
|
425 | (1) |
|
|
425 | (1) |
|
|
425 | (1) |
|
|
426 | (1) |
|
|
426 | (1) |
|
|
427 | (1) |
|
|
427 | (1) |
|
|
427 | (1) |
|
|
427 | (1) |
|
|
428 | (1) |
|
|
428 | (1) |
|
|
429 | (1) |
|
Bring Your Own Device (BYOD) |
|
|
429 | (1) |
|
|
429 | (1) |
|
Corporate-Owned, Personally Enabled (COPE) |
|
|
429 | (1) |
|
Choose Your Own Device (CYOD) |
|
|
429 | (1) |
|
Implications of Wearable Devices |
|
|
429 | (1) |
|
Unauthorized Remote Activation/Deactivation of Devices or Features |
|
|
430 | (1) |
|
Encrypted and Unencrypted Communication Concerns |
|
|
430 | (1) |
|
|
430 | (1) |
|
|
430 | (1) |
|
|
430 | (1) |
|
Digital Forensics on Collected Data |
|
|
430 | (1) |
|
Unauthorized Application Stores |
|
|
431 | (1) |
|
|
431 | (1) |
|
|
431 | (1) |
|
|
432 | (1) |
|
Original Equipment Manufacturer (OEM) and Carrier Differences |
|
|
432 | (1) |
|
|
432 | (1) |
|
|
432 | (1) |
|
|
433 | (1) |
|
|
433 | (1) |
|
|
433 | (1) |
|
Complete Tables and Lists from Memory |
|
|
433 | (1) |
|
|
433 | (4) |
|
Chapter 19 Configuring and Implementing Endpoint Security Controls |
|
|
437 | (22) |
|
|
437 | (1) |
|
Removing Unneeded Services |
|
|
437 | (1) |
|
Disabling Unused Accounts |
|
|
438 | (1) |
|
|
438 | (1) |
|
Removing End-of-Life Devices |
|
|
438 | (1) |
|
Removing End-of-Support Device |
|
|
438 | (1) |
|
|
439 | (1) |
|
Enabling No-Execute (NX)/Execute Never (XN) Bit |
|
|
439 | (1) |
|
Disabling Central Processing Unit (CPU) Virtualization Support |
|
|
439 | (1) |
|
Secure Encrypted Enclaves |
|
|
440 | (1) |
|
|
440 | (1) |
|
|
441 | (1) |
|
Address Space Layout Randomization (ASLR) |
|
|
442 | (1) |
|
|
442 | (1) |
|
|
442 | (1) |
|
|
442 | (1) |
|
|
443 | (1) |
|
|
443 | (1) |
|
|
443 | (1) |
|
|
444 | (1) |
|
Security-Enhanced Linux (SELinux)/Security-Enhanced Android (SEAndroid) |
|
|
444 | (1) |
|
|
444 | (1) |
|
|
444 | (1) |
|
|
445 | (1) |
|
|
445 | (1) |
|
Trusted Platform Module (TPM) |
|
|
445 | (1) |
|
|
446 | (1) |
|
Unified Extensible Firmware Interface (UEFIVBasic Input/Output System (BIOS) Protection |
|
|
447 | (1) |
|
|
448 | (1) |
|
Hardware Security Module (HSM) |
|
|
448 | (1) |
|
|
449 | (1) |
|
Self-Encrypting Drives (SEDs) |
|
|
450 | (1) |
|
|
450 | (1) |
|
|
450 | (1) |
|
|
451 | (1) |
|
Host-Based Intrusion Detection System (HIDS)/Host-Based Intrusion Prevention System (HIPS) |
|
|
451 | (1) |
|
|
451 | (1) |
|
Endpoint Detection and Response (EDR) |
|
|
451 | (1) |
|
|
452 | (1) |
|
|
452 | (1) |
|
User and Entity Behavior Analytics (UEBA) |
|
|
452 | (1) |
|
|
452 | (1) |
|
|
452 | (1) |
|
|
453 | (1) |
|
Complete Tables and Lists from Memory |
|
|
454 | (1) |
|
|
454 | (5) |
|
Chapter 20 Security Considerations Impacting Specific Sectors and Operational Technologies |
|
|
459 | (18) |
|
|
459 | (1) |
|
|
459 | (1) |
|
|
460 | (1) |
|
Methods of Securing IoT Devices |
|
|
461 | (1) |
|
|
461 | (1) |
|
Application-Specific Integrated Circuit (ASIC) and Field-Programmable Gate Array (FPGA) |
|
|
461 | (1) |
|
ICS/Supervisory Control and Data Acquisition (SCADA) |
|
|
462 | (1) |
|
Programmable Logic Controller (PLC) |
|
|
463 | (1) |
|
|
463 | (1) |
|
|
463 | (1) |
|
Safety Instrumented System |
|
|
464 | (1) |
|
Heating, Ventilation, and Air Conditioning (HVAC) |
|
|
464 | (1) |
|
|
465 | (1) |
|
Controller Area Network (CAN) Bus |
|
|
465 | (1) |
|
|
466 | (1) |
|
Distributed Network Protocol 3 (DNP3) |
|
|
466 | (1) |
|
|
467 | (1) |
|
Common Industrial Protocol (CIP) |
|
|
467 | (1) |
|
Data Distribution Service |
|
|
468 | (1) |
|
|
468 | (1) |
|
|
469 | (1) |
|
|
469 | (1) |
|
|
470 | (1) |
|
|
470 | (1) |
|
|
470 | (1) |
|
|
471 | (1) |
|
|
472 | (1) |
|
|
472 | (1) |
|
|
472 | (1) |
|
Complete Tables and Lists from Memory |
|
|
473 | (1) |
|
|
473 | (4) |
|
Chapter 21 Cloud Technology's Impact on Organizational Security |
|
|
477 | (22) |
|
Automation and Orchestration |
|
|
477 | (1) |
|
|
477 | (1) |
|
|
478 | (1) |
|
|
479 | (1) |
|
|
479 | (1) |
|
|
479 | (1) |
|
|
480 | (1) |
|
|
480 | (1) |
|
Monitoring Configurations |
|
|
480 | (1) |
|
Key Ownership and Location |
|
|
481 | (2) |
|
Key Life-Cycle Management |
|
|
483 | (2) |
|
Backup and Recovery Methods |
|
|
485 | (1) |
|
Cloud as Business Continuity and Disaster Recovery (BCDR) |
|
|
486 | (1) |
|
|
486 | (1) |
|
Alternative Provider BCDR |
|
|
486 | (1) |
|
Infrastructure vs. Serverless Computing |
|
|
486 | (1) |
|
Application Virtualization |
|
|
487 | (1) |
|
Software-Defined Networking |
|
|
488 | (1) |
|
|
488 | (1) |
|
|
488 | (1) |
|
|
488 | (1) |
|
|
489 | (2) |
|
|
491 | (1) |
|
Storage and Document Collaboration Tools |
|
|
491 | (1) |
|
|
492 | (1) |
|
|
493 | (1) |
|
|
493 | (1) |
|
Cloud Access Security Broker (CASB) |
|
|
493 | (1) |
|
|
494 | (1) |
|
|
494 | (1) |
|
|
495 | (1) |
|
|
495 | (4) |
|
Chapter 22 Implementing the Appropriate PKI Solution |
|
|
499 | (20) |
|
|
499 | (1) |
|
Registration Authority (RA) |
|
|
499 | (1) |
|
Certificate Authority (CA) |
|
|
499 | (1) |
|
Subordinate/Intermediate CA |
|
|
500 | (1) |
|
|
501 | (1) |
|
|
501 | (1) |
|
|
502 | (1) |
|
|
502 | (1) |
|
|
503 | (1) |
|
Certificate Usages/Profiles/Templates |
|
|
504 | (1) |
|
|
504 | (1) |
|
|
504 | (1) |
|
|
504 | (1) |
|
|
505 | (1) |
|
|
505 | (1) |
|
|
505 | (1) |
|
Subject Alternate Name (SAN) |
|
|
505 | (1) |
|
|
505 | (1) |
|
|
506 | (1) |
|
|
506 | (1) |
|
|
507 | (1) |
|
|
507 | (1) |
|
|
508 | (4) |
|
|
512 | (1) |
|
|
512 | (1) |
|
|
512 | (1) |
|
Certificate Signing Requests (CSRs) |
|
|
513 | (1) |
|
Online Certificate Status Protocol (OCSP) vs. Certificate Revocation List (CRL) |
|
|
513 | (1) |
|
HTTP Strict Transport Security (HSTS) |
|
|
514 | (1) |
|
|
514 | (1) |
|
|
514 | (1) |
|
|
515 | (1) |
|
|
515 | (4) |
|
Chapter 23 Implementing the Appropriate Cryptographic Protocols and Algorithms |
|
|
519 | (24) |
|
|
519 | (1) |
|
Secure Hashing Algorithm (SHA) |
|
|
519 | (1) |
|
Hash-Based Message Authentication Code (HMAC) |
|
|
520 | (1) |
|
|
521 | (1) |
|
RACE Integrity Primitives Evaluation Message Digest (RIPEMD) |
|
|
521 | (1) |
|
|
521 | (1) |
|
|
522 | (1) |
|
|
523 | (1) |
|
Electronic Codebook (ECB) |
|
|
523 | (1) |
|
Cipher Block Chaining (CBC) |
|
|
524 | (1) |
|
|
524 | (1) |
|
|
525 | (1) |
|
Galois/Counter Mode (GCM) |
|
|
525 | (1) |
|
|
526 | (1) |
|
Advanced Encryption Standard (AES) |
|
|
527 | (1) |
|
Triple Digital Encryption Standard (3DES) |
|
|
528 | (1) |
|
|
528 | (1) |
|
|
528 | (1) |
|
|
529 | (1) |
|
|
529 | (1) |
|
Elliptic-Curve Diffie-Hellman (ECDH) |
|
|
530 | (1) |
|
|
530 | (1) |
|
Digital Signature Algorithm (DSA) |
|
|
530 | (1) |
|
Rivest, Shamir, andAdleman (RSA) |
|
|
530 | (1) |
|
Elliptic-Curve Digital Signature Algorithm (ECDSA) |
|
|
531 | (1) |
|
|
531 | (1) |
|
|
532 | (1) |
|
Secure Sockets Layer (SSL)/Transport Layer Security (TLS) |
|
|
532 | (1) |
|
Secure/Multipurpose Internet Mail Extensions (S/MIME) |
|
|
533 | (1) |
|
Internet Protocol Security (IPsec) |
|
|
534 | (1) |
|
|
534 | (1) |
|
|
535 | (1) |
|
Elliptic-Curve Cryptography |
|
|
535 | (1) |
|
|
535 | (1) |
|
|
536 | (1) |
|
Authenticated Encryption with Associated Data |
|
|
536 | (1) |
|
|
536 | (1) |
|
Password-Based Key Derivation Function 2 (PBKDF2) |
|
|
537 | (1) |
|
|
537 | (1) |
|
|
537 | (1) |
|
|
537 | (1) |
|
|
538 | (1) |
|
Complete Tables and Lists from Memory |
|
|
538 | (4) |
|
Implementation and Configuration Issues |
|
|
542 | (1) |
|
|
542 | (1) |
|
Chapter 24 Troubleshooting Issues with Cryptographic Implementations |
|
|
543 | (12) |
|
|
543 | (1) |
|
|
543 | (1) |
|
|
543 | (1) |
|
|
544 | (1) |
|
Invalid Root or Intermediate CAs |
|
|
544 | (1) |
|
|
544 | (1) |
|
|
545 | (1) |
|
|
545 | (1) |
|
|
546 | (1) |
|
|
546 | (1) |
|
|
546 | (1) |
|
|
546 | (1) |
|
|
547 | (1) |
|
|
547 | (1) |
|
|
548 | (1) |
|
|
548 | (1) |
|
|
548 | (1) |
|
|
548 | (1) |
|
Cryptographic Obfuscation |
|
|
548 | (1) |
|
|
549 | (1) |
|
|
549 | (1) |
|
|
549 | (1) |
|
|
549 | (1) |
|
|
550 | (1) |
|
Complete Tables and Lists from Memory |
|
|
550 | (1) |
|
|
550 | (5) |
|
Part IV Governance, Risk, and Compliance |
|
|
|
Chapter 25 Applying Appropriate Risk Strategies |
|
|
555 | (52) |
|
|
555 | (1) |
|
|
556 | (1) |
|
|
556 | (1) |
|
Qualitative vs. Quantitative |
|
|
557 | (1) |
|
Qualitative Risk Analysis |
|
|
557 | (1) |
|
Quantitative Risk Analysis |
|
|
558 | (1) |
|
|
558 | (1) |
|
|
558 | (1) |
|
Total Cost of Ownership (TCO) |
|
|
559 | (1) |
|
Return on Investment (ROI) |
|
|
560 | (1) |
|
|
561 | (1) |
|
|
562 | (1) |
|
Mean Time to Recovery (MTTR) |
|
|
562 | (1) |
|
Mean Time Between Failure (MTBF) |
|
|
562 | (1) |
|
Annualized Loss Expectancy (ALE)/Annualized Rate of Occurrence (ARO)/Single Loss Expectancy (SLE) |
|
|
562 | (1) |
|
|
563 | (1) |
|
|
563 | (1) |
|
|
563 | (1) |
|
|
564 | (1) |
|
|
565 | (1) |
|
|
565 | (1) |
|
|
565 | (1) |
|
|
566 | (1) |
|
|
566 | (1) |
|
|
566 | (1) |
|
|
567 | (1) |
|
|
567 | (1) |
|
|
567 | (1) |
|
Risk Management Life Cycle |
|
|
568 | (1) |
|
|
569 | (1) |
|
|
570 | (1) |
|
|
570 | (2) |
|
|
572 | (1) |
|
|
572 | (1) |
|
|
572 | (1) |
|
|
572 | (1) |
|
|
572 | (1) |
|
|
572 | (1) |
|
|
572 | (1) |
|
|
573 | (1) |
|
|
573 | (1) |
|
|
573 | (1) |
|
|
574 | (4) |
|
Open Source Security Testing Methodology Manual (OSSTMM) |
|
|
588 | (1) |
|
COSO's Enterprise Risk Management (ERM) Integrated Framework |
|
|
588 | (1) |
|
Risk Management Standard by the Federation of European Risk Management Associations (FERMA) |
|
|
589 | (1) |
|
|
590 | (1) |
|
|
590 | (1) |
|
Key Performance Indicators/Key Risk Indicators |
|
|
591 | (1) |
|
|
592 | (2) |
|
|
594 | (1) |
|
Risk Appetite vs. Risk Tolerance |
|
|
594 | (1) |
|
|
595 | (1) |
|
Usability vs. Security Requirements |
|
|
595 | (1) |
|
Policies and Security Practices |
|
|
595 | (1) |
|
|
595 | (1) |
|
|
596 | (1) |
|
|
596 | (1) |
|
|
597 | (1) |
|
Employment and Termination Procedures |
|
|
598 | (1) |
|
Training and Awareness for Users |
|
|
599 | (2) |
|
Auditing Requirements and Frequency |
|
|
601 | (1) |
|
|
601 | (1) |
|
|
601 | (2) |
|
|
603 | (1) |
|
Complete Tables and Lists from Memory |
|
|
603 | (1) |
|
|
603 | (4) |
|
Chapter 26 Managing and Mitigating Vendor Risk |
|
|
607 | (18) |
|
Shared Responsibility Model (Roles/Responsibilities) |
|
|
607 | (1) |
|
Cloud Service Provider (CSP) |
|
|
607 | (1) |
|
|
608 | (1) |
|
|
608 | (1) |
|
Compute/Storage/Networking |
|
|
608 | (1) |
|
|
608 | (1) |
|
|
609 | (1) |
|
|
609 | (1) |
|
|
609 | (1) |
|
|
609 | (1) |
|
|
609 | (1) |
|
Vendor Lock-in and Vendor Lock-out |
|
|
610 | (1) |
|
|
610 | (1) |
|
|
610 | (1) |
|
Merger or Acquisition Risk |
|
|
610 | (1) |
|
Meeting Client Requirements |
|
|
610 | (1) |
|
|
610 | (1) |
|
|
611 | (1) |
|
|
612 | (1) |
|
Device and Technical Configurations |
|
|
612 | (1) |
|
|
612 | (1) |
|
|
613 | (1) |
|
|
614 | (1) |
|
|
614 | (1) |
|
|
615 | (1) |
|
Geographical Consideration |
|
|
615 | (1) |
|
|
615 | (1) |
|
Incident Reporting Requirements |
|
|
616 | (1) |
|
|
616 | (1) |
|
Ongoing Vendor Assessment Tools |
|
|
616 | (1) |
|
|
616 | (1) |
|
|
617 | (1) |
|
|
617 | (1) |
|
|
618 | (1) |
|
|
618 | (1) |
|
|
618 | (1) |
|
|
618 | (1) |
|
|
618 | (1) |
|
|
619 | (1) |
|
|
620 | (1) |
|
|
620 | (1) |
|
|
620 | (1) |
|
Complete Tables and Lists from Memory |
|
|
621 | (1) |
|
|
621 | (4) |
|
Chapter 27 The Organizational Impact of Compliance Frameworks and Legal Considerations |
|
|
625 | (32) |
|
Security Concerns of Integrating Diverse Industries |
|
|
625 | (1) |
|
|
625 | (1) |
|
|
626 | (1) |
|
|
626 | (1) |
|
|
626 | (1) |
|
|
626 | (1) |
|
|
627 | (1) |
|
|
627 | (1) |
|
Commercial Business Classifications |
|
|
628 | (1) |
|
Military and Government Classifications |
|
|
628 | (1) |
|
|
629 | (1) |
|
|
629 | (1) |
|
|
630 | (1) |
|
|
630 | (3) |
|
Personally Identifiable Information (PII) |
|
|
633 | (1) |
|
Data Removal, Destruction, and Sanitization |
|
|
634 | (1) |
|
Geographic Considerations |
|
|
635 | (1) |
|
|
636 | (1) |
|
|
636 | (1) |
|
Location of Cloud Provider |
|
|
637 | (1) |
|
Third-Party Attestation of Compliance |
|
|
637 | (1) |
|
Regulations, Accreditations, and Standards |
|
|
637 | (1) |
|
|
638 | (1) |
|
|
638 | (1) |
|
|
639 | (1) |
|
|
639 | (1) |
|
|
639 | (1) |
|
Payment Card Industry Data Security Standard (PCI DSS) |
|
|
639 | (1) |
|
General Data Protection Regulation (GDPR) |
|
|
640 | (1) |
|
International Organization for Standardization (ISO) |
|
|
641 | (2) |
|
Capability Maturity Model Integration (CMMI) |
|
|
643 | (1) |
|
National Institute of Standards and Technology (NIST) |
|
|
644 | (1) |
|
Children's Online Privacy Protection Act (COPPA) |
|
|
644 | (1) |
|
|
644 | (2) |
|
Cloud Security Alliance (CSA) Security Trust Assurance and Risk (STAR) |
|
|
646 | (1) |
|
|
646 | (1) |
|
|
646 | (1) |
|
|
647 | (1) |
|
|
648 | (1) |
|
|
648 | (1) |
|
Contract and Agreement Types |
|
|
648 | (1) |
|
Service-Level Agreement (SLA) |
|
|
649 | (1) |
|
Master Service Agreement (MSA) |
|
|
649 | (1) |
|
Non-disclosure Agreement (NDA) |
|
|
650 | (1) |
|
Memorandum of Understanding (MOU) |
|
|
650 | (1) |
|
Interconnection Security Agreement (ISA) |
|
|
650 | (1) |
|
Operational-Level Agreement |
|
|
651 | (1) |
|
|
651 | (1) |
|
|
651 | (1) |
|
|
651 | (1) |
|
|
652 | (1) |
|
Complete Tables and Lists from Memory |
|
|
653 | (3) |
|
|
656 | (1) |
|
Chapter 28 Business Continuity and Disaster Recovery Concepts |
|
|
657 | (16) |
|
Develop Contingency Planning Policy |
|
|
658 | (1) |
|
|
658 | (1) |
|
Identify Critical Processes and Resources |
|
|
659 | (1) |
|
|
659 | (1) |
|
|
659 | (1) |
|
|
659 | (1) |
|
Mission Essential Functions |
|
|
659 | (1) |
|
Privacy Impact Assessment |
|
|
660 | (1) |
|
Disaster Recovery Plan (DRP)/Business Continuity Plan (BCP) |
|
|
660 | (1) |
|
|
661 | (1) |
|
|
661 | (1) |
|
Business Continuity Steps |
|
|
662 | (1) |
|
Recovery and Multiple Site Strategies |
|
|
662 | (1) |
|
|
663 | (1) |
|
|
663 | (1) |
|
|
663 | (1) |
|
|
664 | (1) |
|
|
664 | (1) |
|
|
665 | (1) |
|
|
666 | (1) |
|
|
666 | (1) |
|
|
666 | (1) |
|
|
666 | (1) |
|
|
666 | (1) |
|
|
667 | (1) |
|
Parallel Test/Simulation Test |
|
|
667 | (1) |
|
|
667 | (1) |
|
|
667 | (1) |
|
|
668 | (1) |
|
Complete Tables and Lists from Memory |
|
|
668 | (4) |
|
Tools for Final Preparation |
|
|
672 | (1) |
|
Pearson Test Prep Practice Test Software and Questions on the Website |
|
|
672 | (1) |
|
Chapter 29 Final Preparations |
|
|
673 | (6) |
|
Accessing the Pearson Test Prep Software Online |
|
|
673 | (1) |
|
Accessing the Pearson Test Prep Practice Test Software Offline |
|
|
673 | (1) |
|
|
674 | (1) |
|
|
675 | (1) |
|
|
676 | (1) |
|
Chapter-Ending Review Tools |
|
|
676 | (1) |
|
Suggested Plan for Final Review/Study |
|
|
676 | (1) |
|
|
677 | (2) |
Appendix A Answers to the Review Questions |
|
679 | (30) |
Glossary |
|
709 | (52) |
Index |
|
761 | |