From the AVP - The Ten Domains of Information Security
Information Security is not just the security of information systems or IT resources. It is a much more comprehensive than that. Information security must consider each of these 10 different areas:
-
Security Management Practices
- Access Control Systems and Methodology
- Law, Investigation, Ethics
- Physical Security
- Business Continuity & Disaster Recovery Planning
- Security Architecture & Models
- Cryptography
- Telecommunications & Network Security
- Applications & Systems Development
- Operations Security
These domains contain these areas:
- Security Management Practices
- Concepts & Objectives, Risk Management, Policies & Procedures
- Information Classification, IS Awareness, IS Roles and Responsibilities
- Handling Incidents
- Access Control Systems and Methodology
- Identification & Authentication, Single Sign On
- Centralized vs. Distributed Access Control
- Control access by applying the appropriate concepts/methodologies/techniques
- Identify, evaluate and respond to access control attacks (Brute Force, Dictionary Spoofing, Denial of Service)
- Design coordinate and evaluate penetration and vulnerability tests
- Law, Investigation, Ethics
- HIPAA, FERMA, GLB, other Laws and Regulations
- Physical Security
- Facilities Management, Personnel Security, Physical Controls
- Business Continuity & Disaster Recovery Planning
- Concepts: BC vs DR
- Recovery Planning Process, Plan Development & Maintenance, Testing
- Program Management, Vulnerability Assessment, Prevention
- Security Architecture & Models
- CS and Architecture, Security & Control Concepts, Security Models, Evaluation Criteria
- Host-based Security, Client-Server Security, Network Security
- Network and IP Security Architecture
- Cryptography
- History, Definitions, Applications & Uses of Cryptography, Protocols and Standards
- Basic Technologies, Encryption Systems, Symmetric/Asymmetric Cryptography,
- Digital Signatures, Email Sec, Internet Sec, Key Management,
- Public Key Infrastructure (PKI), cryptanalysis & Attacks, Export Issues
- Telecommunications & Network Security
- Communications Security Management, Network Protocols
- Identification & Authentication, Data Communication, Internet & Web Security
- Attack Methods, Multimedia Security, Incident Response Management
- Applications & Systems Development
- Definitions, Security Goals & Threats, System Life Cycle, Security Architecture
- Change Control, Application Development & Security Measures,
- Databases & Data Warehousing, Knowledge Based Systems
- Operations Security
- Resources, Privileges, Control Mechanisms, Potential Abuses, Principles
|
|
|