1/19
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai |
|---|
No analytics yet
Send a link to your students to track their progress
Acquisition
Process of obtaining goods and services
Procurement
Encompasses the full process of acquiring goods and services, including all preceding steps
Bring your own Device (BYOD)
Permits employees to use personal devices for work.
Employee Owned (Security + Control of device)
Security Risk
Corporate-Owned, Personally Enabled (COPE)
Company provides devices to employees for work and personal use.
Higer Investment for company
Standardized device management
Privacy concerns for employees
Choose Your Own Device (CYOD)
A mix of BYOD and COPE which allows employees to choose devices from a company-approved list.
High Costs
Privacy Concerns
Asset Management
Approach to governing and maximixing the value of items an entity is responsible for throughout their lifecycle
Assignment/Acounting
Organizations should designate individuals or groups as owners for each of it assets.
Classification
Categorizing assets based on criteria (Function, Value, etc..) determined by the company
Monitoring/Tracking
Ensures proper accountability and optimal use of each asset (Maintaing inventory/record)
Asset tracking
Maintaining a inventory with assets specifications, locations, users and other details
Enumeration
Identifying and counting assets, especially in large organizations or during time of asset procurement or retirement
Mobile Device Management (MDM)
How organizations securely oversee employee devices. To ensure policy enforcement, software consistency and data protection. The centralization helps ensure devices comply with latest standards and protocol
Special Publication 800-88
Guidelines for Media Sanitization (Sanitization, Destruction and Certification)
Sanitization
Making data inaccessible and irretrievable from a storage medium using forensic methods
Overwriting Data
Degaussing
Encryption
Overwriting
Replacing existing data on a storage device with random bits of information to ensure that the original data is obscured
(1,7,35 passes based on the classification)
Degaussing
Using a degausser to produce a strong magnetic field that can disrupt the magnetic domains on a storage medium (Hard drive or tapes ) This completely erases data.
Secure Erase
Deletes data from. A storage device while ensuring that it can’t be recovered using tradition tools. By deleting encryption keys.
Is Fast and can be repurposed
Destruction
Ensures the device itself is beyond recovery or reuse. (Shredding, Pulverizing, Melting and Incinerating)
Certification
Act of proof (Document/Audit )that the data or hardware has been securely disposed.
Crucial for Organizations who:
Comply with regulatory control
Sensitive data (Top secret data, Financial or Health Records)
Data Rentenion
Deciding what to keep and for how long.