INFS 3929 CH2 Managing Life Cycle Assets

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/190

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:39 AM on 9/9/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

191 Terms

1
New cards

What is an organisational asset?

Anything of value that helps an organisation achieve a business objective.

2
New cards

What are the four Week 2 asset types?

HaS-PeD: Hardware, Software, Personnel and Data/information.

3
New cards

What is a hardware asset?

A physical technology asset, such as a server, laptop, router or POS terminal.

4
New cards

Give two hardware-asset examples.

A server and a network router.

5
New cards

What is a software asset?

A program or service that enables hardware or business activities.

6
New cards

Give two software-asset examples.

An operating system and a customer-ordering application.

7
New cards

Why is personnel considered an asset?

People provide knowledge, skills, judgement and relationships needed for business tasks.

8
New cards

Give two examples of personnel assets.

A system administrator and an incident responder.

9
New cards

What is a personnel single point of failure?

One person is the only individual able or authorised to perform a critical task.

10
New cards

What is the main risk of a personnel single point of failure?

The task or objective may stop if that person leaves or is unavailable.

11
New cards

Name three controls for personnel dependency.

Cross-training, documented procedures and succession/backup staffing.

12
New cards

What is a data/information asset?

Information with business value, regardless of its format or storage location.

13
New cards

Give three examples of data assets.

Customer records, credentials and system configuration data.

14
New cards

What does HaS-PeD stand for?

Hardware, Software, Personnel and Data.

15
New cards

What is a manual business activity?

An activity performed mainly by a person, such as approving a refund.

16
New cards

What is an automated business activity?

An activity performed by a system, such as automatically calculating tax.

17
New cards

Why map both manual and automated activities?

To reveal all people, process and technology dependencies supporting an objective.

18
New cards

What does an asset inventory primarily show?

What assets exist and where they are located.

19
New cards

How is asset management broader than inventory?

It governs ownership, value, configuration, protection, lifecycle and risk.

20
New cards

What identifier should be recorded for hardware?

A unique asset number or serial number.

21
New cards

Why record the owner or custodian of an asset?

So someone is accountable for its security, maintenance and lifecycle decisions.

22
New cards

Why record an asset’s location?

To find, protect, audit and recover the correct asset.

23
New cards

What software details should be inventoried?

Product name, version/build, licences, support status and installed updates.

24
New cards

What is a CMDB?

A Configuration Management Database that records configuration items and their relationships.

25
New cards

What is a configuration item (CI)?

A managed component such as a device, application, service, database or document.

26
New cards

Why are CMDB relationships important?

They show which services and objectives depend on each asset.

27
New cards

How do you read a dependency map DOWN?

From the objective toward the tasks, functions and assets it depends on.

28
New cards

How do you read a dependency map UP?

From an asset failure toward the business objectives it will affect.

29
New cards

What does AIDR stand for in CMDB benefits?

Audits, Incidents, Decommissioning and Recovery.

30
New cards

How does a CMDB help incident response?

It identifies affected services, dependencies, owners and response priorities.

31
New cards

How does a CMDB help decommissioning?

It reveals dependencies and helps prevent orphaned systems, accounts or data.

32
New cards

What makes a CMDB unreliable?

Incomplete, outdated or unverified asset and relationship data.

33
New cards

How can a business keep its CMDB complete?

Use automated discovery, regular audits, reconciliation and named owners.

34
New cards

What is shadow IT?

Technology used without formal IT or security approval.

35
New cards

Give one example of shadow IT.

A team stores customer files in an unapproved personal cloud account.

36
New cards

Why is shadow IT difficult to protect?

It may be invisible to inventory, patching, backup, monitoring and retention controls.

37
New cards

Name one useful response to shadow IT.

Discover it, assess the risk and provide a safe approved alternative.

38
New cards

What is asset criticality?

How important an asset is to achieving a business objective.

39
New cards

Is asset criticality the same as purchase price?

No. A cheap asset may support a service whose failure causes major losses.

40
New cards

What should a criticality assessment consider?

Operational, financial, safety, legal/regulatory and reputational impact.

41
New cards

What are the three asset-value lenses?

RRR: Replacement cost, Revenue/operational impact and Regulatory/liability exposure.

42
New cards

What is the replacement-cost lens?

The cost of rebuilding, restoring or replacing the asset and lost productivity.

43
New cards

What is the revenue/operational-impact lens?

The money or service capacity lost during disruption or downtime.

44
New cards

What is the regulatory/liability lens?

Fines, notification costs, litigation, compensation and other legal exposure.

45
New cards

Why can liability exceed replacement cost?

The technology may be cheap, while a breach triggers large fines, claims and notification costs.

46
New cards

What does B-COR stand for?

Business need, Create/buy, Operate and Retire.

47
New cards

What is the asset lifecycle?

The stages from business need and acquisition through operation to retirement/disposal.

48
New cards

What security action is essential when acquiring an asset?

Record it, assign an owner and establish a secure configuration.

49
New cards

What security actions occur during asset operation?

Maintain, patch, monitor, review access and update inventory records.

50
New cards

What security action is essential at asset retirement?

Sanitise its data and update the inventory/CMDB.

51
New cards

What is the first data-lifecycle stage?

Collect or create the data.

52
New cards

What should happen during data collection?

Collect only necessary data and classify it appropriately.

53
New cards

What should happen when data is stored?

Apply suitable access control, encryption, backup and retention protections.

54
New cards

What should happen when data is shared?

Authorise the recipient and protect the transmission.

55
New cards

What should happen when data reaches retention expiry?

Destroy it securely unless law or business need requires continued retention.

56
New cards

Why must data classification influence disposal?

More sensitive data requires stronger protection against recovery.

57
New cards

What is CLEAR sanitisation?

Logical wiping or overwriting that defeats ordinary recovery methods.

58
New cards

When is CLEAR generally suitable?

When media will remain under organisational control for internal reuse.

59
New cards

What is the memory image for CLEAR?

🧽 Wiping a whiteboard clean.

60
New cards

What is PURGE sanitisation?

A method that makes recovery infeasible even with advanced techniques.

61
New cards

Name two PURGE methods.

Degaussing compatible magnetic media and cryptographic erasure.

62
New cards

What is cryptographic erasure?

Securely destroying encryption keys so encrypted data becomes unreadable.

63
New cards

When is PURGE generally suitable?

Before sensitive media leaves organisational control, if policy permits reuse.

64
New cards

What is the memory image for PURGE?

🧲🔑 Removing the magnetic trace or the encryption key.

65
New cards

What is DESTROY sanitisation?

Physically rendering media unusable and its data irrecoverable.

66
New cards

Name three DESTROY methods.

Shredding, crushing/disintegration and incineration.

67
New cards

When is DESTROY generally required?

For extremely sensitive data or failed media that cannot be securely purged.

68
New cards

What is the memory image for DESTROY?

💥 No readable device remains.

69
New cards

What does CPD stand for?

Clear, Purge and Destroy.

70
New cards

What is the CPD strength order?

Clear → Purge → Destroy.

71
New cards

Why is ordinary file deletion insufficient?

It often removes only a reference; recoverable data blocks may remain.

72
New cards

What evidence should follow sanitisation?

Verification, chain-of-custody records and updated inventory/CMDB status.

73
New cards

Why is cloud data deletion difficult?

Copies may remain in replicas, snapshots, backups, logs and multiple regions.

74
New cards

What should a cloud-deletion plan address?

Retention, replicas, backups, access removal, key destruction and provider evidence.

75
New cards

What is an End-of-Life (EOL) system?

A system that no longer receives vendor support or security updates.

76
New cards

Why does EOL risk increase over time?

New vulnerabilities appear while the unsupported system receives no fixes.

77
New cards

What is the preferred response to an EOL system?

Upgrade or replace it.

78
New cards

Give one temporary control for an unavoidable EOL system.

Network isolation with tightly restricted access.

79
New cards

What is patch currency?

How current an asset is against available security updates.

80
New cards

Why does patch currency reduce attack surface?

It closes known vulnerabilities that attackers could otherwise exploit.

81
New cards

What three factors guide patch priority?

Asset criticality, CVSS severity and exposure/exploitability.

82
New cards

Which patch should normally be prioritised first?

A critical exploitable vulnerability on an internet-facing crown jewel.

83
New cards

Why must patching be verified?

A patch instruction or ticket does not prove the update was successfully installed.

84
New cards

How can patch installation be verified?

Use vulnerability scanning or configuration-compliance checks after deployment.

85
New cards

Which vulnerability was central to the Equifax breach?

Apache Struts CVE-2017-5638.

86
New cards

What sensitive data did Equifax hold?

Identity and credit data such as SSNs, birth dates, addresses and credit histories.

87
New cards

What was Equifax’s unmanaged-asset failure?

The vulnerable dispute-portal server was missing from the CMDB.

88
New cards

How did the missing CMDB entry affect patching?

No accountable owner identified and patched the affected server.

89
New cards

What control addresses Equifax’s unmanaged asset?

Automated asset discovery reconciled with a complete CMDB and named ownership.

90
New cards

What was Equifax’s certificate failure?

An inspection certificate had expired for 19 months, blinding traffic monitoring.

91
New cards

What control addresses certificate expiry?

A certificate inventory with owners, expiry alerts, renewal and monitoring tests.

92
New cards

What was Equifax’s patch-verification failure?

It issued an alert but did not automatically confirm that patches were applied.

93
New cards

What control addresses the verification gap?

Post-patch vulnerability scanning with escalation of unresolved critical findings.

94
New cards

What does ACV stand for in the Equifax case?

Asset absent, Certificate expired, Verification absent.

95
New cards

What is the key Equifax lesson?

Asset discovery, patch verification and working monitoring are separate defence layers.

96
New cards

What is availability?

Authorised users can access required systems and data when needed.

97
New cards

Name three availability controls.

Redundancy, failover and tested backups/recovery plans.

98
New cards

What is a failover cluster?

Multiple nodes arranged so another node takes over when one fails.

99
New cards

What is active-passive failover?

A standby node waits to take over from the active primary node.

100
New cards

What is active-active clustering?

Multiple nodes serve traffic together and share the workload.