1/190
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is an organisational asset?
Anything of value that helps an organisation achieve a business objective.
What are the four Week 2 asset types?
HaS-PeD: Hardware, Software, Personnel and Data/information.
What is a hardware asset?
A physical technology asset, such as a server, laptop, router or POS terminal.
Give two hardware-asset examples.
A server and a network router.
What is a software asset?
A program or service that enables hardware or business activities.
Give two software-asset examples.
An operating system and a customer-ordering application.
Why is personnel considered an asset?
People provide knowledge, skills, judgement and relationships needed for business tasks.
Give two examples of personnel assets.
A system administrator and an incident responder.
What is a personnel single point of failure?
One person is the only individual able or authorised to perform a critical task.
What is the main risk of a personnel single point of failure?
The task or objective may stop if that person leaves or is unavailable.
Name three controls for personnel dependency.
Cross-training, documented procedures and succession/backup staffing.
What is a data/information asset?
Information with business value, regardless of its format or storage location.
Give three examples of data assets.
Customer records, credentials and system configuration data.
What does HaS-PeD stand for?
Hardware, Software, Personnel and Data.
What is a manual business activity?
An activity performed mainly by a person, such as approving a refund.
What is an automated business activity?
An activity performed by a system, such as automatically calculating tax.
Why map both manual and automated activities?
To reveal all people, process and technology dependencies supporting an objective.
What does an asset inventory primarily show?
What assets exist and where they are located.
How is asset management broader than inventory?
It governs ownership, value, configuration, protection, lifecycle and risk.
What identifier should be recorded for hardware?
A unique asset number or serial number.
Why record the owner or custodian of an asset?
So someone is accountable for its security, maintenance and lifecycle decisions.
Why record an asset’s location?
To find, protect, audit and recover the correct asset.
What software details should be inventoried?
Product name, version/build, licences, support status and installed updates.
What is a CMDB?
A Configuration Management Database that records configuration items and their relationships.
What is a configuration item (CI)?
A managed component such as a device, application, service, database or document.
Why are CMDB relationships important?
They show which services and objectives depend on each asset.
How do you read a dependency map DOWN?
From the objective toward the tasks, functions and assets it depends on.
How do you read a dependency map UP?
From an asset failure toward the business objectives it will affect.
What does AIDR stand for in CMDB benefits?
Audits, Incidents, Decommissioning and Recovery.
How does a CMDB help incident response?
It identifies affected services, dependencies, owners and response priorities.
How does a CMDB help decommissioning?
It reveals dependencies and helps prevent orphaned systems, accounts or data.
What makes a CMDB unreliable?
Incomplete, outdated or unverified asset and relationship data.
How can a business keep its CMDB complete?
Use automated discovery, regular audits, reconciliation and named owners.
What is shadow IT?
Technology used without formal IT or security approval.
Give one example of shadow IT.
A team stores customer files in an unapproved personal cloud account.
Why is shadow IT difficult to protect?
It may be invisible to inventory, patching, backup, monitoring and retention controls.
Name one useful response to shadow IT.
Discover it, assess the risk and provide a safe approved alternative.
What is asset criticality?
How important an asset is to achieving a business objective.
Is asset criticality the same as purchase price?
No. A cheap asset may support a service whose failure causes major losses.
What should a criticality assessment consider?
Operational, financial, safety, legal/regulatory and reputational impact.
What are the three asset-value lenses?
RRR: Replacement cost, Revenue/operational impact and Regulatory/liability exposure.
What is the replacement-cost lens?
The cost of rebuilding, restoring or replacing the asset and lost productivity.
What is the revenue/operational-impact lens?
The money or service capacity lost during disruption or downtime.
What is the regulatory/liability lens?
Fines, notification costs, litigation, compensation and other legal exposure.
Why can liability exceed replacement cost?
The technology may be cheap, while a breach triggers large fines, claims and notification costs.
What does B-COR stand for?
Business need, Create/buy, Operate and Retire.
What is the asset lifecycle?
The stages from business need and acquisition through operation to retirement/disposal.
What security action is essential when acquiring an asset?
Record it, assign an owner and establish a secure configuration.
What security actions occur during asset operation?
Maintain, patch, monitor, review access and update inventory records.
What security action is essential at asset retirement?
Sanitise its data and update the inventory/CMDB.
What is the first data-lifecycle stage?
Collect or create the data.
What should happen during data collection?
Collect only necessary data and classify it appropriately.
What should happen when data is stored?
Apply suitable access control, encryption, backup and retention protections.
What should happen when data is shared?
Authorise the recipient and protect the transmission.
What should happen when data reaches retention expiry?
Destroy it securely unless law or business need requires continued retention.
Why must data classification influence disposal?
More sensitive data requires stronger protection against recovery.
What is CLEAR sanitisation?
Logical wiping or overwriting that defeats ordinary recovery methods.
When is CLEAR generally suitable?
When media will remain under organisational control for internal reuse.
What is the memory image for CLEAR?
🧽 Wiping a whiteboard clean.
What is PURGE sanitisation?
A method that makes recovery infeasible even with advanced techniques.
Name two PURGE methods.
Degaussing compatible magnetic media and cryptographic erasure.
What is cryptographic erasure?
Securely destroying encryption keys so encrypted data becomes unreadable.
When is PURGE generally suitable?
Before sensitive media leaves organisational control, if policy permits reuse.
What is the memory image for PURGE?
🧲🔑 Removing the magnetic trace or the encryption key.
What is DESTROY sanitisation?
Physically rendering media unusable and its data irrecoverable.
Name three DESTROY methods.
Shredding, crushing/disintegration and incineration.
When is DESTROY generally required?
For extremely sensitive data or failed media that cannot be securely purged.
What is the memory image for DESTROY?
💥 No readable device remains.
What does CPD stand for?
Clear, Purge and Destroy.
What is the CPD strength order?
Clear → Purge → Destroy.
Why is ordinary file deletion insufficient?
It often removes only a reference; recoverable data blocks may remain.
What evidence should follow sanitisation?
Verification, chain-of-custody records and updated inventory/CMDB status.
Why is cloud data deletion difficult?
Copies may remain in replicas, snapshots, backups, logs and multiple regions.
What should a cloud-deletion plan address?
Retention, replicas, backups, access removal, key destruction and provider evidence.
What is an End-of-Life (EOL) system?
A system that no longer receives vendor support or security updates.
Why does EOL risk increase over time?
New vulnerabilities appear while the unsupported system receives no fixes.
What is the preferred response to an EOL system?
Upgrade or replace it.
Give one temporary control for an unavoidable EOL system.
Network isolation with tightly restricted access.
What is patch currency?
How current an asset is against available security updates.
Why does patch currency reduce attack surface?
It closes known vulnerabilities that attackers could otherwise exploit.
What three factors guide patch priority?
Asset criticality, CVSS severity and exposure/exploitability.
Which patch should normally be prioritised first?
A critical exploitable vulnerability on an internet-facing crown jewel.
Why must patching be verified?
A patch instruction or ticket does not prove the update was successfully installed.
How can patch installation be verified?
Use vulnerability scanning or configuration-compliance checks after deployment.
Which vulnerability was central to the Equifax breach?
Apache Struts CVE-2017-5638.
What sensitive data did Equifax hold?
Identity and credit data such as SSNs, birth dates, addresses and credit histories.
What was Equifax’s unmanaged-asset failure?
The vulnerable dispute-portal server was missing from the CMDB.
How did the missing CMDB entry affect patching?
No accountable owner identified and patched the affected server.
What control addresses Equifax’s unmanaged asset?
Automated asset discovery reconciled with a complete CMDB and named ownership.
What was Equifax’s certificate failure?
An inspection certificate had expired for 19 months, blinding traffic monitoring.
What control addresses certificate expiry?
A certificate inventory with owners, expiry alerts, renewal and monitoring tests.
What was Equifax’s patch-verification failure?
It issued an alert but did not automatically confirm that patches were applied.
What control addresses the verification gap?
Post-patch vulnerability scanning with escalation of unresolved critical findings.
What does ACV stand for in the Equifax case?
Asset absent, Certificate expired, Verification absent.
What is the key Equifax lesson?
Asset discovery, patch verification and working monitoring are separate defence layers.
What is availability?
Authorised users can access required systems and data when needed.
Name three availability controls.
Redundancy, failover and tested backups/recovery plans.
What is a failover cluster?
Multiple nodes arranged so another node takes over when one fails.
What is active-passive failover?
A standby node waits to take over from the active primary node.
What is active-active clustering?
Multiple nodes serve traffic together and share the workload.