CC · Domain 1
Security Principles
About 26% of the exam
The CIA triad and its neighbors
- Confidentiality
- disclosure only to authorized people
- Integrity
- accurate, complete and unaltered
- Availability
- accessible when it is needed
- Authenticity
- the source is genuine
- Non-repudiation
- cannot deny sending or signing
- Privacy
- control over personal information
Ask what the incident broke: a changed record is integrity, an outage is availability, a leak is confidentiality
Identification through accounting
- Identification
- claiming who you are
- Authentication
- proving that claim
- Authorization
- what you may do
- Accounting
- recording what you did
- Something you know
- password, passphrase, PIN
- Something you have
- token, smart card, phone
- Something you are
- fingerprint, face, iris
- Multi-factor
- two different categories, not two passwords
Privacy basics
- Collect only what you need
- State why you collect it
- Keep it only while needed
- Let people correct their data
- Consent must be freely given
- PII identifies a specific person
- PHI is protected health information
- GDPR protects people in Europe
Risk vocabulary
- Asset
- anything of value to protect
- Threat
- something that could cause harm
- Threat actor
- the person or group behind it
- Vulnerability
- the weakness that is exploited
- Risk
- likelihood combined with impact
- Threat vector
- the path the threat takes
- Residual risk
- what remains after controls
- Risk tolerance
- variation the organization accepts
Assessing and treating risk
Identify
- List assets and their value
- Name the threats to each
- Find vulnerabilities that connect them
- Risk exists only when both meet
Analyze
- Qualitative uses high, medium, low
- Quantitative uses monetary figures
- SLE is value times exposure factor
- ALE is SLE times ARO
- Rank by annualized loss
Treat
- Avoid: stop the activity
- Mitigate: reduce likelihood or impact
- Transfer: insurance or outsourcing
- Accept: management signs it off
- Ignoring is not a treatment
Acceptance is a documented decision by a named owner; silence about a known risk is negligence, not acceptance
The three control categories
Physical
- Fences, bollards, lighting, locks
- Badge readers and turnstiles
- Access control vestibule stops tailgating
- Guards apply human judgment
- Cameras record for later review
Technical
- Firewalls and access control lists
- Encryption at rest and moving
- Antivirus and endpoint protection
- Multi-factor authentication systems
- Logging and monitoring tools
Administrative
- Policies, standards and procedures
- Security awareness training
- Background checks before hiring
- Separation of duties and rotation
- A signed acceptable use agreement
The category says who or what enforces the control; the function says whether it deters, prevents, detects or corrects
Governance documents
- Law
- enacted by a government
- Regulation
- issued under a law
- Policy
- senior intent, high level, mandatory
- Standard
- the mandatory specifics
- Procedure
- the steps in order
- Guideline
- advice, not compulsory
Authority runs downward: law, regulation, policy, standard, procedure, with guidelines advisory only
The ISC2 Code of Ethics
- Protect society and infrastructure
- Act honorably and legally
- Serve principals diligently
- Advance the profession
- The canons apply in that order
- Society outranks the employer
- Report unethical requests, never comply
- Breaching the code risks certification
Due care and due diligence
- Due diligence investigates before deciding
- Due care is acting prudently afterwards
- Negligence is knowing and doing nothing
- Document the decision either way
- Vendor checks happen before signing
- Patching promptly shows due care
Defensive principles
- Defense in depth layers controls
- Least privilege grants only what is needed
- Need to know narrows it further
- Separation of duties splits critical tasks
- Two-person rule for high value actions
- Job rotation exposes hidden fraud
- Implicit deny blocks anything unlisted
Control functions
- Deterrent
- makes them think twice
- Preventive
- stops it happening
- Detective
- notices that it happened
- Corrective
- puts things back afterwards
- Compensating
- substitute when the ideal is impossible
- Directive
- instructs the expected behavior
Frameworks and laws to recognize
- ISO 27001
- requirements for an ISMS
- NIST CSF
- identify, protect, detect, respond, recover
- GDPR
- European personal data protection
- HIPAA
- United States health information
- PCI DSS
- card data security requirements
- SOC 2
- report on service provider controls
- ISC2 canons
- four, applied in order
Key formulas
- Risk
- likelihood times impact
- SLE
- asset value times exposure factor
- ALE
- SLE times annual rate of occurrence
- ARO
- how many times per year
- Cost test
- control costs less than ALE
Rapid recall
- CIA
- confidentiality, integrity, availability
- AAA
- authentication, authorization, accounting
- MFA
- two different factor categories
- PII
- identifies a specific person
- PHI
- health data about a patient
- SLE, ALE, ARO
- the quantitative risk trio
- Residual risk
- left over after controls
Reference strip: principles, risk, controls, ethics
Principles
- CIA plus authenticity and non-repudiation
- Privacy and data minimization
- Least privilege and need to know
- Defense in depth, implicit deny
Risk words
- Asset, threat, vulnerability, risk
- Likelihood, impact, residual risk
- Appetite, tolerance, risk owner
- Avoid, mitigate, transfer, accept
Controls
- Physical, technical, administrative
- Deterrent, preventive, detective, corrective
- Compensating and directive
- Separation of duties, job rotation
Governance
- Law, regulation, policy, standard
- Procedure and guideline
- Due care and due diligence
- Owner, custodian, user roles
Ethics
- Protect society and the common good
- Act honorably, honestly, legally
- Serve principals diligently
- Advance and protect the profession
Quick exam traps
- Trap: A password plus a PIN counts as multi-factor
- Trap: Enough controls can reduce risk to zero
- Trap: Ignoring a known risk is the same as accepting it
- Trap: The employer comes first under the ISC2 canons
- Trap: A guideline must be followed exactly like a standard
- Trap: Due care and due diligence describe the same activity
- Trap: Availability matters least of the three properties
cybercertprep.com · original revision sheet written from the public body of knowledge