Security+ · Domain 5
Security Program Management and Oversight
About 20% of the exam
The document hierarchy
- Policy
- high level intent, board approved
- Standard
- mandatory specifics such as key length
- Procedure
- step by step instructions
- Guideline
- recommended, not mandatory
- Playbook
- response steps for one scenario
- Baseline
- the minimum configuration accepted
Policy says what and why, standard says how much, procedure says how, guideline merely suggests
Policies to be able to name
- Acceptable use governs company resources
- Information security policy sets the intent
- Business continuity and disaster recovery
- Incident response policy and playbooks
- Software development lifecycle policy
- Change management policy and board
- Onboarding and offboarding procedures
- Review and revise on a schedule
Governance and data roles
- Board
- owns the risk appetite
- Committee
- reviews and recommends to the board
- Centralized
- one team sets everything
- Decentralized
- business units decide locally
- Data owner
- accountable for the data
- Data controller
- decides purpose and means
- Data processor
- acts on the controller instruction
- Data custodian
- runs the day to day controls
- Data steward
- quality, meaning and use
The risk process
- Identify
- Assess
- Analyze
- Treat
- Report
- Monitor
- Assessment may be ad hoc or recurring
- Continuous assessment keeps the register live
- Every risk has a named owner
- Key risk indicators warn early
- Crossing the threshold triggers escalation
Risk analysis and the numbers
Formulas
- SLE equals asset value times exposure factor
- ALE equals SLE times ARO
- ARO is events expected per year
- Exposure factor is the percentage lost
- A control should cost less than ALE
Terms
- Appetite: expansionary, neutral or conservative
- Tolerance is the variance around appetite
- Inherent risk sits before controls
- Residual risk remains after controls
- Qualitative uses high, medium, low
Worked example
- Asset 100,000 with exposure factor 0.3
- SLE is therefore 30,000
- ARO of 0.5 means once biennially
- ALE is therefore 15,000
- Spend under 15,000 to mitigate
Quantitative gives money and comparability, qualitative gives speed; most programs run both and report money to the board
Third-party risk
Assessment
- Penetration test the vendor connection
- Right to audit clause in the contract
- Ask for evidence of internal audits
- Independent assessment or service audit report
- Supply chain analysis reaching subprocessors
Agreements
- SLA sets measurable service targets
- MOU and MOA state shared intent
- MSA frames the ongoing relationship
- SOW or work order scopes delivery
- NDA protects shared confidential information
- BPA governs a joint business venture
Monitoring
- Questionnaires on a defined cycle
- Rules of engagement before any testing
- Check for conflicts of interest
- Reassess whenever the service changes
Treatment and the register
- Mitigate
- add controls to reduce it
- Transfer
- insurance or contractual shift
- Accept
- documented, with a named owner
- Avoid
- stop doing the activity
- Exemption
- approved permanent deviation
- Exception
- temporary, with an expiry date
- Risk register
- risk, owner, score, treatment
- Key risk indicator
- metric that warns of movement
Business impact analysis
- RTO
- how long until service returns
- RPO
- how much data loss is tolerable
- MTTR
- average time to repair
- MTBF
- average time between failures
- MTD
- the outer limit of downtime
- Work recovery time
- verify and catch up afterwards
- Critical function
- what the business cannot lose
RTO is time to be back, RPO is data you can afford to lose, so backup frequency must beat the RPO
Compliance and its teeth
- Internal and external reporting duties
- Fines and regulatory sanctions
- Loss of a license to operate
- Contractual penalties and lost business
- Reputational damage outlasts the fine
- Attestation and acknowledgement by staff
- Automate evidence collection where possible
- Due care acts, due diligence checks
Privacy
- Data subject
- the living person described
- Controller
- decides why and how
- Processor
- acts on documented instruction
- Data inventory
- know what you hold
- Retention schedule
- delete once the purpose ends
- Right to erasure
- unless law requires keeping it
- Breach notification
- 72 hours under GDPR
- Cross-border transfer
- needs an approved safeguard
Audits, assessments and testing
- Internal audit
- own staff, reports to committee
- External audit
- independent third party opinion
- Regulatory examination
- the regulator inspects directly
- Self-assessment
- a team checks its own controls
- Attestation
- signed statement that controls exist
- Unknown environment
- tester told nothing up front
- Known environment
- tester given full detail
- Partially known
- some detail, saves setup time
- Passive reconnaissance
- no packets touch the target
- Active reconnaissance
- scanning and probing directly
Security awareness
- Phishing simulations with immediate coaching
- Measure report rate, not only clicks
- Teach recognition, response and reporting
- Insider threat and anomalous behavior
- Removable media and unknown cables
- Operational security for public posts
- Guidance for hybrid and remote work
- Initial training then recurring refreshers
- Role specific content beats generic slides
Key formulas
- SLE
- asset value times exposure factor
- ALE
- SLE times annual rate of occurrence
- ARO
- occurrences expected in a year
- Residual risk
- what is left after treatment
- Control test
- annual cost below the ALE
- Availability
- uptime divided by total time
- Failure cycle
- MTBF plus MTTR
Rapid recall
- Due care
- the prudent action taken
- Due diligence
- the homework done first
- Attestation
- someone signs for it
- Right to audit
- contract lets you inspect
- Conflict of interest
- the assessor is not independent
- Risk owner
- the person accountable, not security
- Legal hold
- stop deleting relevant records
Reference strip: govern, quantify, contract, prove
Govern
- Policy, standard, procedure, guideline
- Boards, committees, centralized or not
- Owner, controller, processor, custodian, steward
- External drivers: legal, regulatory, industry
Quantify
- SLE, ALE, ARO, exposure factor
- Qualitative versus quantitative analysis
- Appetite, tolerance, threshold, register
- RTO, RPO, MTTR, MTBF, MTD
Contract
- SLA, MOU, MOA, MSA, SOW
- NDA, BPA, right to audit
- Vendor questionnaires and due diligence
- Rules of engagement for testing
Prove
- Internal audit and audit committee
- External and regulatory examination
- Attestation and self-assessment
- Penetration testing and reconnaissance
Privacy
- Subject, controller, processor
- Inventory, retention, erasure
- Notification timelines and regulators
- Cross-border transfer safeguards
Quick exam traps
- Trap: Risk appetite and risk tolerance are the same measure
- Trap: Transferring risk to an insurer transfers accountability
- Trap: A policy and a standard mean the same thing
- Trap: RPO tells you how long the recovery will take
- Trap: Accepting a risk means nothing has to be documented
- Trap: A signed contract removes the need to monitor the vendor
- Trap: Awareness training is a one-off onboarding task
- Trap: Passing the audit proves the organization is secure
cybercertprep.com · original revision sheet written from the public body of knowledge