Ans- The process of verifying or testing that the claimed identify is valid is

Study Guides Aug 1, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

CISSP - Domain 1

Identification (Ans- Is the process by which a subject professes an identity and accountability is initiated.

Authentication (Ans- The process of verifying or testing that the claimed identify is valid is authentication.

Authorization (Ans- The process of authorization ensures that the requested activity or access to an object is possible given the rights and privileges assigned to the authenticated.

Auditing (Ans- Auditing, or monitoring, is the programmatic means by which a subject's actions are tracked and recorded for the purpose of holding the subject accountable for their actions while authenticaded on a system.

Accountability (Ans- Effective accountability relies on the capability to prove a subject's identity and track their activities.

Protection Mechanisms (Ans- Protection mechanisms are common characteristics of security controls.

Layering (Ans- Layering, also known as "defense in depth", is simply the use of multiple controls in a series.

  • / 3

Abstraction (Ans- Is used to define what types of data an object can contain, what types of functions can be performed on or by that object, and what capabilities that object has.

Data Hiding

(Ans- Is exactly what it sounds like: preventing data from being discovered

or accessed by a subject by positioning the data in a logical storage compartment that is no accessible or seen by the subject.

Encryption (Ans- A standard method for encoding data.

Discuss and describe the CIA Triad (Ans- Confidentiality - is the principle that objects are not disclosed to unauthorized subjects.Integrity - is the principle that objects retain their veracity and are intentionally modified by only authorized subjects.Availability - is the principle that authorizes subjects are granted timely and uninterrupted access to object.

What are the requirements to hold a person accountable for the actions of their user account?(Ans- The requirements of accountability are identification, authentication, authorization, and auditing. Each of these components needs to be legally supportable to truly hold someone accountable for their actions.

Describe the benefits of change control management.(Ans- The goal of change control management is to ensure that any change does not lead to reduced or compromised security. Change management is also responsible for making it possible to roll back any change to a previous secured state.

  • / 3

What are the seven major steps or phases in the implementation of a classification scheme?(Ans-

  • Identify the custodian, and define their responsibilities.
  • Specify the evaluation criteria of how the information will be classified
  • and labeled.

    3.Classify and label each resource. ( the owner conducts this step, but a supervisor should review it).

    4.Document any exception to the classification policy that are discovered, and integrate them into the evaluation criteria.

    5.Select the security controls that will be applied to each classification level to provide the necessary level of protection.

    6.Specify the procedures for declassifying resources and the procedures for transferring custody of a resource to an external entity.

    7.Create an enterprise-wide awareness program to instruct all personnel about the classification system.

Name the six primary security roles as defined by ISC for CISSP (Ans-

  • Senior Manager.
  • Security Professional/IT
  • Data Owner.
  • Data Custodian.
  • User
  • Auditor

What are the four components of a complete organizational security policy and their basic purpose?(Ans-

1. Security Policies: are broad security statements.

2. Security Standards: are tactical documents that define steps or methods

to accomplish the goals and overall direction defined by security policies.

3. Guidelines: are usually system specific and often refer to an industry or

government standard such as ITSec, NIST, or CIS. Often are used when there is not an appropriate procedure.

  • / 3

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: Study Guides
Added: Aug 1, 2025
Description:

CISSP - Domain 1 Identification (Ans- Is the process by which a subject professes an identity and accountability is initiated. Authentication (Ans- The process of verifying or testing that the clai...

Get this document $30.00