CISSP考试学习之道--第一章 安全和风险管理1

  • 重要概念:




  •      知识点:

      a .严格访问控制、入侵检测、哈希等方式可以对抗影响完整性的威胁


      c. 三原则相关的控制措施:

         可用性:RAID、集群(Clustering)、负载均衡、冗余数据和电源线、软件和数据备份、影子盘(Disk shadowing)、场地租凭和场外设施(Co- ocation and offsite facities)、回滚功能、故障转移配置( Failover configurations)。


         保密性:加密存储中数据(整盘、数据库)、加密传输中数据( IPSec、TLs、PpTP、SSH)、访问控制(物理和技术)。


  • 重要概念:

      脆弱性( vulnerability)是 Weaknesses or gaps in a security program that can beexploited by threats to gain unauthorized access to an asset

      威胁( threat)是 Anything that can exploit a vulnerability, intentionally or accidentally, and obtain, damage, or destroy an asset.

      风险(risk)是 The potential for loss, damage or destruction of an asset as aresult of a threat exploiting a vulnerability.

      Risk is the intersection of assets threats and vulnerabilities

      Risk Threat X Vulnerability

      控制( control),或者对策( countermeasure)是用来防护(减少)潜在的风险的手段


  • 知识点 

       控制类型可以分为管理( administrative)控制、技木( technical)控制和物理( physical)控制3种。管理控制如安全文档、冈险管理、人事安全和训练。技术控制如防火墙、IDS、加密、身份和认证。物理控制如安全守卫、锁、栅栏、灯光。 

       安全控制按功能分可以分为阻止型( preventive)、检测型( detective)、改正型( corrective)、威l型( deterrent)、恢复型( recovery)和补偿型( compensating)

       安全程序(security program)是一个由许多实体组成的架构,如逻辑的、物理的、管理的保护机制,规程,商业流程以及所有一起工作为环境提供保护的人员。


       1.规划和组织( Plan and organize)

       2.实现( Implement)

       3.运营和维护( Operate and maintain)

       4.监测和评估( Monitor and evaluate)

       蓝图( Blueprints)是为待走商业需求开发和设计安全需求的重要工具,是安全专家的用武之地,蓝图必须基于管理要求、商业驱动和法律义务定制化去满足组织的安全需求。



       安全程序开发( security program development):

       ISO/EC 2700039J--International standards on how to develop and maintain an ISMS developed by Iso and IEC

       企业架构开发( enterprise architecture development):

       Zachman Framework--Model for the development of enterprise architectures developed by John Zachman

       TOGAF--Model and methodology for development of enterprise architecutres developed by The Open Group

       RDODAF--U.. Department of Defense architecture framework that ensures interoperability of systems to meet military mission goals

       MODAF--Architecture framework used mainly in military support missions developed by the British Ministry of Defense

       SABSA model--Model and methodology for development of information security enterprise architectures

       安全控制开发( security control development)

       COBIT 5--A business framework to allow for IT enterprise management and governance that was developed by Information Systems Audit and Control Association(SACA)

       NIST SP 800-53--Set of controls to protect U.S. federal systems developed by the National Institute if Standards and Technology

       流程管理开发( process management development)

               ITIL--Processes to allow for IT service management developed by the United Kingdoms‘s Office of Government Commerce

               Six Sigma--Business management strategy that can be used to carryout process improvement

               Capability Maturity Model Integration(CMMI)--Organizationaldevelopment for process improvement developed by Carnegie Mellon University









         Zachman Architecture framework:使用6个疑问词(what/how/ where/who/when/why)和不同视角(高管/业务经理/系统架构师/工程师/技术员)相交构成的二雉模型。

         TOGAF(The Open group Architecture Framework可以用来开发4种架构类型:商业架构、数据架构、应用架构和技术架构,不同的架构允许从不同的视角去了解企业。

         DODAF( Department of Defense Architecture Framework)湎面向军方的架构框架关注命令、控制、通信、计算机、情报、监视、侦察系统和流程MODAF。



        SABSA Sherwood Applied Business Security Architecture一个企业安全架构和服务管理的框架和方法学,分层( contextual, conceptual,logical, physical, component, operational) 


         战略匹配 (strategic alignment:企业安全架构应该符合商业驱动、管理和法律的要求;

        商业使能( business enablement):安全不应该成为商业活动的绊脚石,应该为新的商业;

        活动提供安全机制从而帮助组织壮大,如使能远程办公、电子银行等过程增强( process enhancement):在将安全组件集成到商业流程的过程中同时实现流程优化和标准住化;

        安全实效( security effectiveness):关注获得的ROI、满足SLA,便于管理层知道安全解决方案带来的实际效果。















