Privilege Aggregation and Creep

Privileges

Privilege Aggregation and Creep

Privilege Aggregation and Creep is the cause and effect. Here’s my definition:

The privileges granted to a subject accumulate, e.g. because of promotions or rotations over time, to the extent that the aggregation of the privileges exceeds what the subject needs to do his or her duty or violates the security policies.

Confusion Point

Aggregation and Inference in the Context of Privacy

I treat aggregation as the means, while inference as the end. It’s just a process of data collection and reasoning by induction and deduction to make a conclusion.

Example: Aggregation Scam

Continue reading

CISSP PRACTICE QUESTIONS – 20191009

Effective CISSP Questions

Your company decides to start the business of selling toys online and shipping globally. The E-Commerce system that supports the new business will be developed in-house. The development team is designing the software architecture that shall be secure, scalable, responsive, and easy to maintain to support global operations. Which of the following is the least appropriate?
A. Divide concerns into four layers but deploy the solution in three tiers
B. Follow open design and use an open cipher to encrypt confidential data
C. Require strong passwords at least 15 characters to ensure security
D. Validate privileges with the price of the performance every time access occurs
Continue reading

Due Diligence and Due Care – Part 1

The following is my definition of Due Diligence and Due Care. As I am not a lawyer, I just interpret them from my point of view and avoid to relate them to the context of the laws.

Due Diligence

The core concept of due diligence is about making informed decisions. A decision should be made based on sufficient information and justifications. If a decision-maker can’t do so, he or she doesn’t exercise due diligence. The decision-maker often implies the management.

CISSP PRACTICE QUESTIONS – 20190915

  • Security Due Diligence
  • Financial Due Diligence
  • Operational Due Diligence
  • Legal Due Diligence
  • Human Rights Due Diligence

Due Care

The core concept of due care is about a reasonable person’s compliance and best efforts. A reasonable person should do his or her duty according to the organization’s policies, standards, and procedures; and with best efforts. Lack of due care is called negligence. The reasonable person role applies to everyone.


Due Diligence

  • detailed assessment of one or more business processes or production lines, culture, assets, liabilities, intellectual property, judicial and financial situation in order to make the outsourcing decisions. (ISO 37500:2014)
  • detailed assessment conducted by an economic operator to evaluate a supplier’s compliance with the guidance principles.
    Note 1 to entry: In the context of the guidance principles, due diligence is conducted through second-party audits or third-party audits and, wherever feasible, regularly monitored through government inspections and oversight. (ISO/IWA 19:2017)
  • comprehensive, proactive process to identify the actual and potential negative social, environmental and economic impacts of an organization’s decisions and activities over the entire life cycle of a project or organizational activity, with the aim of avoiding and mitigating negative impacts. (ISO 26000:2010)
  • process through which organizations proactively identify, assess, prevent, mitigate and account for how they address their actual and potential adverse impacts as an integral part of decision-making and risk management. (ISO 20400:2017)
  • compilation, comprehensive appraisal and validation of information of an organization required for assessing accuracy, commercial integrity, financial stability and functional competence integrity at the appropriate stage of the agreement sourcing process (ISO 41011:2017)
  • process to further assess the nature and extent of the bribery risk and help organizations make decisions in relation to specific transactions, projects, activities, business associates and personnel. (ISO 37001:2016)

CISSP PRACTICE QUESTIONS – 20191008

Effective CISSP Questions

Your company decides to start the business of selling toys online and shipping globally. The E-Commerce system that supports the new business will be developed in-house. The development team is evaluating the source code repository with concerns such as source code security, integration, and deployment support. Which of the following is the least appropriate?
A. Use common file systems, e.g. NTFS or ext4 to support the code repository
B. Connect to the central code repository using SSH
C. Push or upload code to the central code repository with basic authentication or unencrypted credential over HTTPS
D. Conduct integration tests before the new code are pushed or uploaded to the central code repository to ensure code quality
Continue reading

CISSP PRACTICE QUESTIONS – 20191007

Effective CISSP Questions

Your company decides to start the business of selling toys online and shipping globally. The E-Commerce system that supports the new business will be developed in-house by an integrated product team (IPT). In a meeting, the COO is concerned with performance issues resulting in loss of customer orders because of transaction timeout or customer impatience. Which of the following is the most appropriate to address this concern?
A. Use client scripts to simulate customer’s behavior
B. Conduct Fagan analysis to ensure source code is optimal
C. Install a debugger to monitor the performance of the production system
D. Implement a content distribution network to offload web server performance
Continue reading

CISSP PRACTICE QUESTIONS – 20191006

Effective CISSP Questions

Your company decides to start the business of selling toys online and shipping globally. The E-Commerce system that supports the new business will be developed in-house by an integrated product team (IPT). In a meeting, the IPT is concerned with privacy issues and discussing the security controls to mitigate the data breach risk. Which of the following is least likely implemented?
A. Role-based Access Control
B. Rule-based Access Control
C. Mandatory Access Control
D. Attribute-based Access Control

Continue reading

Get Started Your CISSP Journey (Full)

CISSP is one of the most challenging exams ever because of its comprehensive perspectives and requirements of solid conceptual level understanding and in-depth insights into managerial and technical issues.

The following is the series to get started your CISSP journey:

CISSP PRACTICE QUESTIONS – 20191005

Effective CISSP Questions

Your company decides to start the business of selling toys online and shipping globally. The E-Commerce system that supports the new business will be developed in-house by an integrated product team (IPT). In a meeting, the IPT is discussing the solution using UML diagrams from a variety of views, such as user, logical, process, implementation, and deployment views. Which of the following is least likely used in the meeting?
A. Use Cases
B. DREAD (Damage, Reproducibility, Exploitability, Affected Users, and Discoverability)
C. CWE (Common Weakness Enumeration)
D. Code Review

Continue reading