CISSP PRACTICE QUESTIONS – 20200212

Effective CISSP Questions

Your organization is developing a Transportation Management System (TMS) that processes two types of data: air and ground transportation data. It is about time to categorize the system to determine baseline security controls. Which of the following roles least participates in the system categorization process?
A. Executive management
B. Data custodian
C. Information owner
D. System owner

Continue reading

CISSP PRACTICE QUESTIONS – 20200210

Effective CISSP Questions

A USB dongle used by an engineer in the R&D department lost on the ground is found without a physical label identifying the sensitivity of the information contained. According to the data policy, all storage media shall be labeled. Which of the following action should be taken first?
A. Label the USB dongle at the highest level of sensibility
B. Classify and label the USB dongle as initial level
C. Examine the USB dongle on a secured workstation and label it based on the result
D. Inform the owner of the USB dongle and ask him to label it

Continue reading

CISSP PRACTICE QUESTIONS – 20200209

Effective CISSP Questions

A desktop personal computer with an ATA hard drive used by an engineer in the R&D department is going to be retired. According to the media marking policy, the hard drive with confidential data shall be purged so as not to be recovered. Which of the following sanitization operation can not meet the requirement?
A. Use the block erase method
B. Write zeros in all bytes of logical sectors
C. Overwrite the internal media with a constant value
D. Change the internal encryption keys that are used for user data

Continue reading

CISSP PRACTICE QUESTIONS – 20200208

Effective CISSP Questions

Information is the asset of the organization. Which of the following refers to the careful and responsible management of information belonging to the organization as a whole, regardless of the entity or source that may have originated, created, or compiled the information?
A. Information custodianship
B. Information assurance
C. Information stewardship
D. Information ownership

Continue reading

CISSP PRACTICE QUESTIONS – 20200207

Effective CISSP Questions

Organizations are facing different types of risks that hinder the pursuit of organizational objectives. As a security professional, you are a member of the risk management program. Which of the following is the least likely to conduct when establishing the risk context?
A. Determine risk tolerance
B. Provide a reference risk model
C. Build enterprise architecture
D. Assign a risk executive
Continue reading

What is Mission?

strategicplanning

Mission is “organization’s purpose for existing as expressed by top management.”

ISO 22886

Based on the ISO 22886 and general management concept, I would extend and define “mission” as follows:

“Mission” is the organization’s purpose for existing (the reason for being) as expressed by top management that guides the choice of the context in which the organization operates, provision of services and products, formulation of its vision and long-term goals, and the institutionalization of its tasks, duties, or functions.

The NIST FARM Multi-Tiered Risk Management

NIST FARM deals with risk in terms of three tiers: organization, mission/business processes, and information systems. Organizations generally conduct different types of mission functions composed of a variety of business processes that are supported by information systems to achieve organizational objectives.

NIST FARM-MultiTiered
Source: NIST SP 800-39

Continuity Guidance Circular 2 (CGC 2)

  • According to the Continuity Guidance Circular 2 (CGC 2) of the Federal Emergency Management Agency (FEMA), a mission typically is something unique the organization does.
  • Mission Essential Functions (MEFs) are a broader set of essential functions that organizations must continue throughout or resume rapidly after a disruption of normal activities. MEFs are those functions that enable an organization to provide vital services, exercise civil authority, maintain the safety of the public, and sustain the industrial/economic base.
CGC2 Mission

GIA’s Missions

The organizational mission is typically documented as a mission statement. The missions of government departments or agencies are written in laws or regulations. For example, the missions of the National Geospatial-Intelligence Agency are defined in 10 U.S.C. 442 – Missions as follows:

NGA Missions 442

ISO 21001

The title of ISO 21001 is “Educational organizations — Management systems for educational organizations — Requirements with guidance for use”

fig_3
Figure 3 — EOMS strategy as related to mission and vision (Source: ISO 21001)
fig_2
Figure 2 — Representation of the structure of this document in the PDCA cycle (Source: ISO 21001)

References

Security Architects and Engineers

NIST FARM-Enterprise Architecture

Source: NIST SP 800-39

Security Architects and Engineers

  • Security architects ensure requirements are necessary and adequately addressed in the enterprise architecture.
  • Security engineers ensure requirements are integrated into systems throughout the system development life cycle (SDLC).

Federal Enterprise Architecture

Levels of Architectural Scope and Impact

Source: The Common Approach to Federal Enterprise Architecture (May 2, 2012)

Outcomes_Ouputs_Inputs

Source: Federal Enterprise Architecture Framework Version 2.0 (January 29, 2013)

References

CISSP PRACTICE QUESTIONS – 20200206

Effective CISSP Questions

You are the system owner of the newly implemented Transportation Management System in your organization. You have compiled a package of documentation for authorization to operate (ATO). Which of the following is least likely to be included in the authorization package?
A. Risk Management Strategy
B. Security and privacy plans
C. Security and privacy assessment reports
D. Executive summary
Continue reading

Security Authorization Approaches

Applying the NIST risk management framework

Matthew Metheny, in Federal Cloud Computing (Second Edition), 2017

Security Authorization Approaches

The security authorization process is based on three different approaches.126 The first, and most commonly used, is the traditional approach, which involves only one authorizing official. In this approach, a single authorizing official has both the responsibility and accountability for accepting security risks. Next is the joint authorization127 approach, which includes a shared interest, usually between multiple authorizing officials because the information system ties directly into the strategic mission or business processes. In this approach, the authorizing officials are collectively responsible and accountable for accepting the security risks.

The final approach is used when the mission or business processes are supported by more than one federal agency. This approach is known as the leveraged authorization approach and can be used to authorize an information system, commonly a shared service,128 that can be used by more than one agency based on the original authorization package without requiring reauthorization by the leveraging organization.

Owing to the complexity in implementing the leveraged authorization approach, it is the one used least often of the three, but offers the most cost savings.129 The leveraging organization, usually through an assigned authorizing official, leverages the original authorization130 by accepting the risks, and assesses only those additional requirements beyond the original security control baseline established by the original.131 For example, if the leveraging organization determines that there is insufficient information in the authorization package or inadequate security measures in place for establishing an acceptable level of risk, the leveraging organization may negotiate for additional security measures132 and/or security-related information [3].

Another option that may be used by an organization when multiple instances of the same information system (or subsystem) are deployed in a number of different operational environments is the application of a type authorization [3]. In a type authorization a single authorizing package is used to reflect a common view for all of the instances deployed across all locations where the information system is hosted (also known as site-specific controls133).

Source: https://www.sciencedirect.com/topics/computer-science/authorization-process