CISSP PRACTICE QUESTIONS – 20210215

Effective CISSP Questions

Your company charted a committee to evaluate an initiative to construct a data center in Taiwan located in the circum-Pacific seismic belt or ring of fire and subject to earthquakes. It will operate as a region of the global infrastructure for cloud services. The committee approved the investment despite the concern of frequent earthquakes. Which of the following is the best justification for the decision?
A. The reliability of the data center is assured.
B. The residual risk is higher than the risk appetite of the board.
C. The data center can be recovered within the recovery point objective.
D. The recovery time objective is less than the maximum tolerable downtime (MTD).

Continue reading

Ethics as Priority Cybersecurity Topic

I really love this old textbook, Ethics and the Conduct of Business by John R. Boatright! 

Cybersecurity education is now promoted in high schools in Taiwan. Students are learning the basic concept of cybersecurity and red team and blue team things. I seriously consider our Cybersecurity 101 shall start with “ETHICS.”

The new CISSP exam outline moving ethics to the very first topic has done an excellent job!!

The new CISSP Exam Outline, effective on May 1st.

CISSP PRACTICE QUESTIONS – 20210214

Effective CISSP Questions

As the head of research and development, you are classifying assets based on the corporate asset classification guideline. Which of the following is least likely to happen?
A. Identify the original purchase cost
B. Evaluate the impact of data compromises
C. Establish the classification scheme in terms of business value
D. Determine the security level to support mandatory access control

Continue reading

Investigation Types

An investigation is the collection and analysis of evidence for specific purposes.

Administrative Investigation

  • Administrative investigation means an internal investigation of alleged misconduct by an employee. (Law Insider)
  • Administrative Investigations are conducted by local management, local Personnel Representatives and/or Employee Relations in response to complaints or concerns that generally are personnel related and non-criminal in nature. For example, an administrative investigation may be initiated in response to any of the following conditions or allegations.
    – A grievance or complaint
    – Property misuse/damage/theft
    – Misconduct
    – Prohibited harassment or discrimination
    – Threatening, intimidating, or violent behavior
    – Violation of university policies, rules and/or standards of conduct, or
    – Violation of law. (NC State University)

Civil Investigation

  • A civil investigation uncovers and assembles evidence necessary for a civil trial.
    A civil trial is a type of court case involving two individual citizens who disagree on an issue that relates to their rights as citizens. For example, if one person sues another for damages caused by a domestic accident, the case will likely be conducted as a civil trial. Civil investigators are responsible for gathering the evidence essential to such a trial. (PI Now)
  • When civil matters occur, it is the responsibility of each party to properly prepare to defend its position whether going to trial or trying to settle outside of court. Civil cases are disputes between two parties where one party or both parties failed to fulfill an agreement, service, or uphold their legal obligation. (Global Intelligence Consultants)

Regulatory Investigation

  • Regulatory investigation meansa formal hearing, official investigation, examination, inquiry, legal action or any other similar proceeding initiated by a governmental, regulatory, law enforcement, professional or statutory body against you. (Law Insider)

Criminal Investigation

  • Criminal investigation is an applied science that involves the study of facts that are then used to inform criminal trials. (Wikipedia)
  • Applied to the criminal realm, a criminal investigation refers to the process of collecting information (or evidence) about a crime in order to:
    (1) determine if a crime has been committed;
    (2) identify the perpetrator;
    (3) apprehend the perpetrator; and
    (4) provide evidence to support a conviction in court. (JRank)

Investigation Standards, Guidelines, and Protocols

  1. WHO – Investigation Protocol
  2. CHS Alliance – Guidelines for Investigations
  3. Ombudsman Western Australia – Guidelines on Conducting Investigations
  4. Uniform Guidelines for Investigations
  5. The Australian Government Investigations Standards (AGIS)
  6. UNHCR Investigation Resource Manual
  7. ISO/IEC 27043:2015 — Information technology — Security techniques — Incident investigation principles and processes
  8. ISO/IEC 27041:2015 — Information technology — Security techniques — Guidance on assuring suitability and adequacy of incident investigative method
  9. Accident and incident investigation (ISO 9001:2015, ISO 14001:2015, and ISO 45001:2018)

References

Happy Lunar New Year!

Happy New Year! Ox’s Coming!

Today is the last day of the “mouse” year! The coming one is the Ox., a year of hard work.
I hope you enjoy your CISSP journey and get it done soon!

Best regards,
Wentz

2021/02/11

今天除夕, 農曆鼠年最後一天. 明天就進入牛年了, 剛好可以趁著全球經濟因疫情減緩之際辛勤耕耘, 為下一個機會作好準備! 祝大家身體健康, 學習愉快!!

CISSP PRACTICE QUESTIONS – 20210212

Effective CISSP Questions

You are concerned with session hijacking by a middle man replaying the session token stored in the HTTP cookie. Which of the following is the least effective control to mitigate the risk?
A. End-to-end encryption between the browser and the web server using TLS
B. Automatic log off if a session ends or expires
C. User data or input validation
D. Long and random Session ID

Continue reading

CISSP PRACTICE QUESTIONS – 20210211

Effective CISSP Questions

Your organization established a sound mechanism for authentication, authorization, and accounting by implementing systems for single sign-on, policy enforcement and decision, security information and event management, intrusion detection and prevention, etc. After an administrative investigation, a malicious employee was held accountable for the attempts to steal research and development secrets and got fired. Which of the following is the best perspective that justifies the punitive action?
A. Auditing
B. Authentication
C. Authorization
D. Accounting

Continue reading

Business Drivers and Enablers

Porter's Value Chain
Porter’s Value Chain

Business is all about the delivery of products and services to create value and fulfill the organizational vision and mission. A business driver refers to the factor or function that directs or controls the motions, activities, and business course to create and deliver value. A business enabler, which indirectly delivers value, is an auxiliary factor or function that supports business drivers.

A business function as a business driver typically contributes revenue directly. As a business enabler, the security function is crucial to organizations nowadays, creating value indirectly and shall be integrated into business functions or processes to support business drivers.

In Porter’s value chain, business drivers are primary activities, and business enablers are support activities.