SlideShare a Scribd company logo
1 of 51
Download to read offline
CNIT 125:
Information Security
Professional
(CISSP
Preparation)
Ch 2. Security and Risk
Management (Part 2)
Major Legal Systems
• Civil Law
• Laws and statutes determine what is allowed
• Precedents and particular case rulings carry
less weight than under common law
• Common Law
• Used in the USA, Canada, the UK, and former
British colonies
• Significant emphasis on particular cases and
precedents as determinants of laws
• The major legal system in the CISSP exam
Religious and Customary Law
• Religious Law
• Mainly Sharia (Islamic religious law)
• Customary Law
• Customs or practices that are commonly
accepted and treated as law
• Closely related to Best Practices
• Less important
Criminal and Civil Law
• Criminal Law
• Victim is society itself
• Enforced by police
• Punishment is often prison time
• Proof must be beyond a reasonable doubt
• Civil Law (Tort Law)
• Injury resulting from failure to provide due care
• Victim is an individual
• Enforced by lawsuits
• Result is financial damages paid to victim
• Burden of proof: preponderance of the evidence
(more likely than not)
Administrative Law
• Also called Regulatory Law
• Specify rules and punishments for regulated
industries
• Examples
• FCC regulations
• HIPAA security mandates
• FDS regulations
• FAA regulations
Liability
• Due Care
• Also called Duty of Care
• Prudent Man Rule
• Businesses should do what a prudent
man would do
• Best Practices
• Due Diligence
• The management of due care
• Follows a formal process
Legal Aspects of Investigations
Evidence
• Real evidence
• Physical objects like hard drives, USB drives,
etc.
• Direct evidence
• Witness testimony about what that person
experienced directly
• Circumstantial evidence
• Indirect evidence of guilt
• Can support other evidence, but usually
inadequate for conviction alone
Evidence
• Corroborative evidence
• Additional support for a fact that may be
called into question
• Hearsay
• Secondhand evidence
• Normally inadmissible in court
• Exceptions:
• Business records and computer-generated
evidence
• Computer forensic hard disk and memory
images are original evidence, not hearsay
Evidence
• Best evidence
• Original documents, not copies
• The actual hard drive used
• Etc.
• Secondary evidence
• Copies of documents
• Log files may be considered secondary or
original
• Evidence integrity
• Typically ensured by MD5 or SHA-1 hash
Chain of Custody
• Evidence must be
protected from
tampering
• A list of names of
people who can
testify that they
protected the
evidence
Reasonable Searches
• Fourth amendment protects citizens from
unreasonable search and seizure by the
government
• Illegally obtained evidence is inadmissible in
court
• Most searches require probable cause and
a search warrant
Exceptions
• These searches don't require a warrant
• Objects in plain sight
• At a public checkpoint
• Exigent circumstances
• Immediate threat to human life or of
evidence being destroyed
Agents of Law Enforcement
• Private citizens are not part of the
government, so the fourth amendment does
not apply, unless:
• Private citizens who carry out investigations
on behalf of law enforcement, they are
acting under the color of law enforcement
or agents of law enforcement
• Then the fourth amendment applies
Should You Call Law Enforcement?
• Companies often avoid involving law
enforcement
• Makes cases simpler, avoids publicity
Entrapment and Enticement
• Entrapment
• Law enforcement agent persuades someone
to commit a crime when
• The person otherwise had no intention to
commit a crime
• Enticement
• Law enforcement agent makes conditions
favorable for a crime
• Person is already intent on committing a crime
Computer Crime
• Computer as target
• DoS, installing malware to send spam
• Computer as a tool
• Stealing secrets from a database
• Stealing credit card numbers
• Espionage
• Harassment
• Attribution
• Difficult to prove who did a crime
Intellectual Property
• Trademark
• Name, logo, or symbol used for marketing
• Unregistered ™ or Registered ®
• Patent
• Grants a monopoly for an invention
• Copyright ©
• Restricts copying creative work
• Software typically covered by copyright
• Fair sale & fair use are allowed
Intellectual Property
• Licenses
• End-User License Agreement (EULA)
• Trade secrets
• Special sauce
• Protected by non-disclosure agreements
(NDAs) & non-compete agreements
(NCAs)
Intellectual Property Attacks
• Software piracy
• Copyright infringement
• Corporate espionage
• Cybersquatting & Typosquatting
• Using a domain close to a company's
domain, like yahoo.net or yahooo.com
Privacy
• Confidentiality of personal information
• EU Data Protection Directive
• Individuals must be notified how their data
is used & allowed to opt out
• OECD Privacy Guidelines
• Organization for Economic Cooperation
and Development
• Includes EU, USA, Mexico, AU & more
EU-US Safe Harbor
• Part of EU Data Protection Directive
• Sending personal data from EU to other
countries is forbidden
• Unless the receiving country adequately
protects its data
• The USA lost this privilege in Oct. 2015
because of the Snowden leaks
• Replacement agreement should be reached
next week (Link Ch 1d, Jan. 25, 2016)
International Cooperation
• Council of Europe Convention on
Cybercrime
• Includes most EU countries and the USA
• Promotes cooperation
Import / Export Restrictions
• USA restricted exports of cryptographic
technology in the 1990s
• Restrictions have been relaxed since then
Important Laws and Regulations
HIPAA
• Health Insurance Portability and
Accountability Act
• Guidance on Administrative, Physical, and
Technical safeguards
• For Protected Health Information (PHI)
CFAA
• Computer Fraud and Abuse Act
• Protects government and financial
computers
• Including every computer on the Internet
(probably not the law's original intent)
• It's a crime to exceed your authorization to
use such a computer
ECPA & The PATRIOT Act
• Electronic Communications Privacy Act
• Protected electronic communications from
warrantless wiretapping
• Weakened by the PATRIOT Act
• The PATRIOT Act
• A response to 9/11 attacks
• Greatly expanded law enforcement's
electronic monitoring capabilities
GLAB & SOX
• Gramm-Leach-Bailey Act
• Forces financial institutions to protect
customer financial information
• Sarbanes-Ox;ey Act
• Response to ENRON scandal
• Regulatory compliance mandates for
publicly traded companies
• Ensures financial disclosure and auditor
independence
PCI-DSS
• Payment Card Industry Data Security
Standard
• Self-regulation by major vendors
• Mandates security policy, devices, controls,
and monitoring to protect cardholder data
US Breach Notification Laws
• 47 states require notification
• No federal law yet
• Safe harbor for data that was encrypted at
time of compromise
Security and 3rd Parties
• Service Provider Contractual Security
• Service Level Agreements (SLA)
• Identify key expectations vendor must
meet
• Attestation
• Third party review of the service provider
to determine security posture
• Includes SAS 70 (old), ISO 27001, and
PCI-DSS
Security and 3rd Parties
• Right to Penetration Test / Audit
• Allows the originating organization to
perform these security tests on a vendor
• Procurement
• Purchasing products or services
• Considering security before purchase is
best
Security and 3rd Parties
• Vendor Governance
• Ensure that vendor provides sufficient quality
• Acquisitions
• Purchasing a company to add to an existing
company
• Can disrupt security
• Divestitures
• Splitting a company into parts
• May result in duplicate accounts and other risks
(ISC)^2 Code of Ethics
• Four Canons
• Protect society, the commonwealth, and
the infrastructure
• Act honorably, honestly, justly, responsibly,
and legally
• Provide diligent and competent service to
principals
• Advance and protect the profession
x
Personnel Security
• Security Awareness and Training
• Background Checks
• Employee Termination
• Must use fair process
• Vendor, Consultant and Contractor Security
• Outsourcing and Offshoring
• Can lower Total Cost of Ownership
• May improve security
• Privacy and regulatory issues
• Must perform risk analysis first
Access Control Types
• Preventive
• Detective
• Corrective
• Recovery
• Deterrent
• Compensating
Access Control Categories
• Administrative
• Technical
• Physical
Risk Analysis
• Assets
• Valuable resources to protect
• Threat
• A potentially harmful occurrence
• Vulnerability
• A weakness
Risk = Threat x Vulnerability
• Earthquake risk is the same in Boston and
San Francisco
• Boston
• Earthquakes are rare, but buildings are old
and vulnerable
• San Francisco
• Earthquakes are common, but buildings
are new erand safer
Impact
• Severity of the damage in dollars
• Risk = Threat x Vulnerability x Impact
• Human life is considered near-infinite impact
Total Cost of Ownership (TCO)
• Of a mitigating safeguard includes
• Upfront costs
• Annual cost of maintenance
• Staff hours
• Maintenance fees
• Software subscriptions
Return on Investment (ROI)
• Amount of money saved by implementing a
safeguard
• If Total Cost of Ownership is less than
Annualized Loss Expectancy, you have a
positive ROI
Risk Choices
• Accept the risk
• Mitigate the risk
• Transfer the risk
• Risk avoidance
Quantitative and Qualitative Risk
Analysis
• Quantitative
• Uses hard metrics, like dollars
• Qualitative
• Use simple approximate values
• Or categories like High, Medium, Low
NIST 9-Step Risk Analysis Process
Types of Attackers
• Hackers
• Black hat, white hat, gray hat
• Script kiddies
• Outsiders
• Outside the company
• Insiders
• Hacktivists
• Bots
• Phishing

More Related Content

What's hot

6 Scope & 7 Live Data Collection
6 Scope & 7 Live Data Collection6 Scope & 7 Live Data Collection
6 Scope & 7 Live Data CollectionSam Bowne
 
05. performance-concepts-26-slides
05. performance-concepts-26-slides05. performance-concepts-26-slides
05. performance-concepts-26-slidesMuhammad Ahad
 
CISSP Chapter 7 - Security Operations
CISSP Chapter 7 - Security OperationsCISSP Chapter 7 - Security Operations
CISSP Chapter 7 - Security OperationsKarthikeyan Dhayalan
 
Cybersecurity Awareness Training
Cybersecurity Awareness TrainingCybersecurity Awareness Training
Cybersecurity Awareness TrainingDave Monahan
 
CNIT 152: 6. Scope & 7. Live Data Collection
CNIT 152: 6. Scope & 7. Live Data CollectionCNIT 152: 6. Scope & 7. Live Data Collection
CNIT 152: 6. Scope & 7. Live Data CollectionSam Bowne
 
CISSP - Software Development Security
CISSP - Software Development SecurityCISSP - Software Development Security
CISSP - Software Development SecurityKarthikeyan Dhayalan
 
Cyber Security Introduction.pptx
Cyber Security Introduction.pptxCyber Security Introduction.pptx
Cyber Security Introduction.pptxANIKETKUMARSHARMA3
 
Phishing awareness
Phishing awarenessPhishing awareness
Phishing awarenessPhishingBox
 
Privacy , Security and Ethics Presentation
Privacy , Security and Ethics PresentationPrivacy , Security and Ethics Presentation
Privacy , Security and Ethics PresentationHajarul Cikyen
 
Customer information security awareness training
Customer information security awareness trainingCustomer information security awareness training
Customer information security awareness trainingAbdalrhmanTHassan
 
Security Awareness & Training
Security Awareness & TrainingSecurity Awareness & Training
Security Awareness & Trainingnovemberchild
 
Access Control Presentation
Access Control PresentationAccess Control Presentation
Access Control PresentationWajahat Rajab
 
Hacking ATM machines for fun and profit!
Hacking ATM machines for fun and profit!Hacking ATM machines for fun and profit!
Hacking ATM machines for fun and profit!Zigoo0
 

What's hot (20)

6 Scope & 7 Live Data Collection
6 Scope & 7 Live Data Collection6 Scope & 7 Live Data Collection
6 Scope & 7 Live Data Collection
 
05. performance-concepts-26-slides
05. performance-concepts-26-slides05. performance-concepts-26-slides
05. performance-concepts-26-slides
 
Security Awareness Training by Fortinet
Security Awareness Training by FortinetSecurity Awareness Training by Fortinet
Security Awareness Training by Fortinet
 
CISSP Chapter 7 - Security Operations
CISSP Chapter 7 - Security OperationsCISSP Chapter 7 - Security Operations
CISSP Chapter 7 - Security Operations
 
Domain 1 - Security and Risk Management
Domain 1 - Security and Risk ManagementDomain 1 - Security and Risk Management
Domain 1 - Security and Risk Management
 
Cybersecurity Awareness Training
Cybersecurity Awareness TrainingCybersecurity Awareness Training
Cybersecurity Awareness Training
 
Data protection
Data protectionData protection
Data protection
 
CISSP Chapter 1 Risk Management
CISSP Chapter 1  Risk ManagementCISSP Chapter 1  Risk Management
CISSP Chapter 1 Risk Management
 
CNIT 152: 6. Scope & 7. Live Data Collection
CNIT 152: 6. Scope & 7. Live Data CollectionCNIT 152: 6. Scope & 7. Live Data Collection
CNIT 152: 6. Scope & 7. Live Data Collection
 
CISSP - Software Development Security
CISSP - Software Development SecurityCISSP - Software Development Security
CISSP - Software Development Security
 
Cyber Security Introduction.pptx
Cyber Security Introduction.pptxCyber Security Introduction.pptx
Cyber Security Introduction.pptx
 
Information Security
Information SecurityInformation Security
Information Security
 
Phishing awareness
Phishing awarenessPhishing awareness
Phishing awareness
 
Privacy , Security and Ethics Presentation
Privacy , Security and Ethics PresentationPrivacy , Security and Ethics Presentation
Privacy , Security and Ethics Presentation
 
Physical security.ppt
Physical security.pptPhysical security.ppt
Physical security.ppt
 
Customer information security awareness training
Customer information security awareness trainingCustomer information security awareness training
Customer information security awareness training
 
Security Awareness & Training
Security Awareness & TrainingSecurity Awareness & Training
Security Awareness & Training
 
Access Control Presentation
Access Control PresentationAccess Control Presentation
Access Control Presentation
 
Hacking ATM machines for fun and profit!
Hacking ATM machines for fun and profit!Hacking ATM machines for fun and profit!
Hacking ATM machines for fun and profit!
 
Cybersecurity Awareness
Cybersecurity AwarenessCybersecurity Awareness
Cybersecurity Awareness
 

Viewers also liked

CISSP Prep: Ch 3. Asset Security
CISSP Prep: Ch 3. Asset SecurityCISSP Prep: Ch 3. Asset Security
CISSP Prep: Ch 3. Asset SecuritySam Bowne
 
CISSP Prep: Ch 4. Security Engineering (Part 1)
CISSP Prep: Ch 4. Security Engineering (Part 1)CISSP Prep: Ch 4. Security Engineering (Part 1)
CISSP Prep: Ch 4. Security Engineering (Part 1)Sam Bowne
 
CISSP Prep: Ch 7. Security Assessment and Testing
CISSP Prep: Ch 7. Security Assessment and TestingCISSP Prep: Ch 7. Security Assessment and Testing
CISSP Prep: Ch 7. Security Assessment and TestingSam Bowne
 
CISSP Prep: Ch 6. Identity and Access Management
CISSP Prep: Ch 6. Identity and Access ManagementCISSP Prep: Ch 6. Identity and Access Management
CISSP Prep: Ch 6. Identity and Access ManagementSam Bowne
 
CISSP Prep: Ch 8. Security Operations
CISSP Prep: Ch 8. Security OperationsCISSP Prep: Ch 8. Security Operations
CISSP Prep: Ch 8. Security OperationsSam Bowne
 
CISSP Prep: Ch 4. Security Engineering (Part 2)
CISSP Prep: Ch 4. Security Engineering (Part 2)CISSP Prep: Ch 4. Security Engineering (Part 2)
CISSP Prep: Ch 4. Security Engineering (Part 2)Sam Bowne
 
CISSP Prep: Ch 9. Software Development Security
CISSP Prep: Ch 9. Software Development SecurityCISSP Prep: Ch 9. Software Development Security
CISSP Prep: Ch 9. Software Development SecuritySam Bowne
 
CISSP Prep: Ch 5. Communication and Network Security (Part 1)
CISSP Prep: Ch 5. Communication and Network Security (Part 1)CISSP Prep: Ch 5. Communication and Network Security (Part 1)
CISSP Prep: Ch 5. Communication and Network Security (Part 1)Sam Bowne
 
CISSP Prep: Ch 5. Communication and Network Security (Part 2)
CISSP Prep: Ch 5. Communication and Network Security (Part 2)CISSP Prep: Ch 5. Communication and Network Security (Part 2)
CISSP Prep: Ch 5. Communication and Network Security (Part 2)Sam Bowne
 
CNIT 127: Ch 8: Windows overflows (Part 2)
CNIT 127: Ch 8: Windows overflows (Part 2)CNIT 127: Ch 8: Windows overflows (Part 2)
CNIT 127: Ch 8: Windows overflows (Part 2)Sam Bowne
 
Cissp- Security and Risk Management
Cissp- Security and Risk ManagementCissp- Security and Risk Management
Cissp- Security and Risk ManagementHamed Moghaddam
 
Slide Deck CISSP Class Session 2
Slide Deck CISSP Class Session 2Slide Deck CISSP Class Session 2
Slide Deck CISSP Class Session 2FRSecure
 
CNIT 128 Ch 6: Mobile services and mobile Web (part 2: SAML to end)
CNIT 128 Ch 6: Mobile services and mobile Web (part 2: SAML to end)CNIT 128 Ch 6: Mobile services and mobile Web (part 2: SAML to end)
CNIT 128 Ch 6: Mobile services and mobile Web (part 2: SAML to end)Sam Bowne
 
Slide Deck CISSP Class Session 3
Slide Deck CISSP Class Session 3Slide Deck CISSP Class Session 3
Slide Deck CISSP Class Session 3FRSecure
 
Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck - CISSP Mentor Program Class Session 1Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck - CISSP Mentor Program Class Session 1FRSecure
 
CISSP Certification-Asset Security
CISSP Certification-Asset SecurityCISSP Certification-Asset Security
CISSP Certification-Asset SecurityHamed Moghaddam
 
Slide Deck – Class Session 1 – FRSecure CISSP Mentor Program
Slide Deck – Class Session 1 – FRSecure CISSP Mentor ProgramSlide Deck – Class Session 1 – FRSecure CISSP Mentor Program
Slide Deck – Class Session 1 – FRSecure CISSP Mentor ProgramFRSecure
 
Purple Teaming - The Collaborative Future of Penetration Testing
Purple Teaming - The Collaborative Future of Penetration TestingPurple Teaming - The Collaborative Future of Penetration Testing
Purple Teaming - The Collaborative Future of Penetration TestingFRSecure
 
CNIT 140: Perimeter Security
CNIT 140: Perimeter SecurityCNIT 140: Perimeter Security
CNIT 140: Perimeter SecuritySam Bowne
 
CNIT 123: Ch 1 Ethical Hacking Overview
CNIT 123: Ch 1 Ethical Hacking OverviewCNIT 123: Ch 1 Ethical Hacking Overview
CNIT 123: Ch 1 Ethical Hacking OverviewSam Bowne
 

Viewers also liked (20)

CISSP Prep: Ch 3. Asset Security
CISSP Prep: Ch 3. Asset SecurityCISSP Prep: Ch 3. Asset Security
CISSP Prep: Ch 3. Asset Security
 
CISSP Prep: Ch 4. Security Engineering (Part 1)
CISSP Prep: Ch 4. Security Engineering (Part 1)CISSP Prep: Ch 4. Security Engineering (Part 1)
CISSP Prep: Ch 4. Security Engineering (Part 1)
 
CISSP Prep: Ch 7. Security Assessment and Testing
CISSP Prep: Ch 7. Security Assessment and TestingCISSP Prep: Ch 7. Security Assessment and Testing
CISSP Prep: Ch 7. Security Assessment and Testing
 
CISSP Prep: Ch 6. Identity and Access Management
CISSP Prep: Ch 6. Identity and Access ManagementCISSP Prep: Ch 6. Identity and Access Management
CISSP Prep: Ch 6. Identity and Access Management
 
CISSP Prep: Ch 8. Security Operations
CISSP Prep: Ch 8. Security OperationsCISSP Prep: Ch 8. Security Operations
CISSP Prep: Ch 8. Security Operations
 
CISSP Prep: Ch 4. Security Engineering (Part 2)
CISSP Prep: Ch 4. Security Engineering (Part 2)CISSP Prep: Ch 4. Security Engineering (Part 2)
CISSP Prep: Ch 4. Security Engineering (Part 2)
 
CISSP Prep: Ch 9. Software Development Security
CISSP Prep: Ch 9. Software Development SecurityCISSP Prep: Ch 9. Software Development Security
CISSP Prep: Ch 9. Software Development Security
 
CISSP Prep: Ch 5. Communication and Network Security (Part 1)
CISSP Prep: Ch 5. Communication and Network Security (Part 1)CISSP Prep: Ch 5. Communication and Network Security (Part 1)
CISSP Prep: Ch 5. Communication and Network Security (Part 1)
 
CISSP Prep: Ch 5. Communication and Network Security (Part 2)
CISSP Prep: Ch 5. Communication and Network Security (Part 2)CISSP Prep: Ch 5. Communication and Network Security (Part 2)
CISSP Prep: Ch 5. Communication and Network Security (Part 2)
 
CNIT 127: Ch 8: Windows overflows (Part 2)
CNIT 127: Ch 8: Windows overflows (Part 2)CNIT 127: Ch 8: Windows overflows (Part 2)
CNIT 127: Ch 8: Windows overflows (Part 2)
 
Cissp- Security and Risk Management
Cissp- Security and Risk ManagementCissp- Security and Risk Management
Cissp- Security and Risk Management
 
Slide Deck CISSP Class Session 2
Slide Deck CISSP Class Session 2Slide Deck CISSP Class Session 2
Slide Deck CISSP Class Session 2
 
CNIT 128 Ch 6: Mobile services and mobile Web (part 2: SAML to end)
CNIT 128 Ch 6: Mobile services and mobile Web (part 2: SAML to end)CNIT 128 Ch 6: Mobile services and mobile Web (part 2: SAML to end)
CNIT 128 Ch 6: Mobile services and mobile Web (part 2: SAML to end)
 
Slide Deck CISSP Class Session 3
Slide Deck CISSP Class Session 3Slide Deck CISSP Class Session 3
Slide Deck CISSP Class Session 3
 
Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck - CISSP Mentor Program Class Session 1Slide Deck - CISSP Mentor Program Class Session 1
Slide Deck - CISSP Mentor Program Class Session 1
 
CISSP Certification-Asset Security
CISSP Certification-Asset SecurityCISSP Certification-Asset Security
CISSP Certification-Asset Security
 
Slide Deck – Class Session 1 – FRSecure CISSP Mentor Program
Slide Deck – Class Session 1 – FRSecure CISSP Mentor ProgramSlide Deck – Class Session 1 – FRSecure CISSP Mentor Program
Slide Deck – Class Session 1 – FRSecure CISSP Mentor Program
 
Purple Teaming - The Collaborative Future of Penetration Testing
Purple Teaming - The Collaborative Future of Penetration TestingPurple Teaming - The Collaborative Future of Penetration Testing
Purple Teaming - The Collaborative Future of Penetration Testing
 
CNIT 140: Perimeter Security
CNIT 140: Perimeter SecurityCNIT 140: Perimeter Security
CNIT 140: Perimeter Security
 
CNIT 123: Ch 1 Ethical Hacking Overview
CNIT 123: Ch 1 Ethical Hacking OverviewCNIT 123: Ch 1 Ethical Hacking Overview
CNIT 123: Ch 1 Ethical Hacking Overview
 

Similar to CISSP Prep: Ch 2. Security and Risk Management I (part 2)

CNIT 125: Ch 2. Security and Risk Management (Part 2)
CNIT 125: Ch 2. Security and Risk Management (Part 2)CNIT 125: Ch 2. Security and Risk Management (Part 2)
CNIT 125: Ch 2. Security and Risk Management (Part 2)Sam Bowne
 
CNIT 125: Ch 2. Security and Risk Management (Part 2)
CNIT 125: Ch 2. Security and Risk Management (Part 2)CNIT 125: Ch 2. Security and Risk Management (Part 2)
CNIT 125: Ch 2. Security and Risk Management (Part 2)Sam Bowne
 
Trade Secret Theft in the Digital Age
Trade Secret Theft in the Digital AgeTrade Secret Theft in the Digital Age
Trade Secret Theft in the Digital AgeBoyarMiller
 
Surveillance and security.pptx
Surveillance and security.pptxSurveillance and security.pptx
Surveillance and security.pptxjohn6938
 
Trade Secret Theft – Protecting the Crown Jewels
Trade Secret Theft – Protecting the Crown JewelsTrade Secret Theft – Protecting the Crown Jewels
Trade Secret Theft – Protecting the Crown JewelsWinston & Strawn LLP
 
12 02-14 information security managers - unannotated
12 02-14 information security managers - unannotated12 02-14 information security managers - unannotated
12 02-14 information security managers - unannotatedwdsnead
 
Legal Considerations of Digital Document Storage and E-Signature, Authority f...
Legal Considerations of Digital Document Storage and E-Signature, Authority f...Legal Considerations of Digital Document Storage and E-Signature, Authority f...
Legal Considerations of Digital Document Storage and E-Signature, Authority f...ImageSoft
 
GDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal EnvironmentGDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal EnvironmentAllen Woods
 
CYBOK: Law and Regulation webinar slides.pdf
CYBOK: Law and Regulation webinar slides.pdfCYBOK: Law and Regulation webinar slides.pdf
CYBOK: Law and Regulation webinar slides.pdfHari319621
 
Cyber forensic-Evedidence collection tools
Cyber forensic-Evedidence collection toolsCyber forensic-Evedidence collection tools
Cyber forensic-Evedidence collection toolsN.Jagadish Kumar
 
Digital&computforensic
Digital&computforensicDigital&computforensic
Digital&computforensicRahul Badekar
 
Real World Cybersecurity Tips You Can Use to Protect Your Clients, Your Firm,...
Real World Cybersecurity Tips You Can Use to Protect Your Clients, Your Firm,...Real World Cybersecurity Tips You Can Use to Protect Your Clients, Your Firm,...
Real World Cybersecurity Tips You Can Use to Protect Your Clients, Your Firm,...Shawn Tuma
 
CISSP week 25
CISSP week 25CISSP week 25
CISSP week 25jemtallon
 
164199724-Introduction-To-Digital-Forensics-ppt.ppt
164199724-Introduction-To-Digital-Forensics-ppt.ppt164199724-Introduction-To-Digital-Forensics-ppt.ppt
164199724-Introduction-To-Digital-Forensics-ppt.pptharshbj1801
 
Protecting Client Data 11.09.11
Protecting Client Data 11.09.11Protecting Client Data 11.09.11
Protecting Client Data 11.09.11pdewitte
 
Cybersecurity Legal Issues: What You Really Need to Know
Cybersecurity Legal Issues: What You Really Need to KnowCybersecurity Legal Issues: What You Really Need to Know
Cybersecurity Legal Issues: What You Really Need to KnowShawn Tuma
 
Strong Host Security Policies are Good Business
Strong Host Security Policies are Good BusinessStrong Host Security Policies are Good Business
Strong Host Security Policies are Good BusinessHostingCon
 
Privacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the RiskPrivacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the Riskduffeeandeitzen
 

Similar to CISSP Prep: Ch 2. Security and Risk Management I (part 2) (20)

CNIT 125: Ch 2. Security and Risk Management (Part 2)
CNIT 125: Ch 2. Security and Risk Management (Part 2)CNIT 125: Ch 2. Security and Risk Management (Part 2)
CNIT 125: Ch 2. Security and Risk Management (Part 2)
 
CNIT 125: Ch 2. Security and Risk Management (Part 2)
CNIT 125: Ch 2. Security and Risk Management (Part 2)CNIT 125: Ch 2. Security and Risk Management (Part 2)
CNIT 125: Ch 2. Security and Risk Management (Part 2)
 
Trade Secret Theft in the Digital Age
Trade Secret Theft in the Digital AgeTrade Secret Theft in the Digital Age
Trade Secret Theft in the Digital Age
 
Surveillance and security.pptx
Surveillance and security.pptxSurveillance and security.pptx
Surveillance and security.pptx
 
Chapter 1 Law & Ethics
Chapter 1   Law & EthicsChapter 1   Law & Ethics
Chapter 1 Law & Ethics
 
Trade Secret Theft – Protecting the Crown Jewels
Trade Secret Theft – Protecting the Crown JewelsTrade Secret Theft – Protecting the Crown Jewels
Trade Secret Theft – Protecting the Crown Jewels
 
12 02-14 information security managers - unannotated
12 02-14 information security managers - unannotated12 02-14 information security managers - unannotated
12 02-14 information security managers - unannotated
 
Legal Considerations of Digital Document Storage and E-Signature, Authority f...
Legal Considerations of Digital Document Storage and E-Signature, Authority f...Legal Considerations of Digital Document Storage and E-Signature, Authority f...
Legal Considerations of Digital Document Storage and E-Signature, Authority f...
 
GDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal EnvironmentGDPR and EA Commissioning a web site part 2 - Legal Environment
GDPR and EA Commissioning a web site part 2 - Legal Environment
 
CYBOK: Law and Regulation webinar slides.pdf
CYBOK: Law and Regulation webinar slides.pdfCYBOK: Law and Regulation webinar slides.pdf
CYBOK: Law and Regulation webinar slides.pdf
 
Cyber forensic-Evedidence collection tools
Cyber forensic-Evedidence collection toolsCyber forensic-Evedidence collection tools
Cyber forensic-Evedidence collection tools
 
Digital&computforensic
Digital&computforensicDigital&computforensic
Digital&computforensic
 
Real World Cybersecurity Tips You Can Use to Protect Your Clients, Your Firm,...
Real World Cybersecurity Tips You Can Use to Protect Your Clients, Your Firm,...Real World Cybersecurity Tips You Can Use to Protect Your Clients, Your Firm,...
Real World Cybersecurity Tips You Can Use to Protect Your Clients, Your Firm,...
 
CISSP week 25
CISSP week 25CISSP week 25
CISSP week 25
 
164199724-Introduction-To-Digital-Forensics-ppt.ppt
164199724-Introduction-To-Digital-Forensics-ppt.ppt164199724-Introduction-To-Digital-Forensics-ppt.ppt
164199724-Introduction-To-Digital-Forensics-ppt.ppt
 
Protecting Client Data 11.09.11
Protecting Client Data 11.09.11Protecting Client Data 11.09.11
Protecting Client Data 11.09.11
 
Cybersecurity Legal Issues: What You Really Need to Know
Cybersecurity Legal Issues: What You Really Need to KnowCybersecurity Legal Issues: What You Really Need to Know
Cybersecurity Legal Issues: What You Really Need to Know
 
Pls 780 week 9
Pls 780 week 9Pls 780 week 9
Pls 780 week 9
 
Strong Host Security Policies are Good Business
Strong Host Security Policies are Good BusinessStrong Host Security Policies are Good Business
Strong Host Security Policies are Good Business
 
Privacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the RiskPrivacy and Technology in Your Practice: Why it Matters & Where is the Risk
Privacy and Technology in Your Practice: Why it Matters & Where is the Risk
 

More from Sam Bowne

3: DNS vulnerabilities
3: DNS vulnerabilities 3: DNS vulnerabilities
3: DNS vulnerabilities Sam Bowne
 
8. Software Development Security
8. Software Development Security8. Software Development Security
8. Software Development SecuritySam Bowne
 
4 Mapping the Application
4 Mapping the Application4 Mapping the Application
4 Mapping the ApplicationSam Bowne
 
3. Attacking iOS Applications (Part 2)
 3. Attacking iOS Applications (Part 2) 3. Attacking iOS Applications (Part 2)
3. Attacking iOS Applications (Part 2)Sam Bowne
 
12 Elliptic Curves
12 Elliptic Curves12 Elliptic Curves
12 Elliptic CurvesSam Bowne
 
11. Diffie-Hellman
11. Diffie-Hellman11. Diffie-Hellman
11. Diffie-HellmanSam Bowne
 
2a Analyzing iOS Apps Part 1
2a Analyzing iOS Apps Part 12a Analyzing iOS Apps Part 1
2a Analyzing iOS Apps Part 1Sam Bowne
 
9 Writing Secure Android Applications
9 Writing Secure Android Applications9 Writing Secure Android Applications
9 Writing Secure Android ApplicationsSam Bowne
 
12 Investigating Windows Systems (Part 2 of 3)
12 Investigating Windows Systems (Part 2 of 3)12 Investigating Windows Systems (Part 2 of 3)
12 Investigating Windows Systems (Part 2 of 3)Sam Bowne
 
12 Investigating Windows Systems (Part 1 of 3
12 Investigating Windows Systems (Part 1 of 312 Investigating Windows Systems (Part 1 of 3
12 Investigating Windows Systems (Part 1 of 3Sam Bowne
 
9. Hard Problems
9. Hard Problems9. Hard Problems
9. Hard ProblemsSam Bowne
 
8 Android Implementation Issues (Part 1)
8 Android Implementation Issues (Part 1)8 Android Implementation Issues (Part 1)
8 Android Implementation Issues (Part 1)Sam Bowne
 
11 Analysis Methodology
11 Analysis Methodology11 Analysis Methodology
11 Analysis MethodologySam Bowne
 
8. Authenticated Encryption
8. Authenticated Encryption8. Authenticated Encryption
8. Authenticated EncryptionSam Bowne
 
7. Attacking Android Applications (Part 2)
7. Attacking Android Applications (Part 2)7. Attacking Android Applications (Part 2)
7. Attacking Android Applications (Part 2)Sam Bowne
 
7. Attacking Android Applications (Part 1)
7. Attacking Android Applications (Part 1)7. Attacking Android Applications (Part 1)
7. Attacking Android Applications (Part 1)Sam Bowne
 
5. Stream Ciphers
5. Stream Ciphers5. Stream Ciphers
5. Stream CiphersSam Bowne
 
4. Block Ciphers
4. Block Ciphers 4. Block Ciphers
4. Block Ciphers Sam Bowne
 

More from Sam Bowne (20)

Cyberwar
CyberwarCyberwar
Cyberwar
 
3: DNS vulnerabilities
3: DNS vulnerabilities 3: DNS vulnerabilities
3: DNS vulnerabilities
 
8. Software Development Security
8. Software Development Security8. Software Development Security
8. Software Development Security
 
4 Mapping the Application
4 Mapping the Application4 Mapping the Application
4 Mapping the Application
 
3. Attacking iOS Applications (Part 2)
 3. Attacking iOS Applications (Part 2) 3. Attacking iOS Applications (Part 2)
3. Attacking iOS Applications (Part 2)
 
12 Elliptic Curves
12 Elliptic Curves12 Elliptic Curves
12 Elliptic Curves
 
11. Diffie-Hellman
11. Diffie-Hellman11. Diffie-Hellman
11. Diffie-Hellman
 
2a Analyzing iOS Apps Part 1
2a Analyzing iOS Apps Part 12a Analyzing iOS Apps Part 1
2a Analyzing iOS Apps Part 1
 
9 Writing Secure Android Applications
9 Writing Secure Android Applications9 Writing Secure Android Applications
9 Writing Secure Android Applications
 
12 Investigating Windows Systems (Part 2 of 3)
12 Investigating Windows Systems (Part 2 of 3)12 Investigating Windows Systems (Part 2 of 3)
12 Investigating Windows Systems (Part 2 of 3)
 
10 RSA
10 RSA10 RSA
10 RSA
 
12 Investigating Windows Systems (Part 1 of 3
12 Investigating Windows Systems (Part 1 of 312 Investigating Windows Systems (Part 1 of 3
12 Investigating Windows Systems (Part 1 of 3
 
9. Hard Problems
9. Hard Problems9. Hard Problems
9. Hard Problems
 
8 Android Implementation Issues (Part 1)
8 Android Implementation Issues (Part 1)8 Android Implementation Issues (Part 1)
8 Android Implementation Issues (Part 1)
 
11 Analysis Methodology
11 Analysis Methodology11 Analysis Methodology
11 Analysis Methodology
 
8. Authenticated Encryption
8. Authenticated Encryption8. Authenticated Encryption
8. Authenticated Encryption
 
7. Attacking Android Applications (Part 2)
7. Attacking Android Applications (Part 2)7. Attacking Android Applications (Part 2)
7. Attacking Android Applications (Part 2)
 
7. Attacking Android Applications (Part 1)
7. Attacking Android Applications (Part 1)7. Attacking Android Applications (Part 1)
7. Attacking Android Applications (Part 1)
 
5. Stream Ciphers
5. Stream Ciphers5. Stream Ciphers
5. Stream Ciphers
 
4. Block Ciphers
4. Block Ciphers 4. Block Ciphers
4. Block Ciphers
 

Recently uploaded

How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17Celine George
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...Nguyen Thanh Tu Collection
 
ComPTIA Overview | Comptia Security+ Book SY0-701
ComPTIA Overview | Comptia Security+ Book SY0-701ComPTIA Overview | Comptia Security+ Book SY0-701
ComPTIA Overview | Comptia Security+ Book SY0-701bronxfugly43
 
Magic bus Group work1and 2 (Team 3).pptx
Magic bus Group work1and 2 (Team 3).pptxMagic bus Group work1and 2 (Team 3).pptx
Magic bus Group work1and 2 (Team 3).pptxdhanalakshmis0310
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...Poonam Aher Patil
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxAreebaZafar22
 
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptxMaritesTamaniVerdade
 
Application orientated numerical on hev.ppt
Application orientated numerical on hev.pptApplication orientated numerical on hev.ppt
Application orientated numerical on hev.pptRamjanShidvankar
 
This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.christianmathematics
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxVishalSingh1417
 
How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17Celine George
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingTechSoup
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSCeline George
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxheathfieldcps1
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsTechSoup
 
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdfUGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdfNirmal Dwivedi
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...christianmathematics
 
Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...Association for Project Management
 

Recently uploaded (20)

How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17
 
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
TỔNG ÔN TẬP THI VÀO LỚP 10 MÔN TIẾNG ANH NĂM HỌC 2023 - 2024 CÓ ĐÁP ÁN (NGỮ Â...
 
ComPTIA Overview | Comptia Security+ Book SY0-701
ComPTIA Overview | Comptia Security+ Book SY0-701ComPTIA Overview | Comptia Security+ Book SY0-701
ComPTIA Overview | Comptia Security+ Book SY0-701
 
Magic bus Group work1and 2 (Team 3).pptx
Magic bus Group work1and 2 (Team 3).pptxMagic bus Group work1and 2 (Team 3).pptx
Magic bus Group work1and 2 (Team 3).pptx
 
Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024Mehran University Newsletter Vol-X, Issue-I, 2024
Mehran University Newsletter Vol-X, Issue-I, 2024
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptx
 
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
 
Application orientated numerical on hev.ppt
Application orientated numerical on hev.pptApplication orientated numerical on hev.ppt
Application orientated numerical on hev.ppt
 
This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptx
 
How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17How to Create and Manage Wizard in Odoo 17
How to Create and Manage Wizard in Odoo 17
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
 
Spatium Project Simulation student brief
Spatium Project Simulation student briefSpatium Project Simulation student brief
Spatium Project Simulation student brief
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The Basics
 
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdfUGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
UGC NET Paper 1 Mathematical Reasoning & Aptitude.pdf
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
 
Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...Making communications land - Are they received and understood as intended? we...
Making communications land - Are they received and understood as intended? we...
 

CISSP Prep: Ch 2. Security and Risk Management I (part 2)

  • 2. Major Legal Systems • Civil Law • Laws and statutes determine what is allowed • Precedents and particular case rulings carry less weight than under common law • Common Law • Used in the USA, Canada, the UK, and former British colonies • Significant emphasis on particular cases and precedents as determinants of laws • The major legal system in the CISSP exam
  • 3. Religious and Customary Law • Religious Law • Mainly Sharia (Islamic religious law) • Customary Law • Customs or practices that are commonly accepted and treated as law • Closely related to Best Practices • Less important
  • 4. Criminal and Civil Law • Criminal Law • Victim is society itself • Enforced by police • Punishment is often prison time • Proof must be beyond a reasonable doubt • Civil Law (Tort Law) • Injury resulting from failure to provide due care • Victim is an individual • Enforced by lawsuits • Result is financial damages paid to victim • Burden of proof: preponderance of the evidence (more likely than not)
  • 5.
  • 6. Administrative Law • Also called Regulatory Law • Specify rules and punishments for regulated industries • Examples • FCC regulations • HIPAA security mandates • FDS regulations • FAA regulations
  • 7. Liability • Due Care • Also called Duty of Care • Prudent Man Rule • Businesses should do what a prudent man would do • Best Practices • Due Diligence • The management of due care • Follows a formal process
  • 8. Legal Aspects of Investigations
  • 9. Evidence • Real evidence • Physical objects like hard drives, USB drives, etc. • Direct evidence • Witness testimony about what that person experienced directly • Circumstantial evidence • Indirect evidence of guilt • Can support other evidence, but usually inadequate for conviction alone
  • 10. Evidence • Corroborative evidence • Additional support for a fact that may be called into question • Hearsay • Secondhand evidence • Normally inadmissible in court • Exceptions: • Business records and computer-generated evidence • Computer forensic hard disk and memory images are original evidence, not hearsay
  • 11. Evidence • Best evidence • Original documents, not copies • The actual hard drive used • Etc. • Secondary evidence • Copies of documents • Log files may be considered secondary or original • Evidence integrity • Typically ensured by MD5 or SHA-1 hash
  • 12. Chain of Custody • Evidence must be protected from tampering • A list of names of people who can testify that they protected the evidence
  • 13. Reasonable Searches • Fourth amendment protects citizens from unreasonable search and seizure by the government • Illegally obtained evidence is inadmissible in court • Most searches require probable cause and a search warrant
  • 14. Exceptions • These searches don't require a warrant • Objects in plain sight • At a public checkpoint • Exigent circumstances • Immediate threat to human life or of evidence being destroyed
  • 15. Agents of Law Enforcement • Private citizens are not part of the government, so the fourth amendment does not apply, unless: • Private citizens who carry out investigations on behalf of law enforcement, they are acting under the color of law enforcement or agents of law enforcement • Then the fourth amendment applies
  • 16. Should You Call Law Enforcement? • Companies often avoid involving law enforcement • Makes cases simpler, avoids publicity
  • 17. Entrapment and Enticement • Entrapment • Law enforcement agent persuades someone to commit a crime when • The person otherwise had no intention to commit a crime • Enticement • Law enforcement agent makes conditions favorable for a crime • Person is already intent on committing a crime
  • 18. Computer Crime • Computer as target • DoS, installing malware to send spam • Computer as a tool • Stealing secrets from a database • Stealing credit card numbers • Espionage • Harassment • Attribution • Difficult to prove who did a crime
  • 19. Intellectual Property • Trademark • Name, logo, or symbol used for marketing • Unregistered ™ or Registered ® • Patent • Grants a monopoly for an invention • Copyright © • Restricts copying creative work • Software typically covered by copyright • Fair sale & fair use are allowed
  • 20. Intellectual Property • Licenses • End-User License Agreement (EULA) • Trade secrets • Special sauce • Protected by non-disclosure agreements (NDAs) & non-compete agreements (NCAs)
  • 21. Intellectual Property Attacks • Software piracy • Copyright infringement • Corporate espionage • Cybersquatting & Typosquatting • Using a domain close to a company's domain, like yahoo.net or yahooo.com
  • 22. Privacy • Confidentiality of personal information • EU Data Protection Directive • Individuals must be notified how their data is used & allowed to opt out • OECD Privacy Guidelines • Organization for Economic Cooperation and Development • Includes EU, USA, Mexico, AU & more
  • 23. EU-US Safe Harbor • Part of EU Data Protection Directive • Sending personal data from EU to other countries is forbidden • Unless the receiving country adequately protects its data • The USA lost this privilege in Oct. 2015 because of the Snowden leaks • Replacement agreement should be reached next week (Link Ch 1d, Jan. 25, 2016)
  • 24. International Cooperation • Council of Europe Convention on Cybercrime • Includes most EU countries and the USA • Promotes cooperation
  • 25. Import / Export Restrictions • USA restricted exports of cryptographic technology in the 1990s • Restrictions have been relaxed since then
  • 26. Important Laws and Regulations
  • 27. HIPAA • Health Insurance Portability and Accountability Act • Guidance on Administrative, Physical, and Technical safeguards • For Protected Health Information (PHI)
  • 28. CFAA • Computer Fraud and Abuse Act • Protects government and financial computers • Including every computer on the Internet (probably not the law's original intent) • It's a crime to exceed your authorization to use such a computer
  • 29. ECPA & The PATRIOT Act • Electronic Communications Privacy Act • Protected electronic communications from warrantless wiretapping • Weakened by the PATRIOT Act • The PATRIOT Act • A response to 9/11 attacks • Greatly expanded law enforcement's electronic monitoring capabilities
  • 30. GLAB & SOX • Gramm-Leach-Bailey Act • Forces financial institutions to protect customer financial information • Sarbanes-Ox;ey Act • Response to ENRON scandal • Regulatory compliance mandates for publicly traded companies • Ensures financial disclosure and auditor independence
  • 31. PCI-DSS • Payment Card Industry Data Security Standard • Self-regulation by major vendors • Mandates security policy, devices, controls, and monitoring to protect cardholder data
  • 32. US Breach Notification Laws • 47 states require notification • No federal law yet • Safe harbor for data that was encrypted at time of compromise
  • 33. Security and 3rd Parties • Service Provider Contractual Security • Service Level Agreements (SLA) • Identify key expectations vendor must meet • Attestation • Third party review of the service provider to determine security posture • Includes SAS 70 (old), ISO 27001, and PCI-DSS
  • 34. Security and 3rd Parties • Right to Penetration Test / Audit • Allows the originating organization to perform these security tests on a vendor • Procurement • Purchasing products or services • Considering security before purchase is best
  • 35. Security and 3rd Parties • Vendor Governance • Ensure that vendor provides sufficient quality • Acquisitions • Purchasing a company to add to an existing company • Can disrupt security • Divestitures • Splitting a company into parts • May result in duplicate accounts and other risks
  • 36. (ISC)^2 Code of Ethics • Four Canons • Protect society, the commonwealth, and the infrastructure • Act honorably, honestly, justly, responsibly, and legally • Provide diligent and competent service to principals • Advance and protect the profession
  • 37. x
  • 38. Personnel Security • Security Awareness and Training • Background Checks • Employee Termination • Must use fair process • Vendor, Consultant and Contractor Security • Outsourcing and Offshoring • Can lower Total Cost of Ownership • May improve security • Privacy and regulatory issues • Must perform risk analysis first
  • 39. Access Control Types • Preventive • Detective • Corrective • Recovery • Deterrent • Compensating
  • 40. Access Control Categories • Administrative • Technical • Physical
  • 41. Risk Analysis • Assets • Valuable resources to protect • Threat • A potentially harmful occurrence • Vulnerability • A weakness
  • 42. Risk = Threat x Vulnerability • Earthquake risk is the same in Boston and San Francisco • Boston • Earthquakes are rare, but buildings are old and vulnerable • San Francisco • Earthquakes are common, but buildings are new erand safer
  • 43. Impact • Severity of the damage in dollars • Risk = Threat x Vulnerability x Impact • Human life is considered near-infinite impact
  • 44.
  • 45.
  • 46. Total Cost of Ownership (TCO) • Of a mitigating safeguard includes • Upfront costs • Annual cost of maintenance • Staff hours • Maintenance fees • Software subscriptions
  • 47. Return on Investment (ROI) • Amount of money saved by implementing a safeguard • If Total Cost of Ownership is less than Annualized Loss Expectancy, you have a positive ROI
  • 48. Risk Choices • Accept the risk • Mitigate the risk • Transfer the risk • Risk avoidance
  • 49. Quantitative and Qualitative Risk Analysis • Quantitative • Uses hard metrics, like dollars • Qualitative • Use simple approximate values • Or categories like High, Medium, Low
  • 50. NIST 9-Step Risk Analysis Process
  • 51. Types of Attackers • Hackers • Black hat, white hat, gray hat • Script kiddies • Outsiders • Outside the company • Insiders • Hacktivists • Bots • Phishing