SLIDE 6 Operational - Safeguards
PREVENTATIVE CONTROLS
systems, encryption, vulnerability assessments, Penetration testing, physical security, data minimization
TOOLS
Firewalls, anti-virus, intrusion detection and prevention systems (IDPS )
PRIV ACY & S ECURITY CHECKPOINTS (Internal to S
Development Lifecycle(S DLC) CHANGE, RELEAS E and P ATCH MANAGEMENT
MINIMUM PERMIS S IONS
ensitive information
responsibilities
S EGREGATION OF DUTIES
Key factors that should alert
- rganizations of greater risk of a breach
Universal
sectors where breaches have been reported
- Vulnerabilities that are being
exploited in software packages, applications or tools used by the
- rganization, reported in the
news
Organizational
udden changes in reported scanning/ logging
- People as a threat vector
- Mergers and acquisitions
- S
udden staff turnover
- Planned layoffs
- Boom economy