2 cissp ® Official Study Guide Eighth Edition



Download 19,3 Mb.
Pdf ko'rish
bet656/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   652   653   654   655   656   657   658   659   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Service-Level Agreements
A service-level agreement (SLA) is an agreement between an organization and an outside 
entity, such as a vendor. The SLA stipulates performance expectations and often includes 
penalties if the vendor doesn’t meet these expectations.
As an example, many organizations use cloud-based services to rent servers. A vendor 
provides access to the servers and maintains them to ensure that they are available. The 
organization can use an SLA to specify availability such as with maximum downtimes. 
With this in mind, an organization should have a clear idea of their requirements when 
working with third parties and make sure the SLA includes these requirements.
In addition to an SLA, organizations sometimes use a memorandum of understanding 
(MOU) and/or an interconnection security agreement (ISA). MOUs document the inten-
tion of two entities to work together toward a common goal. Although an MOU is similar 


708
Chapter 16 

Managing Security Operations
to an SLA, it is less formal and doesn’t include any monetary penalties if one of the parties 
doesn’t meet its responsibilities. 
If two or more parties plan to transmit sensitive data, they can use an ISA to specify the 
technical requirements of the connection. The ISA provides information on how the two 
parties establish, maintain, and disconnect the connection. It can also identify the mini-
mum encryption methods used to secure the data. 
NIST Special Publication 800-47, “Security Guide for Interconnecting 
Information Technology Systems,” includes detailed information on 
MOUs and ISAs.
Addressing Personnel Safety and Security 
Personnel safety concerns are an important element of security operations. It’s always pos-
sible to replace things such as data, servers, and even entire buildings. In contrast, it isn’t 
possible to replace people. With that in mind, organizations should implement security con-
trols that enhance personnel safety. 
As an example, consider the exit door in a datacenter that is controlled by a pushbut-
ton electronic cipher lock. If a fi re results in a power outage, does the exit door automati-
cally unlock or remain locked? An organization that values assets in the server room more 
than personnel safety might decide to ensure that the door remains locked when power 
isn’t available. This protects the physical assets in the datacenter. However, it also risks the 
lives of personnel within the room because they won’t be able to easily exit the room. In 
contrast, an organization that values personnel safety over the assets in the datacenter will 
ensure that the locks unlock the exit door when power is lost. 

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   652   653   654   655   656   657   658   659   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish