『Security+ Domain 11 - Governance, Risk, and Compliance』のカバーアート

Security+ Domain 11 - Governance, Risk, and Compliance

Security+ Domain 11 - Governance, Risk, and Compliance

無料で聴く

ポッドキャストの詳細を見る

Security+ GRC outlines key knowledge required to assess enterprise security posture. Security governance establishes management’s intent and operational structure through a strict hierarchy of policies (high-level direction), standards (mandatory requirements), and procedures (step-by-step actions).

The risk management lifecycle involves identifying, assessing, and treating risks through avoidance, acceptance, mitigation, or transference. Quantitative risk analysis uses metrics like Single Loss Expectancy (SLE) and Annualized Rate of Occurrence (ARO) to calculate Annualized Loss Expectancy (ALE=SLE×ARO). Even after applying these controls, some residual risk always remains.

Lastly, compliance ensures organizations adhere to regulatory frameworks like GDPR and HIPAA. This extends to managing third-party risk via thorough vendor assessments and structured agreements such as Service-Level Agreements (SLAs) or Memorandums of Understanding (MOUs). -Dr. Z

adbl_web_anon_alc_button_suppression_t1
まだレビューはありません