<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;A0MHR308eip7ImA9WhdVFEk.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410</id><updated>2011-09-19T09:23:56.372-07:00</updated><title>IT People NEWS, Tips and Tricks</title><subtitle type="html">This Blog is built to help the Internet surfers to get updated information about the IT and some usefull tips and tricks regarding comuter usage / buying along with some threats and vulnerabilities to avoid unwanted crashes..... Wish You a enjoyable surffeing</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://itpeopleworld.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Kash</name><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>64</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/ItPeopleNewsTipsAndTricks" /><feedburner:info uri="itpeoplenewstipsandtricks" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;A0ANSX88eSp7ImA9WhdWFEw.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-2799262586233871603</id><published>2011-09-07T11:23:00.000-07:00</published><updated>2011-09-07T11:23:18.171-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-07T11:23:18.171-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CA" /><category scheme="http://www.blogger.com/atom/ns#" term="Mozilla" /><category scheme="http://www.blogger.com/atom/ns#" term="cloud" /><category scheme="http://www.blogger.com/atom/ns#" term="outsourcing" /><category scheme="http://www.blogger.com/atom/ns#" term="Digital Certificate" /><category scheme="http://www.blogger.com/atom/ns#" term="DigiNotar" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="certificate" /><category scheme="http://www.blogger.com/atom/ns#" term="update" /><category scheme="http://www.blogger.com/atom/ns#" term="Fraudulent Digital Certificates" /><category scheme="http://www.blogger.com/atom/ns#" term="FireFox" /><title>Fraudulent Digital Certificates</title><content type="html">&lt;div&gt;
&lt;a href="http://2.bp.blogspot.com/-ixQ-hpQIdAw/TmeyuM78mFI/AAAAAAAAAU8/s9IoSfwzqFU/s1600/MS%2BSec%2BAdvisory.jpeg"&gt;&lt;span style="color: black;"&gt;&lt;/span&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5649680764375963730" src="http://2.bp.blogspot.com/-ixQ-hpQIdAw/TmeyuM78mFI/AAAAAAAAAU8/s9IoSfwzqFU/s400/MS%2BSec%2BAdvisory.jpeg" style="cursor: pointer; display: block; height: 148px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;div&gt;
&lt;b&gt;&lt;span style="font-size: large;"&gt; &lt;span style="font-family: arial;"&gt;s&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;ome major borwsers have issued a relased because DIGINOTAR the former Certificate Authority whihc managed to issue more than 500 bogus digital certificates in the name of majore web service providers mainly&lt;br /&gt;
&lt;br /&gt;
Facebook&lt;br /&gt;
Twitter&lt;br /&gt;
Microsoft&lt;br /&gt;
Google&lt;br /&gt;
&lt;br /&gt;
even in the name of some intelligence agencies.&lt;br /&gt;
&lt;br /&gt;
In recent update from MoZilla Firefox it have blocked any certificate signed by DigitNotar.&lt;br /&gt;
&lt;br /&gt;
Microsoft have also released an update 2607712 permanently moving all five DigiNotar's root certificates to the Certificate Revokation List  whihc provides protection to all Windows versions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
DigiNotar Root CA&lt;br /&gt;
&lt;br /&gt;
DigiNotar Root CA G2&lt;/div&gt;
&lt;div&gt;
DigiNotar PKIoverheid CA Overheid&lt;/div&gt;
&lt;div&gt;
DigiNotar PKIoverheid CA Organisatie - G2&lt;/div&gt;
&lt;div&gt;
DigiNotar PKIoverheid CA Overheid en Bedrijven&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-2799262586233871603?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/oCuXORaFiURWMpoOJnXm1y_B_Yk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oCuXORaFiURWMpoOJnXm1y_B_Yk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/oCuXORaFiURWMpoOJnXm1y_B_Yk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oCuXORaFiURWMpoOJnXm1y_B_Yk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/vaniCinbrU0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/2799262586233871603/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/09/fraudulent-digital-certificates.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/2799262586233871603?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/2799262586233871603?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/vaniCinbrU0/fraudulent-digital-certificates.html" title="Fraudulent Digital Certificates" /><author><name>Kash</name><email>noreply@blogger.com</email></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-ixQ-hpQIdAw/TmeyuM78mFI/AAAAAAAAAU8/s9IoSfwzqFU/s72-c/MS%2BSec%2BAdvisory.jpeg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/09/fraudulent-digital-certificates.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEADRHs4fSp7ImA9WhdXEks.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-5312782657756574516</id><published>2011-08-25T01:57:00.000-07:00</published><updated>2011-08-25T01:59:35.535-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-25T01:59:35.535-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Netflow" /><category scheme="http://www.blogger.com/atom/ns#" term="Nbar" /><category scheme="http://www.blogger.com/atom/ns#" term="642-874 exam" /><category scheme="http://www.blogger.com/atom/ns#" term="Netflow Vs NBAR" /><title>Netflow Vs NBAR</title><content type="html">&lt;a href="http://4.bp.blogspot.com/-L2YWL1XqDEg/TlYOio-lk7I/AAAAAAAAAU0/eg6eUOnWVRM/s1600/NBAR%2Bvs%2BNetflow.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5644715171233764274" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 370px; CURSOR: hand; HEIGHT: 400px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/-L2YWL1XqDEg/TlYOio-lk7I/AAAAAAAAAU0/eg6eUOnWVRM/s400/NBAR%2Bvs%2BNetflow.JPG" border="0" /&gt;&lt;/a&gt;
&lt;br /&gt;You are the Cisco Network Designer in Cisco.com. Which statement is correct regarding NBARand NetFlow?
&lt;br /&gt;A. NBAR examines data in Layers 1 and 4.
&lt;br /&gt;B. NBAR examines data in Layers 3 and 4.
&lt;br /&gt;C. NetFlow examines data in Layers 3 and 4.
&lt;br /&gt;D. NBAR examines data in Layers 2 through 4.
&lt;br /&gt;
&lt;br /&gt;Answer is &lt;strong&gt;C&lt;/strong&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Explanantion &lt;/strong&gt;&lt;/p&gt;
&lt;br /&gt;&lt;p&gt;Netflow works between 3 and 4 &lt;/p&gt;
&lt;br /&gt;&lt;p&gt;Layer Flexible Netflow workd from Layer 2 to 7 inspect payload &lt;/p&gt;
&lt;br /&gt;&lt;p&gt;NBAR works 3 to 7 &lt;/p&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-5312782657756574516?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Mg7QNTugjECU5O8HOg666I2nduY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Mg7QNTugjECU5O8HOg666I2nduY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Mg7QNTugjECU5O8HOg666I2nduY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Mg7QNTugjECU5O8HOg666I2nduY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/-JLxApEatJc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/5312782657756574516/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/08/netflow-vs-nbar.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/5312782657756574516?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/5312782657756574516?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/-JLxApEatJc/netflow-vs-nbar.html" title="Netflow Vs NBAR" /><author><name>Kash</name><email>noreply@blogger.com</email></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-L2YWL1XqDEg/TlYOio-lk7I/AAAAAAAAAU0/eg6eUOnWVRM/s72-c/NBAR%2Bvs%2BNetflow.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/08/netflow-vs-nbar.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkEAQno9cCp7ImA9WhdQEUg.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-5611929355055081247</id><published>2011-08-12T04:59:00.000-07:00</published><updated>2011-08-12T05:04:03.468-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-12T05:04:03.468-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="non blocking" /><category scheme="http://www.blogger.com/atom/ns#" term="Forwarding" /><category scheme="http://www.blogger.com/atom/ns#" term="Switching" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco Catalyst Switch" /><category scheme="http://www.blogger.com/atom/ns#" term="Backplane and Switching fabric" /><category scheme="http://www.blogger.com/atom/ns#" term="frame size" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco" /><title>Switching, Backplane and Switching fabric</title><content type="html">
&lt;br /&gt;There is a biggest confusing in the datasheets to understand Forwarding , Switching, Backplane and Switching fabric Internally to a switch.
&lt;br /&gt;
&lt;br /&gt;A specialized hardware is needed to move frames between ports.This specific part can be called &lt;span style="font-weight: bold;"&gt;backplane &lt;/span&gt;or in some cases we talk of &lt;span style="font-weight: bold;"&gt;switching fabric&lt;/span&gt;.
&lt;br /&gt;
&lt;br /&gt;When the forwarding capabilities of a backplane or switching fabric are greater then the sum of speeds of all ports (counted twice one for tx and one rx direction) / full duplex we call the switching fabric &lt;span style="font-weight: bold;"&gt;non blocking&lt;/span&gt;
&lt;br /&gt;
&lt;br /&gt;Traffic between a pair of ports is not influenced by what traffic is exchanged on all other ports.The forwarding rate is expressed in packet per seconds and expresses how many packets per second are needed to reach a certain traffic volume (throughpout)
&lt;br /&gt;
&lt;br /&gt;Clearly forwarding rate depends on frame size.
&lt;br /&gt;
&lt;br /&gt;Ideally a backplane switching fabric should be non blocking for every frame size including the smallest ones (64 bytes in ethernet standard) but in reality most devices can be non blocking for an average size of 400 bytes.
&lt;br /&gt;
&lt;br /&gt;bandwidth is the speed of traffic.
&lt;br /&gt;
&lt;br /&gt;to convert between forwarding rate and used bandwidth we need to take in account some specific aspects of ethernet: with this kind of calculation using frames of minimum size &lt;span style="font-weight: bold;"&gt;64 bytes &lt;/span&gt;you need &lt;span style="font-weight: bold;"&gt;1488000 frames per second &lt;/span&gt;and per direction to fill a Gigabit ethernet port.
&lt;br /&gt;
&lt;br /&gt;Be aware that all figures you see sum tx and rx directions so if a switch has 100 Mpps (Million Pkts per second) capability this accounts for a certain number of GE ports at 1 Gbps full duplex.
&lt;br /&gt;
&lt;br /&gt;In almost all switches (Cisco and non-Cisco) the switching limitation is actually NOT bandwidth, its Mpps (mega packets per second).
&lt;br /&gt;
&lt;br /&gt;So the answer actually depends mostly on what your traffic looks like. Worst-case is VOIP traffic which consists of 100byte packets, best case is file transfers using full 1500 byte packets.
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-5611929355055081247?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/G4WNUjPkQ8nZK_cLqmDXX6uwTro/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/G4WNUjPkQ8nZK_cLqmDXX6uwTro/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/G4WNUjPkQ8nZK_cLqmDXX6uwTro/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/G4WNUjPkQ8nZK_cLqmDXX6uwTro/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/7MW2_wys_NQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/5611929355055081247/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/08/switching-backplane-and-switching.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/5611929355055081247?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/5611929355055081247?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/7MW2_wys_NQ/switching-backplane-and-switching.html" title="Switching, Backplane and Switching fabric" /><author><name>Kash</name><email>noreply@blogger.com</email></author><thr:total>0</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/08/switching-backplane-and-switching.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcARX88cSp7ImA9WhdREU4.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-206703542297685569</id><published>2011-07-31T11:44:00.000-07:00</published><updated>2011-07-31T11:47:24.179-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-31T11:47:24.179-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cheat sheet" /><category scheme="http://www.blogger.com/atom/ns#" term="and Investigations" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP Exam" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cramm questions" /><category scheme="http://www.blogger.com/atom/ns#" term="Compliance" /><category scheme="http://www.blogger.com/atom/ns#" term="Regulations" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP CBK  7 Legal" /><category scheme="http://www.blogger.com/atom/ns#" term="Cissp CBK" /><title>CISSP CBK  8 Legal, Regulations, Compliance, and Investigations</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-snVvISzdEjk/TjWjHb23jDI/AAAAAAAAAUk/mt_yJ-UD-9o/s1600/cissp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 136px; height: 132px;" src="http://4.bp.blogspot.com/-snVvISzdEjk/TjWjHb23jDI/AAAAAAAAAUk/mt_yJ-UD-9o/s200/cissp.jpg" alt="" id="BLOGGER_PHOTO_ID_5635589856856345650" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p dir="ltr" style="text-align: center; margin-top: 0pt; margin-bottom: 0pt;" id="internal-source-marker_0.9368713723501633"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Legal, Regulations, Compliance, and Investigations&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Council of Europe (CoE) Convention on Cybe rcrime:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;If the organization is exchanging data with European entities, it may need to adhere to the Safe harbor&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;safe harbor &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;framework how any entity that is going to move Private data to and from Europe must provide protection&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Civil law &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;deals with wrongs against individuals or companies that result in damages or loss. This is referred to as &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;tort law&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;. no Jail sentence&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Criminal law &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;when an individuals conduct violates the government laws / Jail sentence&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Administrative/regulatory &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;law deals with regulatory standards that regulate performance and conduct&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Intellectual property laws &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;do  not necessarily look at who is right or wrong, but rather how a company  can protect what it rightfully owns from unauthorized duplication or  use,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Trade Secret &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;= competitive value or advantage (formula for Drink)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Copyright= &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;rights for authors(unauthorized copying and distribution of a work)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Trademark= &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;protect a word,name, symbol (identifiable packaging, &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;“trade dress.”)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Patent= &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(usually valid for 20 years from the date of approval)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;international trademark law efforts and international registration are overseen by the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;World Intellectual Property Organization (WIPO)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, an agency of the United Nations&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Similar to trademarks, international patents are overseen by the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;WIPO&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Digital Millennium Copyright Act (DMCA), &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;which makes it illegal to create products that circumvent copyright protection mechanisms.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Federal Privacy Act of 1974&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, it has enacted new laws, Gramm-Leach-Bliley Act of 1999&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Federal Privacy Act &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;If  an agency collects data on a person, that person has the right to  receive a report outlining data collected about him if it is requested  ialso gives individuals the right to review records about themselves, to  find out if these records have been disclosed, and to request  corrections or amendments of these records)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Sarbanes-Oxley Act (SOX)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; law governs accounting practices,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Health Insurance Portability and Accountability Act &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(HIPAA)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Gramm-Leach-Bliley Act of 1999 (GLBA) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;requires  financial institutions to develop privacy notices and give their  customers option to share the data with other companies.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;1994 U.S. Communications Assistance for Law Enforcement Act&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; all communications carriers to make wiretaps possible&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer Fraud and Abuse Act&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;,1986, 1996&lt;/span&gt;&lt;ul&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;access to federal Govt computers to access classified info&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;access to financial institution computers or any computer&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;unauthorised access to Govt computer&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;knowing access of a protected computer without authorization with intend to Fraud&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;causing the transmission of Program/ Information and Code from a computer without owners authorization&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;trafficking of computer password for fraud&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;transmission of communication containing threats&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The Federal Privacy Act of 1974&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Government agencies can maintain personnel information only if it is necessary to accomplish the agency’s purpose.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The  Privacy Act dictates that an agency cannot disclose this information  without written Permission from the individual however there are some  exceptions.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;1996 U.S Economic and Protection of Proprietary Information Act &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Industrial and corporate Espionage &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;1980 Organization for Economic Cooperation and Development (OECD) Guidelines&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Deals  with data collection limitations, the quality of data, specifications  of the purpose for data collection, limitations of data use,  participation by the individual on whom the data is being collected, and  accountability of the data controller&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Basel II&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;how much capital banks need to put aside to guard against the types of financial and operational risks banks face&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;1987 U.S. Computer Security Act &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;federal  government agencies to conduct security-related training, to identify  sensitive systems, and to develop a security plan for those sensitive  systems&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer Security Act of 1987 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;identify computers with sensitive information.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;American citizens are protected by the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#0000ff;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"&gt;Fourth Amendment&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;against unlawful search and seizure&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Payment Card Industry Data Security Standards (PCI DSS)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;any  entity that processes, transmits, stores, or accepts credit card data  PCI DSS is a private-sector industry initiative. It is not a law and  failure to comply may lead to revocation of merchant status or a fine&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;PCI DSS main areas &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;ul&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Build and Maintain a Secure Network, &lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Protect Cardholder Data, &lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Maintain a Vulnerability Management Program, &lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Implement Strong Access Control Measures, &lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Regularly Monitor and Test Networks, &lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Maintain an Information Security Policy&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Economic Espionage Act of 1996&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;1991, U.S. Federal Sentencing Guidelines &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;were developed to provide judges with courses of action in dealing with white collar crimes max fine up to 290 Million $&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Employee Privacy Issues&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;manager can listen your conversation with customer but not your personal conversation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Government regulations &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;SOX, HIPAA, GLBA, BASEL&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Self-regulation &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Payment Card Industry (PCI)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Individual &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;user Passwords, encryption, awareness&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Downstream liability &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;when  two companies work to gather they must ensure proper protection for  each other so if virus effect one company other wil get effected and  will finally Sue upstream company.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;event &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is a negative occurrence that can be observed, verified, and documented, whereas an &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;incident &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;i&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;s a series of events that negatively affects the company and/or impacts its security posture.&lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;incident response &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;policy should be managed by Legal Department &lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Three types of incident response team &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;virtual team &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;members have other jobs slower response &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;permanent &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;team &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;which is dedicated strictly to incident response&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;hybrid team &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;some are permanent members and some are called when needed &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Main goal of &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;incident handling &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is to contain and mitigate any damage caused by an incident and to prevent any further damage.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Steps to Incident Responce &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Triage : &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;initial screening of the reported event either it is False positive&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Investigation:&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;- proper collection of relevant data&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Containment:&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Analysis:&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Tracking:&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Recovery:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;honeypots &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;can introduce liability issues and be used to attack other internal targets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Steps of Forensic Investigation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Identification&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Preservation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Collection&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Examination&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Analysis&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Presentation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Decision&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;exigent circumstances &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;when law enforcement quickly seize the evidents to avoid destruction for some one &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Most of the time, computer-related documents are considered &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;hearsay&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, meaning the evidence is &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;secondhand evidence&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;life cycle of evidence &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;includes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Collection and identification&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Storage, preservation, and transportation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Presentation in court&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Return of the evidence to the victim or owner&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Oral evidence &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is not considered best evidence because there is no firsthand reliable proof&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;evidence &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;should be &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;authentic &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;complete &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;sufficient &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;and &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;reliable&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Dumpster diving &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is unethical, but it’s not illegal. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Trespassing &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is illegal, &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Emanation &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;= Tempest&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Some things may not be &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;illegal&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, but that does not necessarily mean they are ethical&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Red box &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;simulated the tones of coins being deposited into a pay phone&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Black Box &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;method to manipulate line voltage to enable people to call toll-free lines.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Blue Box&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; ' that enabled people to make free long-distance phone calls,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Generally Accepted System Security Principles &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(GASSP) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;are security-oriented principles and do not specifically cover viruses or worms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;ISC2 Code of Ethics &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Code of Ethics Preamble:&lt;/span&gt;&lt;ul&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Safety  of the commonwealth, duty to our principals, and to each other requires  that we adhere, and be seen to adhere, to the highest ethical standards  of behavior.&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Therefore, strict adherence to this Code is a condition of certification.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Code of Ethics Canons:&lt;/span&gt;&lt;ul&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Protect society, the commonwealth, and the infrastructure.&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Act honorably, honestly, justly, responsibly, and&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;legally.&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Provide diligent and competent service to principals.&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Advance and protect the profession&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Business attack = competitive intelligence to get trade secret &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Intelligence attack = Military &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Financing Attack = Bank Fraud &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Corroborative Evidence &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;supporting  evidence is used to help prove an idea or a point, however It cannot  stand on its own i.e Torn clothes, 911 call recording&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;computer fraudsters &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;hold a position of trust&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;exclusionary rule&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; mentions that evidence must be gathered legally&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;incident handling&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; Contain and repair any damage caused by an event&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Memory Dump &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;gives an State of the Machine.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Circumstantial evidence &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;= inference of information from other, intermediate, relevant facts. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Secondary evidence &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;= copy of evidence or oral description &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Conclusive evidence &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;= overrides all other evidence &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;GIASP  Generally Accepted Information Security Principles&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer security supports the mission of the organization&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer security is an integral element of sound management&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer security should be cost-effective&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Systems owners have security responsibilities outside their own organization&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer security responsibilities and accountability should be made explicit&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer security requires a comprehensive and integrated approach&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer security should be periodically reassessed&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer security is constrained by societal factors&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#000000;background-font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;font-family:Arial;font-size:11pt;color:transparent;"   &gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-206703542297685569?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/r2y3U717YklJ71p-fuFJgXuww2I/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/r2y3U717YklJ71p-fuFJgXuww2I/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/r2y3U717YklJ71p-fuFJgXuww2I/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/r2y3U717YklJ71p-fuFJgXuww2I/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/_HjwiQPmr9s" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/206703542297685569/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/07/cissp-cbk-7-legal-regulations.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/206703542297685569?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/206703542297685569?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/_HjwiQPmr9s/cissp-cbk-7-legal-regulations.html" title="CISSP CBK  8 Legal, Regulations, Compliance, and Investigations" /><author><name>Kash</name><email>noreply@blogger.com</email></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-snVvISzdEjk/TjWjHb23jDI/AAAAAAAAAUk/mt_yJ-UD-9o/s72-c/cissp.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/07/cissp-cbk-7-legal-regulations.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8ERXYzeyp7ImA9WhdSFU4.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-7797595849912303956</id><published>2011-07-24T11:22:00.000-07:00</published><updated>2011-07-24T11:40:04.883-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-24T11:40:04.883-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cheat sheet" /><category scheme="http://www.blogger.com/atom/ns#" term="business continuty" /><category scheme="http://www.blogger.com/atom/ns#" term="cissp CBK business continuty" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP questions" /><category scheme="http://www.blogger.com/atom/ns#" term="disaster recovery" /><category scheme="http://www.blogger.com/atom/ns#" term="Cissp CBK" /><title>CISSP CBK  7 BCP/DRP</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-NMr6aGYiyyg/TixlPpxnQTI/AAAAAAAAAUc/g2z8meIqcak/s1600/cissp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 108px; height: 105px;" src="http://4.bp.blogspot.com/-NMr6aGYiyyg/TixlPpxnQTI/AAAAAAAAAUc/g2z8meIqcak/s200/cissp.jpg" alt="" id="BLOGGER_PHOTO_ID_5632988553520038194" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p dir="ltr" style="text-align: center; margin-top: 0pt; margin-bottom: 0pt;" id="internal-source-marker_0.08802111825882186"&gt;&lt;span style="font-size:14pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;BCP / DRP&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:14pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;business continuity coordinator &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is leader of BCP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;BCP Planing&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;1. Project initiation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;2. BIA&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;3. Recovery strategy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;4. Plan design and development&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;5. Implementation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;6. Testing&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;7. Continual maintenance&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;1. Project intiation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;develop the continuity planning policy statement.mgmt support and resources&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Establishing need for the BCP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Obtaining management support&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Identifying strategic internal and external resources&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Establishing &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;members &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;of team&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Establishing project management &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;work plan&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Determining need for &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;automated data &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;collection tools&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Preparing and presenting status reports&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;2.Business Impact Analysis&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Maximum tolerable downtime&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Operational disruption and productivity&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Financial considerations&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Regulatory responsibilities&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Reputation, Preventive measures&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;3. Recovery strategy&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Business process recovery&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Facility recovery&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Supply and technology recovery&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;User environment recovery&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Data recovery&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;hot site &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(subscription service) and a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;redundant site &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(owned by the company).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;backup site &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;should be &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;15 Miles &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;recommended , &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;critical environment &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;50-200 Miles&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Software escrow &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;means that a third party holds the source code, backups of the compiled code, manuals, and other supporting materials.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Disk duplexing &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;means there is more than one disk controller. If one disk controller fails, the other is ready and available&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Electronic vaulting &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;makes  copies of files as they are modified and periodically transmits them to  an off site backup site (not real time its batch processing) bulk  Information transfer&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Remote journaling &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is off site data storage for real time transaction logs &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;tape vaulting &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;auto transfer data to tape controller remote site&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Block ciphers do not use public cryptography (private and public keys).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Type of testing includes &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Structured walk-through&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Checklist&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Simulation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Parallel&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Full interruption&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The functions of a critical system can only be replaced by &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;identical capabilities&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;. Other functions can be performed manually.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Dual Data Center &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;strategy  also called redundent site or alternate site would be employed for  applications, which cannot accept any downtime without impacting  business.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;property Insurance &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Replacement Cost Valuation (RCV) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;clause your damaged property will be compensated Based on new item for old regardless of condition of lost item &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;ACV (actual Cost Value)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Value of item on the date of loss&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;disaster recovery plan &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is usually very information technology (IT) focused&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;eight &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;detailed and granular steps of the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;BIA &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;are:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;1. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; Select Individuals to interview for the data gathering.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;2&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.  Create data gathering techniques (surveys, questionnaires, qualitative and quantitative approaches).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;3&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.  Identify the company's critical business functions.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;4&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.  Identify the resources that these functions depend upon.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;5&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.  Calculate how long these functions can survive without these resources.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;6&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.  Identify vulnerabilities and the threats to these functions.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;7&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.  Calculate risk for each of the different business functions.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;8&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.  Document findings and report them to management.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Creating a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;BCP committee &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is part of the scope and plan initiation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Recovery Time Objectives (RTO) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is  the amount of time allowed for the recovery of a business function. If  the RTO is exceeded, then severe damage to the organization would  result. Recovery Time Objectives &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;RTO would be defined as part of the recovery plan and not as part of the BIA.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Recovery Point Objectives (RPO&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;) is the point in time in which data must be restored in order to resume processing (mainly Business Transaction)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;A &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;data backup &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is the first step in contingency planning&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Human Resources &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;may not be a part of the BCP committee&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Named PERILS &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Burden of proof that particular &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;loss is covered &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is on &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Insured&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The primary difference between them is that one type of policy covers what is &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;"named" &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(included)  in the policy while the other covers what is not included. A named  peril policy is often a good choice for those business owners whose  business is located in an area frequently hit by natural disasters such  as hurricanes, tornados, or floods. Such a policy spells out the  specific events for which you are covered. The cost of the premiums will  depend on the location of the business and the likelihood of the  specific peril(s). Anything not specifically named in such a policy is  not covered.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;An all-risk policy &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;covers  your business from damages caused by any type of disaster with the  exception of those specifically excluded in the policy. Floods and  earthquakes are two events that are typically excluded, but coverage for  these types of disasters can be added to the policy for an additional  fee.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Use of the All Risk form shifts the burden of proof onto the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;insurer &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;to prove that a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;particular loss was not covered &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;by the policy.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Occupant Emergency Plan (OEP&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;)  provides the response procedures for occupants of a facility in the  event of a situation posing a potential threat to the health and safety  of personnel, the environment, or property. Such events would include a  fire, hurricane, criminal attack, or a medical emergency&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;BCP is corrective control.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#000000;background-font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;font-family:Arial;font-size:11pt;color:transparent;"   &gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-7797595849912303956?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/6eIKrJUyFL7ZB0j-UlDZicEbSP4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6eIKrJUyFL7ZB0j-UlDZicEbSP4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/6eIKrJUyFL7ZB0j-UlDZicEbSP4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6eIKrJUyFL7ZB0j-UlDZicEbSP4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/iIkgsDP65kk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/7797595849912303956/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/07/cissp-cbk-7-bcpdrp.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/7797595849912303956?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/7797595849912303956?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/iIkgsDP65kk/cissp-cbk-7-bcpdrp.html" title="CISSP CBK  7 BCP/DRP" /><author><name>Kash</name><email>noreply@blogger.com</email></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-NMr6aGYiyyg/TixlPpxnQTI/AAAAAAAAAUc/g2z8meIqcak/s72-c/cissp.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/07/cissp-cbk-7-bcpdrp.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8MQH07fCp7ImA9WhdSEk0.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-1218971217784725646</id><published>2011-07-20T15:56:00.000-07:00</published><updated>2011-07-20T16:01:21.304-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-20T16:01:21.304-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IPsec" /><category scheme="http://www.blogger.com/atom/ns#" term="AES encryption" /><category scheme="http://www.blogger.com/atom/ns#" term="cissp CBK cryptography" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP" /><category scheme="http://www.blogger.com/atom/ns#" term="How encryption works" /><category scheme="http://www.blogger.com/atom/ns#" term="Cissp CBK" /><category scheme="http://www.blogger.com/atom/ns#" term="cryptography" /><category scheme="http://www.blogger.com/atom/ns#" term="2900 Cisco" /><category scheme="http://www.blogger.com/atom/ns#" term="DES vs 3DES" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="VPN IPsec" /><category scheme="http://www.blogger.com/atom/ns#" term="Wireless encryption" /><category scheme="http://www.blogger.com/atom/ns#" term="Free hacking" /><title>CISSP CBK 6 Cryptography</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-iILyKfiYx5c/TiddSFRfpjI/AAAAAAAAAUU/-kFrCh0qNZE/s1600/cissp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 214px; height: 208px;" src="http://1.bp.blogspot.com/-iILyKfiYx5c/TiddSFRfpjI/AAAAAAAAAUU/-kFrCh0qNZE/s320/cissp.jpg" alt="" id="BLOGGER_PHOTO_ID_5631572424284677682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p dir="ltr" style="text-align: center; margin-top: 0pt; margin-bottom: 0pt;" id="internal-source-marker_0.705655422567055"&gt;&lt;span style="font-size:12pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"&gt;Cryptography&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;open-community version of &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;SSL &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Transport Layer Security (TLS). &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The differences between SSL 3.0 and TLS is slight, but TLS is more extensible and is backward compatible with SSL&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;S-Http &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is to encrypt every message however SSL /TLS is for communication channel.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;security parameter index (SPI), keep track of SA and For every tunnel you have two SA one in each direction. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;integrity check value (ICV)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;,  AH calculates this value over whole Data Packet including header and  when packet passes through NAT devices IP header changes and receiving  station discard the packet due to mismatch ICV this is were &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;ESP &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;comes in play and it calculate ICV without using IP headers.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;" id="internal-source-marker_0.705655422567055"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;OAKLEY &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;protocol is the one that carries out the negotiation process. You can think of &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;ISAKMP &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;as providing the playing field (the infrastructure) and &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;OAKLEY &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;as the guy running up and down the playing field (carrying out the steps of the negotiation).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Simple Key Management Protocol for IP (SKIP) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is another key exchange protocol that provides basically the same functionality as IKE &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ffffff;background-color:#ff0000;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;all thease protocols work at Network Layer&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ffffff;background-color:#ff0000;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;passive attacks &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;attacker is not affecting the protocol, algorithm, key, message, or any&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;parts of the encryption system&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Cipher Only attack&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; (COA)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;the attacker has the cipher text of several messages&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Known Plain Text  attack (KPTA)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;the attacker has the plain text and corresponding cipher text of one or more messages&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;chosen-plaintext attacks,(CPA) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;the  attacker has the plain text and cipher text, but can choose the  plaintext that gets encrypted to see the corresponding cipher text. some  one forward your email text with encryption (I can change the Text and  see the resulted Encrypted value)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;chosen-ciphertext attacks&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(CCA)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;the  attacker can choose the cipher text to be decrypted and has access to  the resulting decrypted plain text (most applicable against &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;public key &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;cryptography)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Timestamps and sequence numbers are two countermeasures to &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;replay attacks.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;In an &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;HMAC&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;  operation, a message is concatenated with a symmetric key and the  result is put through a hashing algorithm. This provides integrity and  system or data authentication. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;CBC-MAC &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;uses a block cipher to create a MAC, which is the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;last block of ciphertext&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Key clustering &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;different keys generate the same ciphertext for the same message&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Collision &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;If the algorithm does produce the same value for two distinctly different messages,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;RSA algorithm’s security &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is based on the difficulty of factoring &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ffffff;background-color:#ff0000;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;large numbers&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;into their original prime numbers&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Clipper chip &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is  a chipset that was developed and promoted by the U.S. Government as an  encryption device to be adopted by telecommunications companies for  voice transmission. It was announced in 1993 and by 1996 was entirely  defunct.&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The heart of the concept was&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; key escrow&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.  In the factory, any new telephone or other device with a Clipper chip  would be given a "cryptographic key", that would then be provided to the  government in "escrow".  If government agencies "established their  authority" to listen to a communication, then the password would be  given to those government agencies, who could then decrypt all data  transmitted by that particular telephone.&lt;/span&gt;&lt;/p&gt;&lt;p dir="ltr" style="text-align: justify; margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The  CISSP Prep Guide states, "The idea is to divide the key into two parts,  and to escrow two portions of the key with two separate 'trusted'  organizations. Then, law enforcement officals, after obtaining a court  order, can retreive the two pieces of the key from the organizations and  decrypt the message."&lt;/span&gt;&lt;/p&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;There are four types of MACs:&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(1) unconditionally secure,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(2) hash function based,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(3) stream cipher-based &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;4) block cipher-based.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The algorithm does produce the same value for two distinctly different messages, this is called a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;collision&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;MD5 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is subject to this attack&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;HAVAL &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;variable one way hash modification of MD5 and hash &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;128 or 256&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;An attacker can attempt to force a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;collision&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, which is referred to as a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;birthday attack&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;A &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;digital signature &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is  a hash value that has been encrypted with the sender’s private key.the  act of signing means encrypting the message’s hash value with a private  key,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;A send message to B generate hash value and then encrypt this with sender &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Private Key &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;,  So when B receives the message will perform the hashing function on the  message, and come up with his own hash value. Then he will decrypt the  sent &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;hash value (digital signature) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;with  Senders (A) public key and compare the two values. ensure integrity and  authenticity/ non repudiation Signing means value encrypting with  private Key &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;X.509 Version 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;When users need new certificates, they make requests to the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;RA (registration authority)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The frequency of use of a cryptographic key has a direct correlation to how often the key should be changed&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;end-to-end encryption&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, the headers, addresses, routing, and trailer information are not encrypted however in &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Link encryption &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(some  time Online encryption) every thing is encrypted and every hop need to  decrypt it read the header and decide where to send traffic.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Link encryption &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Data Link Layer.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;End-to-end encryption &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;happens within the applications.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;SSL &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;encryption takes place at the transport layer.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;PPTP &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;encryption takes place at the data link layer.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;IPsec &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;at Network&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;S/MIME &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;provides  confidentiality through encryption algorithms, integrity through  hashing algorithms, authentication through the use of X.509 public key  certificates, and nonrepudiation through cryptographically signed  message digests&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;protocols within &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;PEM (Private enhanced Module) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;provide authentication, message integrity, encryption, and key management&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Message Security Protocol (MSP&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;)  is the military’s PEM. Developed by the NSA,it is an X.400-compatible  application-level protocol used to secure e-mail messages&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;PGP &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;uses &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;IDEA &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;for Encryption , &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;MD5 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;for hashing and it uses its own digital certificates.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;A message can be encrypted, which provides &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;confidentiality&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;A message can be hashed, which provides &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;integrity.&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;A message can be &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;digitally signed&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, which provides &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;authentication,non repudiation, and integrity&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;A message can be encrypted and digitally signed, which provides confidentiality, authentication, non repudiation, and integrity.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Simple substitution and transposition ciphers are vulnerable to attacks that perform &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;frequency analysis&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;. In every language, there are words and patterns that are used more than others.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Some  patterns common to a language can actually help attackers figure out  the transformation between plaintext and ciphertext, which enables them  to figure out the key that was used to perform the transformation. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Polyalphabetic ciphers use &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;different alphabets to defeat frequency analysis. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;NSA took the 128-bit algorithm &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#0000ff;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"&gt;Lucifer&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;that IBM developed, reduced the key size to 64 bits and with that developed DES.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Twofish.&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; is related to &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#0000ff;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;"&gt;Blowfish&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; as a possible replacement for DES.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Skipjack.&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; was developed after DES by the NSA .&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ffffff;background-color:#ff0000;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Digital envelop &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;A  message encrypted with a secret key attached with the message.  The  secret key is encrypted with the public key of the receiver.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;digital watermarking &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is  a computing techniques for inseparably embedding unobtrusive marks or  labels as bits in digital data-text, graphics, images, video, or  audio#and for detecting or extracting the marks later. The set of  embedded bits (the digital watermark) is sometimes hidden, usually  imperceptible, and always intended to be unobtrusive. It is used as a  measure to protect intellectual property rights. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Steganography &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;involves hiding the very existence of a message.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;SHA-1&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; = 160 bit digest&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;SHA-256&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;  = 256 bit digest&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;SHA-384&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; = 384 bit digest&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;SHA-512&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;  =  512 bit digest&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;DSS &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;provides &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Integrity, digital signature and Authentication&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, but &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;does not provide Encryption.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;An &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;analytic attack &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;refers to using algorithm and algebraic manipulation weakness to reduce complexity&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;RC5 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is a fast block cipher designed by Ronald Rivest for RSA Data Security (now RSA Security) in 1994&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Clipper Chip &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is  a NSA designed tamperproof chip for encrypting data and it uses the  SkipJack algorithm. Each Clipper Chip has a unique serial number and a  copy of the unit key is stored in the database under this serial number.  The sending Clipper Chip generates and sends a Law Enforcement Access  Field (LEAF) value included in the transmitted message. It is based on a  &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;80-bit key and a 16-bit checksum..&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Authentication Header &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is a mechanism for providing strong integrity and authentication for IP datagrams. It might also provide non-repudiation, &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;concealment cipher&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, every X number of words within a text, is a part of the real message. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;IDEA &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;128 Bits &lt;/span&gt;&lt;br /&gt;&lt;h1 dir="ltr"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;PKCS #1= RSA Cryptography Standard&lt;/span&gt;&lt;span style="font-size:12pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;/h1&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;AES Rijindel Algoritham &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;10 rounds if the key/block size is 128 bits&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;12 rounds if the key/block size is 192 bits&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;14 rounds if the key/block size is 256 bits&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Cryptography supports all three goals of the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;CIA Triad. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Key encapsulation&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is one class of key recovery techniques and is defined as &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;a  key recovery technique for storing knowledge of a cryptographic key by  encrypting it with another key and ensuring that that only certain third  parties called "recovery agents" can perform the decryption operation  to retrieve the stored key&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Key encapsulation&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; typically allows direct retrieval of the secret key used to provide data confidentiality.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The other class of key recovery technique is&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Key escrow&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;,&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; defined as &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;a  technique for storing knowledge of a cryptographic key or parts thereof  in the custody of one or more third parties called "escrow agents", so  that the key can be recovered and used in specified circumstances&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#ffffff;background-color:#ff0000;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;ECC KEY &lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;I&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;n most cases, the longer the key, the more protection that is provided, but&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; ECC can provide the same level of protection with a key size that is shorter than what RSA&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;  requires. Because longer keys require more resources to perform  mathematical tasks, the smaller keys used in ECC require fewer resources  of the device&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ffffff;background-color:#ff0000;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Private key Cryptosystem is a synonym to Symmetric Key or Secret Key cryptosystems &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ffffff;background-color:#ff0000;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;very important to remeber it in EXAM!!!!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ffffff;background-color:#ff0000;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Cipher Block Chaining &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;and &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Cipher Feedback &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;create a key that is dependent of the previous block and the final block serves as a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Message Authentication Code&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Key clustering &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;happens when a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;plaintext &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;message generates &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;identical ciphertext &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;messages using the same transformation algorithm, but with &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;different keys.&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Blowfish &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;symmetric &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;block  cipher with variable-length key (32 to 448 bits) designed in 1993 by  Bruce Schneier as an unpatented, license-free, royalty-free replacement  for DES or IDEA.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;IKE= &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Key establishment , Partly based on Okley, putting in place auth keying material.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;SKIP= &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Hybrid encryption for session Key&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;KEA= &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;simmilar to DH&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Users can obtain certificates with various levels of assurance.   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Class 1/Level 1 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;for individuals, intended for email, no proof of identity&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Class 2/Level 2 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is  for organizations and companies for which proof of identity is  requiredLevel 2 certificates verify a user's name, address, social  security number, and other information against a credit bureau database.  - &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Class 3/Level 3 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is  for servers and software signing, for which independent verification  and checking of identity and authority is done by the issuing  certificate authorityLevel 3 certificates are available to companies.   This level of certificate provides photo identification to accompany  the other items of information provided by a level 2 certificate. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Class 4 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;for online business transactions between companies- &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Class 5 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;for private organizations or governmental security&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Certificated &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;issued to CA = ARL&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Certificated &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;issued by CA = CRL&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Internet Key Exchange&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.  A hybrid protocol that implements Oakley and Skeme key exchanges inside  the ISAKMP framework. IKE can be used with other protocols, but its  initial implementation is with the IPSec protocol. IKE provides  authentication of the IPSec peers, negotiates IPSec keys, and negotiates  IPSec &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;security associations (SA)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;DEA &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is  the algorithm that fulfills DES, which is really just a standard. So  DES is the standard and DEA is the algorithm, but in the industry we  usually just refer to it as DES. The CISSP exam may refer to the  algorithm by either name, so remember both&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ffffff;background-color:#ff0000;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;DES MODES &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Electronic Code Book (ECB) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;encypt individual block , good for Databases &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(reveal a pattern)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Cipher Block Chaining (CBC) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The results of one block are XORed with the next block before it is encrypted &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;good large chunks of data at a time&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Cipher Feedback (CFB)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;steady stream of data&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Output Feedback (OFB)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;what  if bit of first block get corrupted (small amount of data at a time but  you need to ensure possible errors do not affect your encryption and  decryption processes) &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Values &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;used to encrypt the next block of plaintext are coming &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;directly from the keystream&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, not from the resulting ciphertext&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Counter Mode (CTR) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;very similar to OFB uses IV Counter &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;DES-EEE3 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Uses three different keys for encryption, and the data are encrypted, encrypted, encrypted.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;DES-EDE3 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Uses three different keys for encryption, and the data are encrypted, decrypted, and encrypted.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;DES-EEE2 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The same as DES-EEE3 but uses only two keys, and the first and third encryption processes use the same key.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;DES-EDE2 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The same as DES-EDE3 but uses only two keys, and the first and third encryption processes use the same key&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-1218971217784725646?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ZSi7KqRECxiKOpeffPSQo5VcE48/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZSi7KqRECxiKOpeffPSQo5VcE48/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ZSi7KqRECxiKOpeffPSQo5VcE48/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZSi7KqRECxiKOpeffPSQo5VcE48/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/T2FQ_R54G8w" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/1218971217784725646/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/07/cissp-cbk-6-cryptography.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/1218971217784725646?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/1218971217784725646?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/T2FQ_R54G8w/cissp-cbk-6-cryptography.html" title="CISSP CBK 6 Cryptography" /><author><name>Kash</name><email>noreply@blogger.com</email></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-iILyKfiYx5c/TiddSFRfpjI/AAAAAAAAAUU/-kFrCh0qNZE/s72-c/cissp.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/07/cissp-cbk-6-cryptography.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEACR306eyp7ImA9WhdTF0g.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-525549296589171184</id><published>2011-07-15T10:56:00.000-07:00</published><updated>2011-07-15T10:59:26.313-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-15T10:59:26.313-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cheat sheet" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP Exam" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cramm questions" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP CBK 4 Physical Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Pass Cissp" /><category scheme="http://www.blogger.com/atom/ns#" term="ISC2 Exam" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP questions" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP" /><category scheme="http://www.blogger.com/atom/ns#" term="Cissp CBK" /><title>CISSP CBK 5 Physical Security</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-prkcUlSN5zc/TiB_hkeCPTI/AAAAAAAAAUM/AhhRZm17m_s/s1600/cissp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 161px; height: 157px;" src="http://3.bp.blogspot.com/-prkcUlSN5zc/TiB_hkeCPTI/AAAAAAAAAUM/AhhRZm17m_s/s320/cissp.jpg" alt="" id="BLOGGER_PHOTO_ID_5629639748915182898" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p dir="ltr" style="text-align: center; margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;span style="color:#000000;background-font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;font-family:Arial;font-size:18pt;color:transparent;"   &gt;Physical Security&lt;/span&gt;&lt;span style="color:#000000;background-font-weight:bold;font-style:normal;font-variant:normal;text-decoration:underline;vertical-align:baseline;font-family:Arial;font-size:11pt;color:transparent;"   &gt;&lt;/span&gt;&lt;/p&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;" id="internal-source-marker_0.832291902630175"&gt;Crime Prevention Through Environmental Design (CPTED)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;  is a discipline that outlines how the proper design of a physical  environment can reduce crime by directly affecting human behavior&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:italic;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Soda acid&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; removes fuel from the fire by discharging a thick form that moves the fire away from the fuel supply.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Carbon dioxide&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; removes oxygen from the fire.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Water &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;reduces fire temperature.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Halon&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; (gas) or its substitutes interferes with the chemical reactions between elements in the fire.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;clapper valve &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;hold the water back in Dray pipe &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Auxiliary station &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;alarms  automatically cause an alarm originating in a data center to be  transmitted over the local municipal fire or police alarm circuits for  relaying to both the local police/fire station and the appropriate  headquarters&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;auditing is a technical control auditing as a audit logs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;static charge of &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;1500 volts &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is able to cause disk drive data loss.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;A charge of &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;1000 volts &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is likely to scramble monitor display and a charge of &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;2000 volts &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;can cause a system shutdown.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;It should be noted that charges of up to &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;20,000 volts &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;or more are possible under conditions of very low humidity with non-static-free carpeting.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;preaction &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;system combines both the dry and wet pipe systems,is most recommended in Comms room . though it is &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;WATER &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;point to remember.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The organization may also have to comply with requirements of the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Occupational Safety and Health Administration (OSHA) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;and the Environmental Protection Agency &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;(EPA)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Tempered glass &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;heating and immediately cooling it 6 to 7 times stronger&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Acrylic glass &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;can be made out of polycarbonate acrylic, which is stronger than&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;standard glass but produces toxic fumes if burned.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The strongest window &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;material is &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;glass-clad polycarbonate &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;good for wide range like&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;fire chemical and breakage.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;passive relocking &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;function, it can detect when someone attempts to tamper with it,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;in which case extra internal bolts will fall into place to ensure it cannot be compromised.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Common-mode noise &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;is electrical noise between the hot and ground wire and between&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;the neutral and ground wire&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;If a safe has a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;thermal relocking &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;function,  when a certain temperature is met (possibly from drilling), an extra  lock is implemented to ensure the valuables are properly protected.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Capacitance detectors &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;monitor  an electrical field surrounding the object being monitored. They are  used for spot protection within a few inches of the object, rather than  for overall room security monitoring used by wave detectors.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;focal length&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt; value relates to the angle of view that can be achieved. Short focal length lenses provide &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;wider-angle views&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;, while long focal length lenses provide a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;narrower view&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;.  The size of the images shown on a monitor, along with the area covered  by one camera, is defined by the focal length. For example, if a company  implements a CCTV camera in a warehouse, the focal length lens values  should be between 2.8 and 4.3 millimeters (mm) so the whole area can be  captured. If the company implements another CCTV camera that monitors an  entrance, that lens value should be around 8mm, which allows a smaller  area to be monitored.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;depth of field &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;refers  to the portion of the environment that is in focus when shown on the  monitor. The depth of field varies depending upon the size of the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;lens opening&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;,  the distance of the object being focuse on, and the focal length of the  lens. The depth of field increases as the size of the lens opening &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;decreases&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;,  the subject distance increases, or the focal length of the lens   decreases. So, if you want to cover a large area and not focus on  specific items, it is best to use a wide-angle lens and a small lens  opening.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;EPA-approved &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;replacements for Halon: FM-200, NAF-S-III, CEA-410, FE-13, Water, Inergen, Argon and Argonite&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Rate-of-rise temperature sensors &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;usually provide a quicker warning than fixed-temperature sensors &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Lighting &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;should be used to discourage intruders and provide safety for personnel, entrances, parking areas and critical sections. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;Critical areas &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;should be illuminated 8 feet high and 2 feet out.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#000000;background-font-weight:normal;font-style:normal;font-variant:normal;text-decoration:none;vertical-align:baseline;font-family:Arial;font-size:11pt;color:transparent;"   &gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-525549296589171184?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/8ljmSEUAPFg8NvNyaXRT0Cq2OrI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8ljmSEUAPFg8NvNyaXRT0Cq2OrI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/8ljmSEUAPFg8NvNyaXRT0Cq2OrI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8ljmSEUAPFg8NvNyaXRT0Cq2OrI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/R_Ukhz46bEU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/525549296589171184/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/07/cissp-cbk-4-physical-security.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/525549296589171184?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/525549296589171184?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/R_Ukhz46bEU/cissp-cbk-4-physical-security.html" title="CISSP CBK 5 Physical Security" /><author><name>Kash</name><email>noreply@blogger.com</email></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-prkcUlSN5zc/TiB_hkeCPTI/AAAAAAAAAUM/AhhRZm17m_s/s72-c/cissp.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/07/cissp-cbk-4-physical-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUMBSHkzfyp7ImA9WhZbFk0.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-5883224862151784321</id><published>2011-06-20T15:02:00.001-07:00</published><updated>2011-06-20T15:04:19.787-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-20T15:04:19.787-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cheat sheet" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cramm" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP Exam" /><category scheme="http://www.blogger.com/atom/ns#" term="Boink Attack" /><category scheme="http://www.blogger.com/atom/ns#" term="telecom and network security" /><category scheme="http://www.blogger.com/atom/ns#" term="Pass Cissp" /><category scheme="http://www.blogger.com/atom/ns#" term="free cissp questions" /><category scheme="http://www.blogger.com/atom/ns#" term="OSI layer model" /><category scheme="http://www.blogger.com/atom/ns#" term="Free hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Network Attacks and Mitigation" /><category scheme="http://www.blogger.com/atom/ns#" term="Cissp CBK" /><title>CISSP CBK 4 Telecom and Network security</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-3n-YtUOxTHk/Tf_DmIk1P-I/AAAAAAAAAUE/bokvodsErSA/s1600/cissp.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 200px; height: 194px;" src="http://3.bp.blogspot.com/-3n-YtUOxTHk/Tf_DmIk1P-I/AAAAAAAAAUE/bokvodsErSA/s200/cissp.jpg" alt="" id="BLOGGER_PHOTO_ID_5620425919886082018" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Forth domain as under.&lt;br /&gt;&lt;br /&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:donotoptimizeforbrowser/&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman";  mso-ansi-language:#0400;  mso-fareast-language:#0400;  mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal" style="text-align:center" align="center"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Telecom and Network security&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:center" align="center"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;span style="text-decoration:none"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:center" align="center"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;span style="text-decoration:none"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Quarter Inch Cartridge drives (QIC).&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; This format is mostly used for home/small office backups, has a small capacity, and is slow, but inexpensive.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Digital Linear Tape (DLT) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is only 0.498 inches (8mm Tape format) in size, yet the compression techniques and head scanning process make it a large capacity and fast tape the QIC and DAT 5Mbps&lt;b&gt;. Digital Audio Tape (DAT)&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;LTO (Linear Tape-Open) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;open-format technology and storage in TB&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;Application: &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;Gateway&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;Presentation: &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;encryption, compression, formating&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;Session: &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;Transport: &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;Network:&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt; Router&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;Datalink:&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt; Bridge, Switch&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;Physical:&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt; Repeater&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Amplitude &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(height of the signal) &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Frequency &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(number of waves in a defined period of time)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Digital signals &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;are more reliable to be used over a longer distance because can easily be extracted from noise and retransmitted and it has only two possible discrete values&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;1 and 0&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;ASynchronous communication &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;sender can send data at any time, and the receiving end must always be ready. (Modem use start and stop bit Asynchronous)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Synchronous communication &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;takes place between two devices that are synchronized usually via a clocking mechanism (Remember &lt;b&gt;synchronous Token &lt;/b&gt;was time based access control)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Baseband &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;uses the entire communication channel for its transmission, &lt;b&gt;Ethernet &lt;/b&gt;is a baseband technology that uses the entire wire for just one channel.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Broadband &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;divides the communication channel into individual and independent channels.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;***Important to note &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;that node authentication, by itself, should not be used to establish trustworthiness of a user within the network.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Fast Ethernet uses the traditional &lt;b&gt;CSMA/CD&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;wireless LAN technology, 802.11, uses&lt;b&gt;CSMA/CA &lt;/b&gt;for its media access functionality.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Token Ring &lt;b&gt;IEEE 802.5 &lt;/b&gt;standard. Each computer is connected to a central hub, called a Multistation Access Unit &lt;b&gt;(MAU) 16 Mbps &lt;/b&gt;Speed &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;UTP Categories Cat 1 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;voice grade&lt;b&gt; Cat 2&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;&lt;/b&gt;Data 4 Mbps &lt;b&gt;Cat 3 &lt;/b&gt;10 Mbps for Token ring &lt;b&gt;Cat 4 &lt;/b&gt;16 Mbps &lt;b&gt;Cat 5 &lt;/b&gt;100 Mbps and Cat 5E 1 Gbp.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Polling LAN media access method setup primary and secondary station primary ask secodary if it need to transmit. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;MAC to IP address&lt;b&gt; ARP&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;IP to MAC = &lt;b&gt;RARP&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Attackers alter a system’s ARP table so it contains incorrect information known &lt;b&gt;ARP table poisoning&lt;/b&gt;. The attacker’s goal is to receive packets intended for another computer. This is a type of &lt;b&gt;masquerading attack&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Wires are encapsulated within &lt;b&gt;pressurized conduits &lt;/b&gt;so if someone attempts to access a wire, the pressure of the conduit will change, causing an alarm to sound.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Class D &lt;b&gt;multicast &lt;/b&gt;uses IGMP protocol.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DHCP &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Discover, client searches for the present DHCP Server &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DHCP Offer, &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Server offer a client an available IP address&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DHCP Request&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;, Client Confirms accepting allocated setting&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DHCP Pack&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;. ack that ip address has been allocated&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;with lease time.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DHCP snooping &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;ensures that DHCP servers can assign IP addresses to only selected systems, identified by their MAC addresses&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;RARP &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The diskless machine hold mac adress it broadcast the information for a specific hardware address and RARP Server reponds with IP address &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;RARP &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;evolved into &lt;b&gt;BOOTP&lt;/b&gt;, which evolved into &lt;b&gt;DHCP&lt;/b&gt;.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;ARP &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;knows the IP address and broadcasts to find the matching hardware address, the MAC address. &lt;b&gt;RARP &lt;/b&gt;knows the hardware address and broadcasts to find the IP address&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Loki attack &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;ICMP status packet is stuffed with data as well&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Routers usually do not pass broadcast information, but bridges do pass broadcast information&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;e-mail gateway &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;convert the message into a standard that all mail servers understand &lt;b&gt;X.400&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;phreaker &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(a phone hacker)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;Types of Firewalls&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;1. Packet filtering&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt; s&lt;/span&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;imple ACL based (Network Layer)&lt;/span&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;2. Stateful&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;keep track of every connection state and maintain &lt;b&gt;state table. &lt;span style="background:yellow;mso-shading:yellow; mso-pattern:solid yellow"&gt;(Transport Layer 3rd Generation)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;3. Proxy&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;&lt;span style="background:yellow;mso-shading: yellow;mso-pattern:solid yellow"&gt;2nd generation &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;firewall, it had 2 types &lt;/span&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:red"&gt;3.1 application-level&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial; color:blue"&gt; &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;(&lt;/span&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;layer 7 make decision on contents of packet) does not understand a certain protocol&lt;/span&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family: Arial;color:red"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:red"&gt;3.2 circuit-level&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt; &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Proxy firewalls (session Layer) SOCKS is a circuit-level proxy gateway&lt;/span&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family: Arial;color:red"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;4. Dynamic packet filtering&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial; color:blue"&gt; &lt;b&gt;&lt;span style="background:yellow;mso-shading:yellow;mso-pattern: solid yellow"&gt;4th Generation&lt;/span&gt;&lt;/b&gt;&lt;span style="background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;firewall, once inside system decide to communicate firewall creates an ACL that allows the external entity to communicate with the internal system via this high port&lt;/span&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;5. Kernel proxy&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue;background:yellow;mso-shading: yellow;mso-pattern:solid yellow"&gt;5th generation FW &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;uses stacking for packet inspection,.(Application Layer)&lt;/span&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family: Arial;color:blue"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;color:white; background:red;mso-shading:red;mso-pattern:solid red"&gt;Three main FW architecture&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;• Screened host&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;• Dual-home&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;• Screened subnet&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;legal honeypot &lt;b&gt;&lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt;Enticement&lt;/span&gt;&lt;/b&gt;&lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt; &lt;/span&gt;system indicating that free Songs are available to download on the honeypot system is &lt;b&gt;&lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt;entrapment&lt;/span&gt;&lt;/b&gt;, because this sets up the user to access the honeypot for &lt;b&gt;reasons other than the intent to harm&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DNS Hierarical &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;structure &lt;b&gt;1992 &lt;/b&gt;the National Science Foundation &lt;b&gt;(NSF)&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;authoritative root &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DNS server contained &lt;b&gt;13 files &lt;/b&gt;one for each root server.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DNS namespaces are split up administratively into &lt;b&gt;zones &lt;/b&gt;and record are called &lt;b&gt;Resource Record &lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;It is recomended to have two DNS servers &lt;b&gt;Primary and secondary &lt;/b&gt;and zones are shared via &lt;b&gt;zone transfer.&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;cyber squatters, &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;individualswho register prominent or established names, hoping to sell these later&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Protocol field values TCP &lt;b&gt;6, &lt;/b&gt;UDP &lt;b&gt;17, &lt;/b&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;ICMP &lt;b&gt;1,&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;&lt;/b&gt;IGMP &lt;b&gt;2&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Diverse routing &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is a method of providing telecommunication continuity that involves routing traffic through split or duplicate cable facilities. &lt;b&gt;Alternative routing &lt;/b&gt;is accomplished via alternative media such as copper cable or wire optics&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Transport layer &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is responsible for reliable data delivery , Congestion Control&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;IEEE 802.5 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;standard defines the token ring media access method. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;802.3 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;refers to Ethernet's CSMA/CD, &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;802.11 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;refers to wireless communications and &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;802.2 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;refers to the logical link control.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;NFS &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;allow Different types of file systems to interoperate.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;FRDS&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;+ (Failure Resistant Disk System Plus).&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The&lt;b&gt; physical layer&lt;/b&gt; (layer 1) defines the X.24, V.35, X.21 and HSSI standard interfaces.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Circuit level proxy &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(Session Layer) does not anayze the application content of the packet in making its decisions, it has lower overhead than an application level proxy&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Internet Message Access Protocol, version 4 (IMAP4) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;as an Internet protocol by which a client workstation can dynamically access a mailbox on a server host to manipulate and retrieve mail messages that the server has received and is holding for the client. IMAP4 has mechanisms for optionally authenticating a client to a server and providing other security services&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;TLS =&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; (TLS) Handshake Protocol + TLS Record Protocol&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Digital Signal level 1 (DS-1) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is the framing specification used for transmitting digital signals at 1.544 Mbps on a T1 facility. &lt;b&gt;DS-0 &lt;/b&gt;is the framing specification used in transmitting digital signals over a single 64 Kbps channel over a T1 facility. &lt;b&gt;DS-3 &lt;/b&gt;is the framing specification used for transmitting digital signals at 44.736 Mbps on a T3 facility.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The &lt;b&gt;Point-to-Point Protocol (PPP&lt;/b&gt;) was designed to support multiple network types over the same serial link &lt;b&gt;SLIP &lt;/b&gt;only support IP over serial network&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;A &lt;b&gt;Failure Resistant Disk System pr&lt;/b&gt;ovides the ability to reconstruct the contents of a failed disk onto a replacement disk and provides the added protection against data loss due to the failure of many hardware parts of the server.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Data Link layer &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;of the OSI/ISO model provides &lt;b&gt;SLIP, CSLIP &lt;/b&gt;and &lt;b&gt;PPP &lt;/b&gt;protocol.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;DOD &lt;b&gt;Application Layer&lt;/b&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;contains protocols that implement user-level functions, such as mail delivery, file transfer and remote login.&lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;DOD &lt;b&gt;Host-to-Host Layer&lt;/b&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; handles connection rendez vous, flow control, retransmission of lost data, and other generic&lt;b&gt; data flow management&lt;/b&gt; between hosts. The mutually exclusive TCP and UDP protocols are this layer's most important members.&lt;span style="background:yellow;mso-shading:yellow; mso-pattern:solid yellow"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;DOD &lt;b&gt;Internet Layer&lt;/b&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is responsible for delivering data across a series of different physical networks that interconnect a source and destination machine. Routing protocols are most closely associated with this layer, as is the IP Protocol, the Internet's fundamental protocol.&lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;DOD &lt;b&gt;Network Access Layer&lt;/b&gt; &lt;/span&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is responsible for delivering data over the particular hardware media in use. Different protocols are selected from this layer, depending on the type of physical network&lt;span style="background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;A &lt;b&gt;&lt;i&gt;differential backup&lt;/i&gt; &lt;/b&gt;is a partial backup that copies a selected file to tape only if the archive bit for that file is turned on, indicating that it has changed since the last full backup. A differential backup leaves the archive bits unchanged on the files it copies.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;A &lt;i&gt;full copy backup&lt;/i&gt; &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(which Microsoft calls a &lt;i&gt;copy backup&lt;/i&gt;) is identical to a full backup except for the last step. The full backup finishes by turning off the archive bit on all files that have been backed up. The full copy backup instead leaves the archive bits unchanged.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Structured Query Language (SQL), &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;implemented at the &lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt;session layer (layer 5) &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The Secure Electronic Transaction (SET) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;protocol requires two pair of asymmetric keys and two digital certificates.&lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt;(Application Layer)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Hierarchical Storage Management (HSM) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is commonly employed in very large data retrieval systems&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Write-once, read-many (WORM) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;optical disk "jukeboxes" are used for archiving data that does not change.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Secure HTTP (S-HTTP) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is designed to send individual messages securely. SSL is designed to establish a secure connection between two computers. SET was originated by VISA and MasterCard as an Internet credit card protocol using digital signature&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Secure HTTP (S-HTTP&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;), which operates at the application layer. S-HTTP is being overtaken by &lt;b&gt;SSL and TLS works on transport layer#&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;X.400 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is used in e-mail as a message handling protocol. &lt;b&gt;X.500 &lt;/b&gt;is used in directory services. &lt;b&gt;X.509 &lt;/b&gt;is used in digital certificates and &lt;b&gt;X.800 &lt;/b&gt;is used a network security standard&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;An open network &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;architecture is one that no vendor owns&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;intranet, &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;a “private” network that uses Internet technologies.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;extranet &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;extends outside the bounds of the company’s network to enable two or more companies.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;MAN &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Connects LAN, MANs are Synchronous Optical Networks (SONETs) or FDDI rings&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;SONET &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;self HEaling network&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;ATM &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;encapsulates data in fixed cells 53 bytes&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;T3 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;= 28 T1 &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;T2 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;= 4 T1&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;T4 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;= 168 T1&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;T1 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;1.544 Mbps&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;T3 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;44.736 Mbps&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;OC1&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; 51.84 Mbps&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Statistical time-division multiplexing (STDM) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;determines in real time how much time each device should be allocated for data transmission&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Frequency division Multiplexing&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;: in available wireless spectrum Each frequency within the spectrum is used as a channel to move data&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;CSU/DSU &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;provides a digital interface for Data Terminal Equipment (DTE), such as terminals, multiplexers, or routers, and an interface to the Data Circuit-Terminating Equipment (DCE) device,&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;circuit Switching Dedicated virtual link.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Packet Switching one connection can pass through a number of different individual devices.X.25 , framerelay&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DTE &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is usually a customer-owned device&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DCE &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is the service provider’s device&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Switched Multimegabit Data Service (SMDS)&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt; is a high-speed packetswitched technology&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Synchronous Data Link Control (SDLC)&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; Dedicated leased lines IBM 1970&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;High-level Data Link Control (HDLC)&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; protocol is also a bit-oriented link layer protocol used for transmission over synchronous lines (time based)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;HDLC &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is extention of SDLC&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;High-Speed Serial Interface (HSSI) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is an interface used to connect multiplexers and&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;routers to high-speed communications services&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;SIP &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is an &lt;b&gt;application layer protocol &lt;/b&gt;that can work over TCP or UDP&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;isochronous &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;network contains the necessary protocols and devices that guarantee continuous bandwidth without interruption.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;voice stream is carried on media protocols such as the &lt;b&gt;Real-time Transport Protocol (RTP).&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;User Agent Client (UAC) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;IPhone, SIP Phone&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;User Agent Server (UAS) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;SIP Server&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;New spam for VOIP = &lt;b&gt;SPIT &lt;/b&gt;(Spam over Internet Telephony).&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;WEP &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;only provide system authentication however 802.1X provides User authentication.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;supplicant &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(wireless device),&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;authenticator &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(AP),&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Authentication server&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; (usually a RADIUS server).&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;EAP &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;allows for mutual authentication to take place between the authentication server and wireless device and provide flexibility.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;802.11i &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;does not specify particular authentication protocols Cisco uses a purely password-based authentication framework called Lightweight&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Extensible Authentication Protocol (LEAP). Other vendors, including Microsoft, use &lt;b&gt;EAP &lt;/b&gt;and Transport Layer Security (&lt;b&gt;EAP-TLS&lt;/b&gt;), which carries out authentication through digital certificates. And yet another choice is Protective EAP (PEAP), where only the server uses a digital certificate&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;WEP Problems&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;1. static WEP encryption keys on all devices (every one have &lt;b&gt;same pasword &lt;/b&gt;in company)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;2. how initialization vectors (IVs) + &lt;b&gt;RC4 &lt;/b&gt;are used that are XOR with packet to produce cipher text (IV value is used over and over again)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;3. integrity assurance issue &lt;b&gt;ICV &lt;/b&gt;Integrity check value&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;802.15 Bluetooth &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;1 to 3 Mbps 2.4 GHz Bluejacking is a type of attach some one send message to avoid setup ur blouetooth device undiscoverable.range is 10 Meter&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;For WAP transport layer security protocol called &lt;b&gt;Wireless Transport Layer Security (WTLS) &lt;/b&gt;When &lt;b&gt;WTLS &lt;/b&gt;data come for Internet service provider have to decrypt and encrypt it back in TLS And SSL so it is in plain taxt for a second whihc is called gap in the WAP&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;WAP &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;uses an XML-compliant Wireless Markup Language (WML&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Imode&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; is same as WAP but target entertainment market , i-Mode works with a slimmed-down version of HTML called compact HTML&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;“log scrubbers” &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;that remove traces of the attacker’s activities from the system logs&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;First generation firewall" &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;packet filtering firewalls&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;"Second generation firewall" &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Proxy based firewalls.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Under proxy based firewall you have Application Level Proxy and also the Circuit-level proxy firewall.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;The application level proxy is very smart and understand the inner structure of the protocol itself.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;The Circuit-Level Proxy is a generic proxy that allow you to proxy protocols for which you do not have an Application Level Proxy.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;This is better than allowing a direct connection to the net.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Today a great example of this would be the SOCKS protocol. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;"Third generation firewall" &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Stateful Inspection firewall.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;This type of firewall makes use of a state table to maintain the context of connections being established. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;"Fourth generation firewall" &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;dynamic packet filtering firewall&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;WAP Stack &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Wireless Markup Language (WML)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Wireless Application Environment (WAE)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Wireless Transport Layer Security Protocol (WTLS)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Wireless Application Environment (WAE)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Wireless Session Layer (WSL)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Wireless Transport Layer (WTL)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;TCP Wrapper&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is a program that monitors incomming packets. It is considered open source. &lt;/span&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family: Arial;color:blue"&gt;TCP Wrappers&lt;/span&gt;&lt;/u&gt;&lt;span style="mso-bidi-font-family: Arial"&gt; can be used to control when UDP servers start, but it has no other control over the server once it is started. UDP servers may continue to run after they've finished processing a legitimate request.&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Again &lt;b&gt;PPTP &lt;/b&gt;operates at &lt;b&gt;Layer 2 &lt;/b&gt;of the OSI model.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;High-rate Digital Subscriber Line (HDSL) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;delivers &lt;b&gt;1.544 Mbps &lt;/b&gt;of bandwidth each way over &lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt;two copper twisted pairs. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;SDSL &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;also delivers &lt;b&gt;1.544 Mbps &lt;/b&gt;but over a &lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt;single copper twisted pair. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;i&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;IPSec &lt;b&gt;Transport mode &lt;/b&gt;is established when the enpoint is a&lt;span style="background:#660000; mso-shading:#660000;mso-pattern:solid #660000"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;b&gt;&lt;i&gt;&lt;span style="mso-bidi-font-family:Arial;color:white;background:#CC0000;mso-shading: #CC0000;mso-pattern:solid #CC0000"&gt;host&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;10Base2, also known as &lt;b&gt;&lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt;RG58&lt;/span&gt;&lt;/b&gt;, or &lt;b&gt;thinnet, &lt;/b&gt;is limited to 185 meters. 10Base5, also known as &lt;b&gt;&lt;span style="background:yellow;mso-shading:yellow;mso-pattern:solid yellow"&gt;RG8/RG11&lt;/span&gt;&lt;/b&gt; or thicknet, is limited to 500 meters&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Failure Resistand Disk System (FRDS) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is that it enables the continuous monitoring of these parts and the alerting of their failure.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;AH (51) provides &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;integrity, authentication, and non-repudiation. Security Associations (SAs) can be combined into bundles to provide authentication, confidentialility and layered communication.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The &lt;b&gt;Well Known Ports&lt;/b&gt; are those from 0 through 1023.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The &lt;b&gt;Registered Ports&lt;/b&gt; are those from 1024 through 49151.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The &lt;b&gt;Dynamic and/or Private Ports&lt;/b&gt; are those from 49152 through 65535.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;There are &lt;b&gt;six basic security services &lt;/b&gt;defined by the OSI: &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Authentication, access control, data confidentiality, data integrity, nonrepudiation and logging and monitoring. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;POP &lt;b&gt;110&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Post Office Protocol (POP2) &lt;b&gt;109&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Network News Transfer Protocol &lt;b&gt;119&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;NetBIOS &lt;b&gt;139&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The &lt;b&gt;TRANSPORT LAYER &lt;/b&gt;establish &lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%; mso-bidi-font-family:Arial"&gt;logical connection between the END POINTS of an internetwork, that is, the &lt;b&gt;originating host &lt;/b&gt;and the &lt;b&gt;destination host&lt;/b&gt;.&lt;/span&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The &lt;b&gt;Land&lt;/b&gt; attack involves the perpetrator sending spoofed packet(s) with the SYN flag set to the victim's machine on any open port that is listening&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The &lt;b&gt;Boink&lt;/b&gt; attack, involves the perpetrator sending corrupt UDP packets to the host. It however allows the attacker to attack multiple ports where Bonk was mainly directed to port 53 (DNS&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-5883224862151784321?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/vBWzvW8BtM9QRt9NtvdzHeX6oCY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vBWzvW8BtM9QRt9NtvdzHeX6oCY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/vBWzvW8BtM9QRt9NtvdzHeX6oCY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vBWzvW8BtM9QRt9NtvdzHeX6oCY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/1gOxDZyFxNA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/5883224862151784321/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/06/cissp-cbk-4-telecom-and-network.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/5883224862151784321?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/5883224862151784321?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/1gOxDZyFxNA/cissp-cbk-4-telecom-and-network.html" title="CISSP CBK 4 Telecom and Network security" /><author><name>Kash</name><email>noreply@blogger.com</email></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-3n-YtUOxTHk/Tf_DmIk1P-I/AAAAAAAAAUE/bokvodsErSA/s72-c/cissp.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/06/cissp-cbk-4-telecom-and-network.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUUGSX48fip7ImA9WhZbFk0.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-4568308066839924737</id><published>2011-06-15T15:13:00.000-07:00</published><updated>2011-06-20T15:00:28.076-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-20T15:00:28.076-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cheat sheet" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cramm" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP Exam" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cramm questions" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Architecture and Design" /><category scheme="http://www.blogger.com/atom/ns#" term="Pass Cissp" /><category scheme="http://www.blogger.com/atom/ns#" term="free cissp questions" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP questions" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cramm Sheet" /><category scheme="http://www.blogger.com/atom/ns#" term="Cissp CBK" /><title>CISSP CBK 3 Security Architecture and Design</title><content type="html">&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;a href="http://2.bp.blogspot.com/-ZSpz-SelKow/Tfkvuayp0vI/AAAAAAAAAT8/fn9I1HURJd8/s1600/cissp.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5618574484633670386" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 139px; CURSOR: pointer; HEIGHT: 134px; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/-ZSpz-SelKow/Tfkvuayp0vI/AAAAAAAAAT8/fn9I1HURJd8/s200/cissp.jpg" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;br /&gt;Hi everyone, 3rd domain is as under&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:donotoptimizeforbrowser/&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman";  mso-ansi-language:#0400;  mso-fareast-language:#0400;  mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;System is working in &lt;b&gt;asymmetric mode &lt;/b&gt;one CPU is dedicated to one application.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;A &lt;b&gt;&lt;i&gt;process &lt;/i&gt;&lt;/b&gt;is the set of instructions that is actually running, program is not a process until unless its is loaded and being allocated resources.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;mso-bidi-font-family: Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;multiprogramming&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;, which means that more than one program (or process) can be loaded i.e antivirus and another programme running side by side &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="font-size:10.0pt; line-height:115%;mso-bidi-font-family:Arial"&gt;.&lt;/span&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;A &lt;b&gt;&lt;i&gt;maskable &lt;/i&gt;i&lt;/b&gt;nterrupt is assigned to an event that may not be overly important and the programmer can indicate that if that interrupt calls, the program does not stop what it is doing. &lt;b&gt;&lt;i&gt;Non-maskable interrupts &lt;/i&gt;&lt;/b&gt;can never be overridden by an application because the event that has this type of interrupt assigned to it is critical. As the reset button.&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;mso-bidi-font-family: Arial"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Watchdog timer&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; is an example of critical process that resets the system if the system cannot recover it self from the problem&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="font-size:10.0pt;line-height:115%; mso-bidi-font-family:Arial"&gt;thread &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;is made up of an individual instruction set and the data that must be worked on by the CPU like print function in word process multi threading refers to the multiple thread handling simultaneously&lt;/span&gt;&lt;span style="font-size: 10.0pt;line-height:115%;mso-bidi-font-family:Arial"&gt;. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;mso-bidi-font-family: Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;A &lt;b&gt;garbage collector i&lt;/b&gt;s software that runs an algorithm to identify unused committed memory and then tells the operating system to mark that memory as “available.”&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;kernel mode, privileged mode, and supervisory mode all mean the same thing A &lt;b&gt;monolithic kernel &lt;/b&gt;means all of the kernel’s activity works in privileged (supervisory) mode windows vista anad xp are all monolitic operating system as alll function workd inside kernel &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Computer Security Policy Model &lt;b&gt;Orange Book &lt;/b&gt;is based is the &lt;b&gt;Bell-LaPadula Model.&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The &lt;b&gt;&lt;i&gt;reference monitor &lt;/i&gt;&lt;/b&gt;is an abstract machine that mediates all access subjects have to objects&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;mso-bidi-font-family: Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Security labels are not required until security rating &lt;b&gt;B&lt;/b&gt;; thus, &lt;b&gt;C2 &lt;/b&gt;does not require security labels but &lt;b&gt;B1 &lt;/b&gt;does.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;TCSEC &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;addresses confidentiality, but not integrity &lt;b&gt;ITSEC &lt;/b&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;addresses &lt;b&gt;CIA&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Limitation of Orange book &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is it dosent evaluate the system for what those users do with the information oncethey are authorized, Only &lt;b&gt;address Single system Security &lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;b&gt;&lt;i&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;Trusted Network Interpretation (TNI)&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;, also called the &lt;b&gt;&lt;i&gt;Red Book &lt;/i&gt;&lt;/b&gt;because of the color of its cover, addresses security evaluation topics for networks and &lt;b&gt;&lt;i&gt;network components. &lt;/i&gt;&lt;/b&gt;It addresses isolated local area networks and wide area internetwork systems.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="mso-bidi-font-family: Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;ITSEC (European) actually &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;separates these two attributes (functionality and assurance) and rates them separately, whereas &lt;b&gt;TCSEC &lt;/b&gt;clumps them together and assigns them one rating (D through A1).&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="mso-bidi-font-family: Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;Certification&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; is the comprehensive technical evaluation of the security components and their compliance for the purpose of accreditation.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;Accreditation &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Accreditation is the formal acceptance of the adequacy of a system’s overall security and functionality by management.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="mso-bidi-font-family: Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;Certification &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is a &lt;b&gt;technical &lt;/b&gt;review that assesses the security mechanisms and evaluates their effectiveness. &lt;b&gt;Accreditation &lt;/b&gt;is &lt;b&gt;management’s &lt;/b&gt;official acceptance of the information in the certification process findings&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Security testing and trusted distribution are required for &lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family: Arial;color:blue"&gt;Life-Cycle Assurance&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;.&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DIACAP&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;DIACAP &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(DoD Information Assurance Certification and Accreditation Process) effective Nov 2007 for C&amp;amp;A within the Department of Defense. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The &lt;b&gt;DoD Information Assurance Certification and Accreditation Process&lt;/b&gt; (&lt;b&gt;DIACAP&lt;/b&gt;) is the United States Department of Defense (DoD) process to ensure that&lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Risk_management"&gt;&lt;span style="mso-bidi-font-family: Arial;color:black;text-decoration:none;text-underline:none"&gt; &lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Risk_management"&gt;&lt;span style="mso-bidi-font-family: Arial;color:#000099"&gt;risk&lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Risk_management"&gt;&lt;span style="mso-bidi-font-family: Arial;color:#000099"&gt; &lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Risk_management"&gt;&lt;span style="mso-bidi-font-family: Arial;color:#000099"&gt;management&lt;/span&gt;&lt;/a&gt;&lt;span style="mso-bidi-font-family: Arial"&gt; is applied on&lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Information_systems"&gt;&lt;span style="mso-bidi-font-family: Arial;color:black;text-decoration:none;text-underline:none"&gt; &lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Information_systems"&gt;&lt;span style="mso-bidi-font-family: Arial;color:#000099"&gt;information&lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Information_systems"&gt;&lt;span style="mso-bidi-font-family: Arial;color:#000099"&gt; &lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Information_systems"&gt;&lt;span style="mso-bidi-font-family: Arial;color:#000099"&gt;systems&lt;/span&gt;&lt;/a&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; (IS). DIACAP defines a DoD-wide formal and standard set of activities, general tasks and a management structure process for the certification and accreditation (C&amp;amp;A) of a DoD IS that will maintain the&lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Information_assurance"&gt;&lt;span style="mso-bidi-font-family:Arial;color:black;text-decoration:none;text-underline: none"&gt; &lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Information_assurance"&gt;&lt;span style="mso-bidi-font-family:Arial;color:#000099"&gt;information&lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Information_assurance"&gt;&lt;span style="mso-bidi-font-family:Arial;color:#000099"&gt; &lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Information_assurance"&gt;&lt;span style="mso-bidi-font-family:Arial;color:#000099"&gt;assurance&lt;/span&gt;&lt;/a&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; (IA) posture throughout the&lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Systems_Development_Life_Cycle"&gt;&lt;span style="mso-bidi-font-family:Arial;color:black;text-decoration:none;text-underline: none"&gt; &lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Systems_Development_Life_Cycle"&gt;&lt;span style="mso-bidi-font-family:Arial;color:#000099"&gt;system&lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Systems_Development_Life_Cycle"&gt;&lt;span style="mso-bidi-font-family:Arial;color:#000099"&gt;'&lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Systems_Development_Life_Cycle"&gt;&lt;span style="mso-bidi-font-family:Arial;color:#000099"&gt;s&lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Systems_Development_Life_Cycle"&gt;&lt;span style="mso-bidi-font-family:Arial;color:#000099"&gt; &lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Systems_Development_Life_Cycle"&gt;&lt;span style="mso-bidi-font-family:Arial;color:#000099"&gt;life&lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Systems_Development_Life_Cycle"&gt;&lt;span style="mso-bidi-font-family:Arial;color:#000099"&gt; &lt;/span&gt;&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/Systems_Development_Life_Cycle"&gt;&lt;span style="mso-bidi-font-family:Arial;color:#000099"&gt;cycle&lt;/span&gt;&lt;/a&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;NIACAP&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;National Information Assurance Certification and Accreditation Process (NIACAP), establishes the minimum national standards for certifying and accrediting national security systems. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;&lt;b&gt;HIPAA&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;The HIPAA legislation had four primary objectives:&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(1) Assure health insurance portability by eliminating job-lock due to pre-existing medical conditions,&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(2) Reduce healthcare fraud and abuse,&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(3) Enforce standards for health information and&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;(4) Guarantee security and privacy of health information.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;B2 &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;and &lt;b&gt;B3 &lt;/b&gt;are concerned with covert channels, only level A1 involves a formal covert channel analysis.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;In &lt;b&gt;state machine models&lt;/b&gt;, to verify the security of a system, the state is used&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Evaluation &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is the process of independently assessing a system against a &lt;b&gt;standard &lt;/b&gt;of comparison, such as &lt;b&gt;evaluation criteria&lt;/b&gt;. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Certification &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is the process of performing a &lt;b&gt;comprehensive analysis &lt;/b&gt;of the &lt;b&gt;security features &lt;/b&gt;and &lt;b&gt;safeguards &lt;/b&gt;of a system to establish the extent to which the security requirements are satisfied. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Accreditation &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is the official management decision to operate a system. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Acceptance &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;testing refers to user testing of a system before accepting delivery.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Orange book &lt;i&gt;Operational &lt;/i&gt;&lt;/span&gt;&lt;/b&gt;&lt;i&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Assurance and &lt;b&gt;Life-Cycle &lt;/b&gt;Assurance.&lt;/span&gt;&lt;/i&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Clark Wilsom&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; integrity model defines a &lt;b&gt;constrained &lt;/b&gt;data item, an &lt;b&gt;integrity &lt;/b&gt;verification procedure and a &lt;b&gt;transformation &lt;/b&gt;procedure?&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;National Computer Security Center (NCSC)= &lt;b&gt;TCSEC&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;The &lt;b&gt;life cycle &lt;/b&gt;assurance requirements specified in the Orange Book are: &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;security testing&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow;mso-shading:yellow; mso-pattern:solid yellow"&gt;, &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;design specification and testing (B1,2,3,A1)&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;, &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;configuration management &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;trusted distribution(A1)&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow;mso-shading:yellow; mso-pattern:solid yellow"&gt;. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;System integrity is also defined in the Orange Book but is an operational assurance requirement, not a life cycle assurance requirement&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Complex Instruction Set Computer (CISC) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;uses instructions that perform many operations per instruction.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Pipelining &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;involves overlapping the steps of different instructions to increase the performance in a computer. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Reduced Instruction Set Computers (RISC) &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;involve simpler instructions that require fewer clock cycles to execute. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Scalar processors &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;are processors that execute one instruction at a time.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Polyinstantiation&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; permits a database to have two records that are identical except for their classifications &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Information Labels &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;contain more information than &lt;b&gt;Sensitivity Levels&lt;/b&gt;, but are not used by the Reference Monitor to determine access permissions.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;There are &lt;b&gt;three &lt;/b&gt;main requirements of the &lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family:Arial; color:blue"&gt;security kernel&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family: Arial"&gt;:&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;• It must provide &lt;b&gt;isolation for the processes &lt;/b&gt;carrying out the reference monitor concept, and the processes must be tamperproof.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;• It must be &lt;b&gt;invoked for every access attempt &lt;/b&gt;and must be impossible to circumvent. Thus, the security kernel must be implemented in a complete and foolproof way.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;• It must be &lt;b&gt;small enough &lt;/b&gt;to be able to be tested and verified in a complete and comprehensive manner.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Indirect addressing &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is when the address location that is specified in the program instruction contains the address of the final desired location. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Direct addressing &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is when a portion of primary memory is accessed by specifying the actual address of the memory location. &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Indexed addressing &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is when the contents of the address defined in the program's instruction is added to that of an index register.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;D – Minimal protection&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;C – Discretionary protection&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;C1 – Discretionary Security Protection&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;C2 – Controlled Access Protection&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;B – Mandatory Protection&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;B1 – Labeled Security&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;B2 – Structured Protection&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;B3 –&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Security Domains&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;A – Verified Protection&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;A1 – Verified Design&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;In &lt;b&gt;MAC &lt;/b&gt;Model &lt;b&gt;subject &lt;/b&gt;has &lt;b&gt;clearance &lt;/b&gt;and &lt;b&gt;Need to know &lt;/b&gt;when this alliens with &lt;b&gt;Object classification &lt;/b&gt;and &lt;b&gt;Category &lt;/b&gt;information can flow &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;EAL 1 : functionally tested&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;EAL 2 : structurally tested&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;EAL 3 : methodically tested and checked&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;EAL 4 : methodically designed, tested and reviewed&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;EAL 5 : semifomally designed and tested&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;EAL 6 : semifomally verified design and tested&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;EAL 7 : fomally verified design and tested.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;NIST &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;PRODUCES and &lt;b&gt;PUBLISHES&lt;/b&gt; the &lt;i&gt;Federal Information Processing Standards (&lt;b&gt;FIPS&lt;/b&gt;)&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;operational assurance &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow;mso-shading:yellow; mso-pattern:solid yellow"&gt;requirements specified in the Orange Book are&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;1. &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow;mso-shading:yellow; mso-pattern:solid yellow"&gt;system architecture, &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;2. &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow;mso-shading:yellow; mso-pattern:solid yellow"&gt;system integrity, &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;3. &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow;mso-shading:yellow; mso-pattern:solid yellow"&gt;covert channel analysis, &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;4. &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow;mso-shading:yellow; mso-pattern:solid yellow"&gt;trusted facility management &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt;5. &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow;mso-shading:yellow; mso-pattern:solid yellow"&gt;trusted recovery&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial;background:yellow; mso-shading:yellow;mso-pattern:solid yellow"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;Trusted Facility Management&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; is &lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family:Arial;color:blue"&gt;Separation of Duties&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;and is provided in the form of support for system administrator and operator functions and that stringent configuration management controls are imposed. You have single accounts to perform specific functions and not general accounts available to all individuals. (single admin account is use to do all Security things)&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="mso-bidi-font-family: Arial;color:blue"&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Polyinstantiation &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;permits a database to have two records that are identical except for their classifications (i.e., the primary key includes the classification). Thus, APFEL's new unclassified record did not collide with the real, top secret record, so APFEL was not able to learn about FIGs pineapples.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;Polymorphism &lt;/span&gt;&lt;/b&gt;&lt;span style="mso-bidi-font-family:Arial"&gt;is a term that can refer to, among other things, viruses that can change their code to better hide from anti-virus programs or to objects of different types in an object-oriented program that are related by a common superclass and can, therefore, respond to a common set of methods in different ways. That's also irrelevant to this question.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-4568308066839924737?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ZTW7-B_9fn20CNeQhImaUt32FCw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZTW7-B_9fn20CNeQhImaUt32FCw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ZTW7-B_9fn20CNeQhImaUt32FCw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZTW7-B_9fn20CNeQhImaUt32FCw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/71CekAxNOlM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/4568308066839924737/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/06/cissp-cbk-3-security-architecture-and.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/4568308066839924737?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/4568308066839924737?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/71CekAxNOlM/cissp-cbk-3-security-architecture-and.html" title="CISSP CBK 3 Security Architecture and Design" /><author><name>Kash</name><email>noreply@blogger.com</email></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-ZSpz-SelKow/Tfkvuayp0vI/AAAAAAAAAT8/fn9I1HURJd8/s72-c/cissp.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/06/cissp-cbk-3-security-architecture-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0YNR34-eip7ImA9WhZUEkQ.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-6435103132761198497</id><published>2011-06-05T11:35:00.001-07:00</published><updated>2011-06-05T11:39:56.052-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-05T11:39:56.052-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cheat sheet" /><category scheme="http://www.blogger.com/atom/ns#" term="Access control Entry Summary" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP Exam" /><category scheme="http://www.blogger.com/atom/ns#" term="Pass Cissp" /><category scheme="http://www.blogger.com/atom/ns#" term="Two fish encryption" /><category scheme="http://www.blogger.com/atom/ns#" term="free cissp questions" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP" /><category scheme="http://www.blogger.com/atom/ns#" term="Netcat" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cramm Sheet" /><category scheme="http://www.blogger.com/atom/ns#" term="Cissp CBK" /><title>CISSP CBK 2 Access control</title><content type="html">&lt;p style="text-align: center; margin-top: 0pt; margin-bottom: 0pt;" id="internal-source-marker_0.21688891675462596"&gt;&lt;span style="color:#000000;background-font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;font-family:Arial;font-size:11pt;color:transparent;"   &gt;Access Control &lt;/span&gt;&lt;/p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-N589xEiPTiQ/TevMmI3qcNI/AAAAAAAAAT0/g4HaX_cuetI/s1600/cissp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 115px; height: 112px;" src="http://4.bp.blogspot.com/-N589xEiPTiQ/TevMmI3qcNI/AAAAAAAAAT0/g4HaX_cuetI/s320/cissp.jpg" alt="" id="BLOGGER_PHOTO_ID_5614806316035502290" border="0" /&gt;&lt;/a&gt;Hi every one !!! Cramm sheet for Second domain as ready&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;" id="internal-source-marker_0.21688891675462596"&gt;A &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;race condition&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;  is when processes carry out their tasks on a shared resource in an  incorrect order like authorization is done before authentication.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;When system rejects an authorized individual, it is called a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Type I error &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(false rejection rate). When the system accepts impostors who should be rejected, it is called a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Type II error &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(false acceptance rate).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;CER (Cross Error Rate)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; where Type I and Type II matches and CER 3 is good then CER 4 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Biometrics Process time 5 to 10 minutes &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;OTP asynchronous &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is based on challenge/response mechanisms, while &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;synchronous&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; is based on time- or counter-driven mechanisms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Rainbow table &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;An attacker uses a table that contains all possible passwords already in a hash format.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;digital signature &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is  a technology that uses a private key to encrypt a hash value (message  digest). The act of encrypting this hash value with a private key is  called digitally signing a message&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;memory card &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;holds information but cannot process information. A &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;smart card &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;holds information and has the necessary hardware and software to actually process that information.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Fault Generation &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;attach   attacker generate the fault and try to figure out how the system  behave like in smart card they increase the input voltage &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Side channel &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;attack the attacker watches how something works and how it reacts in different situations instead of trying to “invade” it&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Kerberose &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;authentication service &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is the part of the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;KDC &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;that authenticates a principal, and the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;TGS &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is the part of the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;KDC &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;that makes the tickets and hands them out to the principals.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;TGTs &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are used so the user does not have to enter his password each time he needs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;to communicate with another principal&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Kerberos &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;uses tickets to authenticate subjects to objects, whereas &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;SESAME &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(it  is used to address the weakness in Kerberose and uses symmetric and  Asymmetric Encryption) uses Privileged Attribute Certificates (&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;PACs&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;),&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Three main types of &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;access control models&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;discretionary, &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(Owner gives access to resource) identity based access control&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;mandatory&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;,  (owners dont have control every thing is based upon clerence levels &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;nondiscretionary &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(also called role based). (&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;RBAC &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;model is the best system for a company that has high employee turnover)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Controls are implemented to mitigate risk and reduce the potential for loss. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Preventive controls &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are put in place to inhibit harmful occurrences; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;detective controls &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are established to discover harmful occurrences; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;corrective controls &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are used to restore systems that are victims of harmful attacks.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;DAC &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Data owners decide who has access to resources, and ACLs are used to enforce the security policy.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;MAC &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Operating systems enforce the system’s security policy through the use of security labels.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; RBAC &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Access decisions are based on each subject’s role and/or functional position&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Access control matrix &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Table of &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ff0000;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;subjects and objects&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; that outlines their access relationships&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;ACL &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Bound to an &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ff0000;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;object &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;and indicates what subjects can access it&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Capability table &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Bound to a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ff0000;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;subject &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;and indicates what objects that subject can access&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Content-based access &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Bases access decisions on the sensitivity of the data, not solely on subject identity&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Context-based access Bases &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;access decisions on the state of the situation, not solely on identity or content sensitivity&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Restricted interface Limits &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;the user’s environment within the system,thus limiting access to objects&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Rule-based access Restricts &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;subjects’ access attempts by predefined rules&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Watchdog&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; timers are commonly used to detect software faults, such as a process ending abnormally or hanging&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Diameter &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is a peer-based protocol that allows either end to initiate cnnection.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Administrative Controls&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Policy and procedures&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Personnel controls&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Supervisory structure&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Security-awareness training&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Testing&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; Physical Controls&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Network segregation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Perimeter security&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Computer controls&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Work area separation&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Data backups&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Cabling&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Control zone&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Technical Controls&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• System access&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Network architecture&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Network access&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Encryption and protocols&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• Auditing&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The seven different &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;access control functionalities &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are asfollows:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Deterrent &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Intended to discourage a potential attacker&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Preventive &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Intended to avoid an incident from occurring&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Corrective&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; Fixes components or systems after an incident has occurred&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Recovery &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Intended to bring controls back to regular operations&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Detective &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Helps identify an incident’s activities&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Compensating &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Controls that provide for an alternative measure of control&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Directive &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Mandatory controls that have been put in place due to regulations or environmental requirements&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;threshold &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;= clipping Level&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;when hacker deletes the audit logs it is known as &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Scrubbing&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Avoid &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Tempest  &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;two solution &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;control Zone &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;by having special material in the walls to contain electrical signals or &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;White Noise &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;uniform spectrum of random electrical signals.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;entrapment &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is illegal where u trap the hacker &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Entrancement &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;when you leave a system as a honey pot&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Pharming &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is the DNS poisoning&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;DAC &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is implemented and enforced through the use of access control lists (ACLs), which are held in a matrix (access control Matrix). &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;MAC &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is implemented and enforced through the use of &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;security labels.&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;In the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;lattice model,&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;  users are assigned security clearences and the data is classified.   Access decisions are made based on the clearence of the user and the  classification of the object.  &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ff0000;background-color:#ffff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ff0000;background-color:#ffff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Cognitive passwords &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are fact or opinion-based information used to verify an individuals identity&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Due Diligance is for Compliance&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A network-based IDS is &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;passive &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;while it acquires data. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:10pt;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Bell-LaPadula model &lt;/span&gt;&lt;span style="font-size:10pt;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Simple security rule: &lt;/span&gt;&lt;span style="font-size:10pt;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A subject cannot read data within an object that resides at a higher security level ("&lt;/span&gt;&lt;span style="font-size:10pt;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;No read up&lt;/span&gt;&lt;span style="font-size:10pt;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;" rule).&lt;/span&gt;&lt;span style="font-size:10pt;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;*- property rule: &lt;/span&gt;&lt;span style="font-size:10pt;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A subject cannot write to an object at a lower security level ("&lt;/span&gt;&lt;span style="font-size:10pt;font-family:Verdana;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;No write down&lt;/span&gt;&lt;span style="font-size:10pt;font-family:Verdana;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;" rule).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Assurance &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;procedures  ensure that access control mechanisms correctly implement the security  policy for the entire life cycle of an information system.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The position of a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;bank teller is &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#0000ff;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:underline;vertical-align:baseline;"&gt;specific role&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; within the bank, so you would implement a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;role-based policy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Kerberose &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is authentication &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;NOTT &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;authorization service&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Soft Control &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is another way of referring to &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Administrative control&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;From most effective &lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(lowest CER) &lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;to least effective &lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(highest CER&lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;) are: Iris scan, fingerprint, voice verification, keystroke dynamics.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Emanation attacks &lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are the act of intercepting electrical signals that radiate from computing equipment &lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(TEMPEST)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;SESAME &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;uses &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Attribute Certificate&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;  (AC) that allows for granular access control . It supports  authentication, confidentiality but also authorization.  In environment  with well defined roles and capability is an issue , SESAME and PERMIS  are role based single sign on technologies&lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:10pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Capability &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is Row in Matrix and ACL is &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Column&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; in Matrix.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Access control list (ACL) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;"It [ACL] specifies a list of users [subjects] who are allowed access to each object"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A capability table &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are used to track, manage and apply controls based on the object and rights, or &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;capabilities&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;of a subject&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;An access control matrix &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is a way of describing the rules for an access control strategy.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Discretionary&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; access control is &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Identity based ACL &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;widely used in Commercial environment&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;MAC &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is Lattice Based.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Systems  accountability depends on the ability to ensure that senders cannot  deny sending information and that receivers cannot deny receiving it.  Because the mechanisms implemented in &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;nonrepudiation &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;prevent the ability to successfully repudiate an action, it can be considered as a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;preventive control&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Subject &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;could be a users, a programs, a print queue, and processes where &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Objects &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;would be files, directories, devices, windows, and sockets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Padded cells&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;  are simulated environments to which IDSs seamlessly transfer detected  attackers and are designed to convince an attacker that the attack is  going according to the plan. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Principle P1 authenticates to the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Key Distribution Center (KDC), &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;principle P1 receives a Ticket Granting Ticket &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(TGT), &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;and principle P1 requests a service ticket from the Ticket Granting Service &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(TGS) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;in order to access the application server P2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffffff;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Clark-Wilson &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;model uses &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;separation of duties&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;,  which divides an operation into different parts and requires different  users to perform each part. This prevents authorized users from making  unauthorized modifications to data, thereby protecting its integrity.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Each ticket in &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#0000ff;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:underline;vertical-align:baseline;"&gt;Kerberos&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; has a timestamp and are subject to time expiration to help prevent replay attack&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;In 1973 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#0000ff;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:underline;vertical-align:baseline;"&gt;Bell and LaPadula&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; created the first mathematical model of a multi-level security system.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Biometric devices can be use for either IDENTIFICATION or AUTHENTICATION&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;ONE TO ONE is for AUTHENTICATION&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;ONE TO MANY is for IDENTIFICATION&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Internal consistency of the information system. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;ensures  that internal data is consistent, the subtotals match the total number  of units in the data base. total number of Printers in LAN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;External consistency of the information system. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;External  consistency is were the data matches the real world. If you have an  automated inventory system the numbers in the data must be consistent  with what your stock actually is.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Rule based or role based = Non-Discretionary Access Control (NDAC) &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Identity based = DAC&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer Security Policy Model &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Orange Book &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is based is the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Bell-LaPadula Model&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;.&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Calibri;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#f6b26b;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Bell LaPadula &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#f6b26b;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;  = Confidentiality , &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#f6b26b;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;NO&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#f6b26b;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#f6b26b;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;READ UP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#f6b26b;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;* STAR (NO Write Down)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;ClarkWilson = Program &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;B/W &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;subject &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;and &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Object/ Separation of Duties&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;BIBA *STAR = NO Write UP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Twofish encryption &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;to encrypt network traffic thereby evading IDS/IDP detection. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Netcat &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is  a utility that can be used to open ports on a compromised host.Cryptcat  does this but supports twofish (Schneier) encryption which is not  decryptable by an IDS in transit&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Static Password token &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;the  owner identity is authenticated by the token. An example of this  occurring is when an employee swipes his or her smart card over an  electronic lock to gain access to a store room. (smart card is like  users password something you have)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;hand geometry &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;pattern can be stored in only 9 bytes. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Retina pattern &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;uses 96 bytes whereas the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;fingerprint &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;uses between 0.5 and 1.5 kb and the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;voice pattern &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;typically uses between 1 and 10 kb.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;principal &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;decrypts the message containing the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;session key&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;  (Kc, tgs) with its secret key (Kc), and will now use this session key  to communicate with the TGS principal (sometimes refer to as resource or  server) he wishes to access. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Operations Security &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;domain is concerned with triples &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;- threats, vulnerabilities and assets&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(ATV)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The hand geometry pattern can be stored in only &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;9 bytes&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Retina pattern uses 96 bytes whereas the fingerprint uses between &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;0.5 and 1.5 kb &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;voice pattern typically uses between &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;1 and 10 kb&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Take-Grant access &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;control model uses a &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;directed graph &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;to specify the rights that a subject can transfer to an object, or that a subject can take from another subject. The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Biba &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;and &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Clark-Wilson &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;models are integrity models and the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Non-interference &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;model is an &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;information flow model&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-6435103132761198497?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/LiQM6Hw9e4f9jCkszCrdDqRot5s/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LiQM6Hw9e4f9jCkszCrdDqRot5s/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/LiQM6Hw9e4f9jCkszCrdDqRot5s/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LiQM6Hw9e4f9jCkszCrdDqRot5s/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/GTFr7rFTyNQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/6435103132761198497/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/06/cissp-cbk-2-access-control.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/6435103132761198497?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/6435103132761198497?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/GTFr7rFTyNQ/cissp-cbk-2-access-control.html" title="CISSP CBK 2 Access control" /><author><name>Kash</name><email>noreply@blogger.com</email></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-N589xEiPTiQ/TevMmI3qcNI/AAAAAAAAAT0/g4HaX_cuetI/s72-c/cissp.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/06/cissp-cbk-2-access-control.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEYEQno_eyp7ImA9WhZUEk0.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-2099571897568246372</id><published>2011-06-04T09:43:00.000-07:00</published><updated>2011-06-04T09:48:23.443-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-04T09:48:23.443-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cheat sheet" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP Exam" /><category scheme="http://www.blogger.com/atom/ns#" term="Exam questions" /><category scheme="http://www.blogger.com/atom/ns#" term="Pass Cissp" /><category scheme="http://www.blogger.com/atom/ns#" term="ISC2 Exam" /><category scheme="http://www.blogger.com/atom/ns#" term="Information Security and Risk Mgmt  questions" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP questions" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP" /><category scheme="http://www.blogger.com/atom/ns#" term="Information Security and Risk Mgmt" /><category scheme="http://www.blogger.com/atom/ns#" term="CISSP cramm Sheet" /><title>CISSP CBK 1 Information Security and Risk Mgmt</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-JSFOUq_BEZA/TephpuZgMrI/AAAAAAAAASo/beb-jP9OBMc/s1600/cissp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 116px; height: 113px;" src="http://3.bp.blogspot.com/-JSFOUq_BEZA/TephpuZgMrI/AAAAAAAAASo/beb-jP9OBMc/s320/cissp.jpg" alt="" id="BLOGGER_PHOTO_ID_5614407254928274098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="  color: rgb(0, 0, 0); background- font-weight: bold; font-style: normal; text-decoration: underline; vertical-align: baseline;font-family:Arial;font-size:11pt;color:transparent;"   &gt;&lt;span style="font-size:130%;"&gt;Information Security and Risk Mgmt&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: left;"&gt;&lt;span style="  color: rgb(0, 0, 0); background- font-weight: bold; font-style: normal; text-decoration: underline; vertical-align: baseline;font-family:Arial;font-size:11pt;color:transparent;"   &gt;&lt;/span&gt;Hi guys, I have strated writing down Cramm sheet for CISSP Exam, though it is tough task buy I am commited to complete it by the end of June 2011.&lt;br /&gt;&lt;br /&gt;All the best for Exam.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;" id="internal-source-marker_0.665317248135471"&gt;Control Objectives for Information and related Technology (CobiT) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is a framework and set of best practices developed by the Information Systems Audit and Control Association&lt;/span&gt; &lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(ISACA) and the IT Governance Institute (ITGI)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;CobiT was derived from the COSO framework, developed by the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Committee of Sponsoring Organizations (COSO)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;COSO  is a model for corporate governance and CobiT is a model for IT  governance. COSO deals more at the strategic level, while CobiT focuses  more at the operational level. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;You can think of CobiT as a way to meet many of the COSO objectives, but only from the IT perspective.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;BS7799 Part 1&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;,  which outlines control objectives and a range of controls that can be  used to meet those objectives; and BS7799 Part 2, which outlines how a  security program can be set up and maintained. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;BS7799 Part 2 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;also  served as a baseline that organizations could be certified against.  Organization can decide to be accredited against for part 2 or only the  portion of part 2 same is the case with ISO17799&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;ISO9000 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Quality Control &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;ISO/IEC 27001 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Based  on British Standard BS7799 Part 2, which is establishment,  implementation, control, and improvement of the Information Security  Management System&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• ISO/IEC 27002 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Code  of practice providing good practice advice on ISMS (previously known as  ISO 17799), itself based on British Standard BS 7799 Part 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• ISO/IEC 27004 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A standard for information security management measurements&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• ISO/IEC 27005 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Designed to assist the satisfactory implementation of information security based on a risk management approach&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• ISO/IEC 27006 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A guide to the certification/registration process&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;• ISO/IEC 27799 &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A guide to illustrate how to protect personal health information&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; &lt;/span&gt;&lt;a href="http://www.27000.org/"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000099;background-color:#00ff00;font-weight:bold;font-style:normal;text-decoration:underline;vertical-align:baseline;"&gt;http://www.27000.org/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ffffff;background-color:#cc0000;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;CobiT and COSO provide the “what is to be achieved,” but not the “how to achieve&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#ffffff;background-color:#cc0000;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;it.” This is where ITIL and the ISO/IEC 27000 series come in&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#00ff00;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Annualized Loss Expectancy (ALE) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is the average monetary value of losses per year.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Annualized Loss Expectancy = Single Loss Expectancy * Annualized Rate of Occurrence&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Discretionary Access Control (DAC) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;DACs are an access control policy that restricts&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;access to files and other system resources based on the identity and assignment of&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;the user and/or the groups to which the user belongs. DACs are considered a&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;policy-based control.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Functional Requirements evaluation means&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;, “Does this solution carry out the&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;required tasks?”&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Assurance requirements evaluation means&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;, “How sure are we of the level of&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;protection this solution provides?” Assurance requirements encompass the integrity,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;availability, and confidentially aspects of the solution&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Annnualized Rate of Occurence (ARO)&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; is a value that represents the estimated&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;frequency in which a threat is expected to occur.if 100 DEO doo 1 mistake every&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;month and 12*100 = 1200 ARO&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Good Configuration Management process is one that can &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(1) accommodate change; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(2)accommodate the reuse of proven standards and best practices; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(3) ensure that all requirements remain clear, concise, and valid; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(4) ensure changes, standards, and requirements are communicated promptly and precisely; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(5) ensure that the results conform to each instance of the product.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Risk is the possibility of damage happening and the ramifications of such damage&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;should it occur.&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; Information risk management (IRM) &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;is the process of identifying&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;and assessing risk, reducing it to an acceptable level, and implementing the right&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;mechanisms to maintain that level. There is no such thing as a 100 percent secure&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;environment.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Standards &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are a "&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Mandatory &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;statement of minimum requirements that support some part&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;of a policy, the standards in this case is your own company standards and not&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;standards such as the ISO standards&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Guidelines &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are discretionary or &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;optional controls &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;used to enable individuals to make judgments with respect to security actions&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Procedures &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;step-by-step instructions &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;in  support of of the policies, standards, guidelines and baselines. The  procedure indicates how the policy will be implemented and who does what  to accomplish the tasks&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Test equipment must&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;  be secured. There are equipment and other tools that if in the wrong  hands can "sniff" a network traffic and be used to commit fraud. The  storage and use of this equipment &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;should&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; be detailed in the security policy for this reason.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;It is common for s&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;ystem development&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; and &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;systems maintenance &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;to  be undertaken by the same person. In both cases the programmer requires  access to the source code in the development environment, but should  not be allowed access in the production environment.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Other choices are not correct.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The roles of &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;security administration &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;and &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;change management &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are  incompatible functions. The level of security administration access  rights could allow changes to go undetected. Computer operations and  system development are incompatible since it would be possible for an  operator to run a program that he/she had amended. The system  development and change management task are incompatible because the  combination of system development and change control would allow program  modifications to bypass change control approvals.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The common steps used the the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;development of security policy &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;are initiation of the&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;project, evaluation, development, approval, publication, implementation, and&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;maintenance.   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The  other choices listed are the phases of  the software development life  cycle and not the step used to develop documents such as Policies,  Standards, etc...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The  data owner, not the database administrator, is responsible for accurate  use of the information and should normally provide authorization for  users to gain access to computerized information. The database  administrator (DBA) handles technical matters, not access authorization  to data.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Threat  analysis is the examination of threat sources against system  vulnerabilities to determine the threats for a particular system in a  particular operational environment.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;A risk analysis has three main goals&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;:  identify risks, quantify the impact of potential threats, and provide  an economic balance between the impact of the risk and the cost of the  associated countermeasure. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Choosing the best countermeasure is &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;not part of the risk analysis. The Operations Security domain is concerned with triples - threats, vulnerabilities and assets.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Risk Analysis Steps&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;1 Assign Vlaue to Assets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;2 Estimate Potential loss per threat (SLE)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;3 Perform a threat Analysis (ARO)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;4 Derive overall annlai Loss potential per threat (ALE)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;5 Reduce/ Transfer/ Avoid and Accept the Risk&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;SLE = Asset Value x Exposure Factor&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;ALE = SLE x ARO&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Risk Analysis = value to assets + risk analysis and assessment + Countermeasure&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;selection&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Advisory&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Advisory policies are security polices that are not mandated&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;  to be followed but are strongly suggested, perhaps with serious  consequences defined for failure to follow them (such as termination, a  job action warning, and so forth). A company with such policies wants  most employees to consider these policies mandatory.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Most policies fall under this broad category.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Advisory  policies can have many exclusions or application levels. Thus, these  policies can control some employees more than others, according to their  roles and responsibilities within that organization. For example, a  policy that&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;requires  a certain procedure for transaction processing might allow for an  alternative procedure under certain, specified conditions.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Regulatory&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Regulatory  policies are security policies that an organization must implement due  to compliance, regulation, or other legal requirements.&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;   These companies might be financial institutions, public utilities, or  some other type of organization that operates in the public interest.  These policies are usually very detailed and are specific to the  industry in which the organization perates.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Regulatory polices commonly have two main purposes:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;1. To ensure that an organization is following the standard procedures or base practices of operation in its specific industry&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;2. To give an organization the confidence that it is following the standard and accepted industry policy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Informative&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Informative policies are policies that exist simply to inform the reader. &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;There  are no implied or specified requirements, and the audience for this  information could be certain internal (within the organization) or  external parties. This does not mean that the policies are authorized  for public consumption but that they are general enough to be  distributed to external parties (vendors accessing an extranet, for  example) without a loss of confidentiality.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Computer security should be first and foremost cost-effective. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Access to facilities by is not considered as a personnel security control, but as a Physical/environmental control.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:#ffff00;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;threats × vulnerability × asset value = total risk&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(threats × vulnerability × asset value) × controls gap = residual risk&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;The Sec policy should not dictate business objectives&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Isssue Specific Policy &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(email usage policy)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;system-specific policy &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(approved SW list, Hos IDS and FW are deployed &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;**standards, guidelines, and procedures are the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;tactical &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(short term Goal) tools used to achieve and support the directives in the security policy, which is considered the &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;strategic goal&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; (long term end point Goal)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;security policy &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;says customer information should be protected &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;standard &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;says data stored in DB should be AES and If in transit should be IPSEC and &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Procedure &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;explains how to setup AES  encryption, &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;guidelines &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;cover how to handle cases when data is accidentally corrupted or compromised during transmission&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Due Diligence = Do Detect &lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;(understand risk company faces)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Due Care = Do Correct&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; (steps taken do identify the risk)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;ul&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Confidential&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Private&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Sensitive&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Public&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;and now Military &lt;/span&gt;&lt;ul&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Top Secret &lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Secret &lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Confidential &lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;sensitive but unclassified &lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;unclassified &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;commercial sector is described next:&lt;/span&gt;&lt;ul&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;For official use only Financially sensitive&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Proprietary Protects competitive edge&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Privileged Ensures conformance with business standards and laws&lt;/span&gt;&lt;/li&gt;&lt;li style="list-style-type:disc;font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Private Contains records about individuals&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Sensitive&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;  : Requires special precautions to ensure the integrity and  confidentiality of the data by protecting it from unauthorized  modification or deletion. b) Requires higher than normal assurance of  accuracy and completeness.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Examples : Financial Information , Details Of Projects , Profit Earnings and Forecasts&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Organization : Commercial Businesses&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Private&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; : a) Personal information for use within a company b) Unauthorized disclosure could adversely affect personnel or company.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Examples : Work History , Human resources information , Medical information&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Organization : Commercial Businesses&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:bold;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Secret&lt;/span&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt; : a) If disclosed , it could cause serious damage to national security.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:11pt;font-family:Arial;color:#000000;background-color:transparent;font-weight:normal;font-style:normal;text-decoration:none;vertical-align:baseline;"&gt;Examples : Deployment plans for troops , Nuclear bomb placement&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#000000;background-font-weight:bold;font-style:normal;text-decoration:underline;vertical-align:baseline;font-family:Arial;font-size:11pt;color:transparent;"   &gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5615161993419460410-2099571897568246372?l=itpeopleworld.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ZFrdB1HPPcrBG5koMoNIEN95Guw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZFrdB1HPPcrBG5koMoNIEN95Guw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ZFrdB1HPPcrBG5koMoNIEN95Guw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZFrdB1HPPcrBG5koMoNIEN95Guw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ItPeopleNewsTipsAndTricks/~4/-OS6CJJstYs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://itpeopleworld.blogspot.com/feeds/2099571897568246372/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://itpeopleworld.blogspot.com/2011/06/cissp-cbk-1-information-security-and.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/2099571897568246372?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5615161993419460410/posts/default/2099571897568246372?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ItPeopleNewsTipsAndTricks/~3/-OS6CJJstYs/cissp-cbk-1-information-security-and.html" title="CISSP CBK 1 Information Security and Risk Mgmt" /><author><name>Kash</name><email>noreply@blogger.com</email></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-JSFOUq_BEZA/TephpuZgMrI/AAAAAAAAASo/beb-jP9OBMc/s72-c/cissp.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://itpeopleworld.blogspot.com/2011/06/cissp-cbk-1-information-security-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0cMSHs-cSp7ImA9WhZWFE0.&quot;"><id>tag:blogger.com,1999:blog-5615161993419460410.post-3201340579615700531</id><published>2011-05-14T14:36:00.001-07:00</published><updated>2011-05-14T14:38:09.559-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-05-14T14:38:09.559-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IPsec" /><category scheme="http://www.blogger.com/atom/ns#" term="IKE" /><category scheme="http://www.blogger.com/atom/ns#" term="VPN IPsec" /><category scheme="http://www.blogger.com/atom/ns#" term="IKE v1 vs IKE v2" /><title>IKEv1 vs IKEv2</title><content type="html">&lt;table class="ecxMsoNormalTable" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;thead&gt;&lt;tr&gt;    &lt;td style="padding:.75pt .75pt .75pt .75pt" valign="top"&gt;    &lt;p class="ecxMsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:12.0pt;font-family:'Times New Roman','serif'"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;    &lt;/td&gt;    &lt;td style="padding:.75pt .75pt .75pt .75pt" valign="top"&gt;    &lt;p class="ecxMsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:12.0pt;font-family:'Times New Roman','serif'"&gt;IKEv1&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;  &lt;/thead&gt;  &lt;tbody&gt;&lt;tr&gt;   &lt;td style="padding:.75pt .75pt .75pt .75pt" valign="top"&
