Episode 31 — A.5.17–5.18 — Authentication information; Access rights

Episode 31 — A.5.17–5.18 — Authentication information; Access rights

A.5.17 requires organizations to protect authentication information throughout its lifecycle, emphasizing creation, issuance, use, storage, and revocation. For exam purposes, distinguish between authentication factors (something you know, have, are) and the artifacts that embody them, such as passwords, tokens, private keys, and biometric templates. The control stresses proper strength, secrecy, and integrity: strong password policies, salted hashing, hardware-backed keys, secure enrollment, and secure recovery procedures that do not expose secrets. It also addresses risks like credential stuffing, phishing, SIM swap, and replay by advocating multi-factor authentication, rate limiting, secure channels, and anti-phishing mechanisms. Candidates should be able to explain how governance sets minimum assurance levels based on data classification and how exceptions require documented risk acceptance and compensating controls to preserve confidentiality and integrity expectations.

A.5.18 governs access rights, ensuring that entitlements are granted, changed, and revoked according to policy and role requirements. This control operationalizes least privilege and segregation of duties, requiring explicit approval, timely provisioning, periodic recertification, and immediate deprovisioning at termination or role change. In practice, identity governance integrates HR events with joiner–mover–leaver workflows, automates birthright access, and uses role or attribute-based models to prevent permission sprawl. Auditors will sample user accounts, service principals, and API keys to verify ownership, justification, and last-use evidence. Common pitfalls include shared accounts, unmanaged machine identities, and standing privileged access without session control. Effective programs employ privileged access management, just-in-time elevation, break-glass procedures with post-use review, and anomaly detection tied to SIEM. Candidates should link these controls to tangible artifacts: password vault configurations, WebAuthn enrollment records, RBAC catalogs, recertification attestations, and deprovisioning SLAs that demonstrate a secure, auditable end-to-end identity lifecycle. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(71)

Welcome to Framework - ISO 27001

Welcome to Framework - ISO 27001

Dive into a fast, no-fluff overview of what this podcast delivers, who it’s for, and how each episode helps you level up with practical, real-world takeaways. In this trailer, you’ll hear the show’s p...

14 Okt 20251min

Episode 70 — A.8.33–8.34 — Test information; Protecting systems during audit testing

Episode 70 — A.8.33–8.34 — Test information; Protecting systems during audit testing

A.8.33 governs test information—data and artifacts used to verify functionality and security—so that confidentiality, integrity, and legality are preserved. For the exam, distinguish data sources and ...

14 Okt 202513min

Episode 69 — A.8.31–8.32 — Separation of dev/test/prod; Change management

Episode 69 — A.8.31–8.32 — Separation of dev/test/prod; Change management

A.8.31 enforces separation between development, test, and production to prevent inadvertent changes, data leakage, and unauthorized access. For the exam, stress environment isolation, distinct identit...

14 Okt 202511min

Episode 68 — A.8.29–8.30 — Security testing in development & acceptance; Outsourced development

Episode 68 — A.8.29–8.30 — Security testing in development & acceptance; Outsourced development

A.8.29 requires structured security testing throughout development and acceptance, proving that controls operate as intended before release. For the exam, differentiate testing modalities and purposes...

14 Okt 202513min

Episode 67 — A.8.27–8.28 — Secure system architecture & engineering; Secure coding

Episode 67 — A.8.27–8.28 — Secure system architecture & engineering; Secure coding

A.8.27 focuses on secure system architecture and engineering, requiring designs that partition trust, minimize attack surface, and enforce least privilege at every layer. For the exam, emphasize archi...

14 Okt 202514min

Episode 66 — A.8.25–8.26 — Secure development lifecycle; Application security requirements

Episode 66 — A.8.25–8.26 — Secure development lifecycle; Application security requirements

A.8.25 requires a secure development lifecycle (SDLC) that embeds security from concept to retirement, not as a late-stage gate. For the exam, describe SDLC phases with explicit security tasks: threat...

14 Okt 202514min

Episode 65 — A.8.23–8.24 — Web filtering; Use of cryptography

Episode 65 — A.8.23–8.24 — Web filtering; Use of cryptography

A.8.23 establishes web filtering to manage risk from browsing and outbound HTTP/S traffic, acknowledging that the browser is a primary threat vector. For the exam, emphasize policy-aligned controls th...

14 Okt 202515min

Episode 64 — A.8.21–8.22 — Security of network services; Segregation of networks

Episode 64 — A.8.21–8.22 — Security of network services; Segregation of networks

A.8.21 requires that network services—whether internal or provided by third parties—be specified and secured to meet business and security requirements. For the exam, think beyond raw connectivity: se...

14 Okt 202513min

Populärt inom Utbildning

historiepodden-se
rss-bara-en-till-om-missbruk-medberoende-2
det-skaver
nu-blir-det-historia
harrisons-dramatiska-historia
sektledare
rss-viktmedicinpodden
not-fanny-anymore
roda-vita-rosen
allt-du-velat-veta
johannes-hansen-podcast
rikatillsammans-om-privatekonomi-rikedom-i-livet
sa-in-i-sjalen
rss-ar-det-rimligt
rss-basta-livet
rss-max-tant-med-max-villman
i-vantan-pa-katastrofen
sex-pa-riktigt-med-marika-smith
rss-traningsklubben
rss-mina-andetag