Chapter 6 – Security Management Models
TRUE/FALSE
1. A security blueprint is the outline of the more thorough security framework.
2. Separation of duties is the principle by which members of the organization can access the minimum
amount of information for the minimum amount of time necessary to perform their required duties.
3. Lattice-based access control specifies the level of access each subject has to each object, if any.
4. Under the Clark-Wilson model, internal consistency means that the system is consistent with similar
data in the outside world.
5. Information Technology Infrastructure Library provides guidance in the development and
implementation of an organizational InfoSec governance structure.
MULTIPLE CHOICE
1. Which of the following is a generic blueprint offered by a service organization which must be flexible,
scalable, robust, and detailed?
a.
framework
c.
organizational model
b.
security outline
d.
security model
2. Which access control principle specifies that members of the organization can access the minimum
amount of information for the minimum amount of time necessary to perform their required duties?
a.
need-toknow
c.
least privilege
b.
eyes only
d.
separation of duties
3. Which access control principle limits a user’s access to the specific information required to perform
the currently assigned task?
a.
need-toknow
c.
least privilege
b.
eyes only
d.
separation of duties
4. Controls that remedy a circumstance or mitigate damage done during an incident are categorized as
which of the following?
a.
preventative
c.
corrective
b.
deterrent
d.
compensating
5. Which of the following is NOT a category of access control?
a.
preventative
c.
deterrent
b.
remitting
d.
compensating
6. Which control category discourages an incipient incident?
a.
preventative
c.
remitting
b.
deterrent
d.
compensating
7. Which of the following is NOT one of the five levels in the U.S. military data classification scheme?
a.
confidential
c.
top secret
b.
secret
d.
private
8. Which of the following specifies the authorization classification of information asset an individual user
is permitted to access, subject to the needto-know principle?
a.
Discretionary access controls
c.
Security clearances
b.
Task-based access controls
d.
Sensitivity levels
9. Which type of access controls can be role-based or task-based?
a.
constrained
c.
nondiscretionary
b.
content-dependent
d.
discretionary
10. Under lattice-based access controls, the column of attributes associated with a particular object (such
as a printer) is referred to as which of the following?
a.
access control list
c.
access matrix
b.
capabilities table
d.
sensitivity level
11. In which form of access control is access to a specific set of information dependent on its subject
matter?
a.
content-dependent access controls
c.
temporal isolation
b.
constrained user interfaces
d.
None of these
12. A time-release safe is an example of which type of access control?
a.
content-dependent
c.
temporal isolation
b.
constrained user interface
d.
nondiscretionary
13. Which security architecture model is part of a larger series of standards collectively referred to as the
“Rainbow Series”?
a.
Bell-LaPadula
c.
ITSEC
b.
TCSEC
d.
Common Criteria
14. Which piece of the TCSEC system manages access controls?
a.
trusted computing base
c.
covert channel
b.
reference monitor
d.
verification module
15. Under the Common Criteria, which term specifies the user-generated specifications for security
requirements?
a.
Target of Evaluation (ToE)
b.
Protection Profile (PP)
c.
Security Target (ST)
d.
Security Functional Requirements (SFRs)
16. Which security architecture model is based on the premise that higher levels of integrity are more
worthy of trust than lower ones.
a.
Clark-Wilson
c.
Common Criteria
b.
Bell-LaPadula
d.
Biba
17. Which of the following is NOT a change control principle of the Clark-Wilson model?
a.
No changes by unauthorized subjects
b.
No unauthorized changes by authorized subjects
c.
No changes by authorized subjects without external validation
d.
The maintenance of internal and external consistency
18. Which of the following is the primary purpose of ISO/IEC 27001:2005?
a.
Use within an organization to formulate security requirements and objectives
b.
Implementation of business-enabling information security
c.
Use within an organization to ensure compliance with laws and regulations
d.
To enable organizations that adopt it to obtain certification
19. Which of the following provides advice about the implementation of sound controls and control
objectives for InfoSec. and was created by the Information Systems Audit and Control Association
(ISACA) and the IT Governance Institute?
a.
COBIT
c.
NIST
b.
COSO
d.
ISO
20. The COSO framework is built on five interrelated components. Which of the following is NOT one of
them?
a.
Control environment
c.
Control activities
b.
Risk assessment
d.
Internal reporting
COMPLETION
1. To design a security blueprint, an organization can use a(n) ____________________, which is a
generic blueprint offered by a service organization.
2. ISO/IEC 27001 provides implementation details using a(n) ____________________ cycle.
3. The ____________________ principle is based on the requirement that people are not allowed to view
data simply because it falls within their level of clearance.
4. ____________________ channels are unauthorized or unintended methods of communications hidden
inside a computer system, and include storage and timing channels.
5. In the COSO framework, ___________ activities include those policies and procedures that support
management directives.
MATCHING
a.
blueprint
f.
sensitivity levels
b.
DAC
g.
storage channels
c.
content-dependent access controls
h.
task-based controls
d.
rule-based access controls
i.
timing channels
e.
separation of duties
j.
TCB
1. controls where access to a specific set of information may be dependent on its content
2. One of the TCSEC’s covert channels, which transmit information by managing the relative timing of
events
3. ratings of each collection of information as well as each user
4. sets out the model to be followed in the creation of the design of security controls
5. a type of data access control in which individuals are allowed to use data, based on their job
responsibilities
6. the combination of all hardware, firmware, and software responsible for enforcing the security policy
7. requires that significant tasks be split up in such a way that more than one individual is responsible for
their completion.
8. controls implemented at the discretion or option of the data user
9. one of the TCSEC’s covert channels, which communicate by modifying a stored object
10. access is granted based on a set of rules specified by the central authority
SHORT ANSWER
1. Access controls are build on three key principles. List and briefly define them.
2. There are six access controls methodologies categorized by their inherent characteristics. List and
briefly define them.
3. Lattice-based access controls use a two-dimensional matrix to assign authorizations, what are the two
dimensions and what are they called?
4. What are the two primary access modes of the Bell-LaPadula model and what do they restrict?
5. What are the five principles that are focused on the governance and management of IT as specified by
COBIT 5?
6. What are the three categories of internal control according to COSO?
7. One approach used to categorize access control methodologies categorizes controls based on their
operational impact on the organization. What are these categories as described by NIST?
8. What are the five levels of data classification as specified by the U.S. military?
9. When copies of classified information are no longer valuable or too many copies exist, what steps
should be taken to destroy them properly? Why?
10. Under what circumstances should access controls be centralized vs. decentralized?