II. Implementing Trustworthy Computing
1. Trustworthy computing is a method of computing that delivers secure, private, and
reliable computing experiences based on sound business practices—which is what
organizations worldwide are demanding today. Use Figure 3-4 and Table 3–76 to aid the
discussion.
2. Note that the security of any system or network is a combination of technology, policy, and
Teaching
Tip
Explain why longer passwords that use numbers and special characters are more
secure, noting that if a password is 2 characters long, and the number of
possible characters is 26, then there are 262 possible different combinations a
hacker would have to try, but if the password is 12 characters long, then the
hacker would have to test 2612 different possibilities. If a password uses
numbers as well as letters, then the hacker has to try 3612 different combinations.
A. Risk Assessment
1. Risk assessment is the process of assessing security-related risks to an organization’s
computers and networks from both internal and external threats. Such threats can
B. Establishing a Security Policy
1. A security policy defines an organization’s security requirements, as well as the controls
and sanctions needed to meet those requirements. Explain that a good security policy
delineates responsibilities and the behavior expected of members of the organization.
2. Point out that the SANS (SysAdmin, Audit, Network, Security) Institute’s Web site offers
a number of security-related policy templates that can help an organization to quickly
develop effective security policies.