Asset Security

Identification and Classification

  • Inventory: You must identify and list all assets (hardware, software, data) to protect them.

  • Valuation: Assets are valued to determine the appropriate level of security. This can be quantitative (e.g., monetary cost) or qualitative (e.g., labels like High/Medium/Low).

  • Classification: Data is grouped by sensitivity (e.g., Confidential, Public) to enforce access controls.

  • Categorisation: Determines the impact if data is lost or damaged (Confidentiality, Integrity, Availability).

2. Roles and Responsibilities

  • Data Owner: Has ultimate accountability for the data. They decide the classification and who gets access.

  • Data Custodian: Responsible for the technical protection of data (e.g., performing backups, patching systems).

  • Data Controller: Determines why and how personal data is processed.

  • Data Processor: Processes data on behalf of the controller (e.g., a cloud provider).

3. Asset Lifecycle Data must be protected during all phases:

  1. Create: Classify data immediately upon creation.

  2. Store: Protect data at rest using encryption and access controls.

  3. Use: Data is most vulnerable here because it must be unencrypted to be processed.

  4. Share: Use encryption (like TLS) to protect data in transit between users or systems.

  5. Archive: Long-term storage governed by retention policies.

  6. Destroy: Securely removing data when no longer needed.

4. Data States

  • Data at Rest: Data stored on media (hard drives, tapes) and protected by encryption and physical security.

  • Data in Transit (Motion): Data moving across a network. Protected by link encryption or end-to-end encryption.

  • Data in Use: Data currently in memory or being processed. It is generally unencrypted and vulnerable.

5. Privacy and Retention

  • Privacy: Organisations must protect Personally Identifiable Information (PII). The OECD guidelines provide principles for handling personal data, such as limiting collection and specifying the purpose.

  • Retention: Data should be kept only as long as required by laws or business needs.

6. Data Destruction

  • Data Remanence: Data left behind after an attempt to delete it.

  • Clearing: Removing data so standard user tools cannot recover it.

  • Purging: Removing data so it cannot be recovered by laboratory techniques (e.g., degaussing agents).

  • Destruction: Physically destroying the media (shredding, melting).

  • SSD Sanitisation: Standard overwriting is ineffective on Solid State Drives (SSDs). Cryptographic erasure (destroying the encryption keys) is the preferred method.

7. Security Baselines

  • Baselines: Minimum security standards applied to all systems.

  • Scoping: Removing baseline controls that do not apply to a specific system.

  • Tailoring: Modifying baseline controls to fit the specific organization's needs.

Principles of Information Security Management

Buy nowLearn more
  • Course Description:

1. Security and Risk Management (1 - 2h)

  • A Strategic Governance and Risk Architecture
  • Cybersecurity Architecture: Fundamentals of Confidentiality, Integrity, and Availability (12 min)
  • Risky Business: Strengthening Cybersecurity with Risk Analysis (12 min)
  • Controls Categories (12 min)
  • Zero Trust (7 min)
  • Cyber Risk Management: Essentials for the Practical CISO (1 hr)

2. Asset Security (0.5 - 1h)

  • Asset Security
  • Data Security: Protect your critical data (or else) (6 min)
  • SSD Data destruction (10 min reading)
  • Google Data Center Security: 6 Layers Deep (2 min)
  • Data Governance (10 min)

3. Security Architecture and Engineering (3 - 4 hrs)

  • Security Architecture and Engineering
  • Cryptography: Crash Course Computer Science (12 min)
  • The Adventure of Alice and the Encrypted Message (14 min)
  • Steganography (3 min)
  • Virtualization Explained (5 min)
  • Cybersecurity Architecture: Who Are You? Identity and Access Management (30 min)
  • Cloud security guidance (30 min - reading)
  • Full SANS Webcast | Decoding the Shared Responsibility Model (49 min)
  • Buffer Overflows (3 min)
  • Stack vs Heap Memory - Simple Explanation ( 5 min)
  • What are hardware security modules (HSM), why we need them and how they work. (7 min)
  • How Access Control Systems Work | Point Monitor Corporation (6 min)

4 - Communication and Network Security (2 - 3 hrs)

  • Network Security basics
  • Understanding the OSI Model (12 min)
  • Cybersecurity Architecture: Networks (27 min)
  • Internet Networks & Network Security | Google Cybersecurity Certificate (1 hr)
  • How does HTTPS work? What's a CA? What's a self-signed Certificate? (11 min)
  • Kerberos (3 min)

5 - Identity and Access Management (1- 2hr)

  • Identity and Access Management (12 min)
  • Cybersecurity Architecture: Who Are You? Identity and Access Management (31 min)
  • OAuth terminologies and flows explained (24 min)

6. Security Assessment and Testing

  • Key Terminology
  • Building a Cybersecurity Framework (8 min)
  • NIST Cybersecurity Framework 2.0 (5 min)
  • SOC 1 vs SOC 2 Audits: What’s the Difference? (5 min)
  • CertMike Explains SOC Audits (8 min)

7 - Security Operations

  • The Incident Scene & Evidence Collection
  • Malware (21 min)
  • Attack Frameworks (8 min)
  • How Hackers Steal Passwords: 5 Attack Methods Explained (13 min)
  • Examples: Data resilience, RAID and storage

8- Software Development Security

  • Software Development Security
  • Cybersecurity Architecture: Application Security (16 min)
  • Container Security Explained (6 min)
  • Threat Modeling in the Age of AI - Susanna Cox (45 min)