Secure Design Principles and Controls
Being a Certified Information Systems Security Professional (CISSP) means carrying the responsibility of architecting systems that secure environments using researched and tested standards and methods. Models that work well for one organization may not work well for another, so knowledge of security models and their selection are also important. For example, security professionals who manage a military base may decide to install barbed-wire fencing and check the identification cards of everyone who enters the base. On the other hand, security professionals who design a commercial enterprise might design a four-foot fence for the parking lot and have visitors just sign a registry to enter the workplace.
By the end of this chapter, you will be able to answer questions on the following:
- Researching, implementing, and managing engineering processes securely
- The fundamental concepts of security models
- How to select controls based...