Which of the following is used to organize authentication and authorization rules into manageable, departmentalized sections? conditions policy sets
Added by Susan F.
Step 1
These rules control access to resources by verifying user identity (authentication) and determining permissions (authorization). Show more…
Show all steps
Your feedback will help us improve your experience
Akash M and 91 other AP CS educators are ready to help you.
Ask a new question
Labs
Want to see this concept in action?
Explore this concept interactively to see how it behaves as you change inputs.
Key Concepts
Recommended Videos
You have been hired as a security consultant to develop policies that document the minimum security requirements for Regional Bank covering its financial system and customer-facing online web service. Part 1: Regional Bank Financial Software System (RBFSS) Regional Bank has an accounting system that tracks its revenue, accounts receivable, accounts payable, and employee payroll. Write a 2- to 3-page security policy for RBFSS in which you describe: - Access control-based user roles for each component (accounts receivable, accounts payable, employee payroll) - Password requirements and protection - Password-protected screen savers - Data encryption at rest Annotate each security control with at least one Critical Security Control (CSC) from the Center for Internet Security (CIS).
Akash M.
__________ would specify that only selected members of the payroll and human resources department would have the right to change sensitive employee data, such as an employee’s salary and social security number, and that these departments are responsible for making sure that such employee data are accurate.
Mauya M.
You have been tasked with implementing an access control solution based upon users' roles. Write a 2-4 page paper on how you would go about doing this assuming that the cloud environment is either Microsoft Azure or Amazon Web Services (AWS) (pick only one). Scenario: An insurance company has a claims application used to capture data about their policyholders and any property damage they suffer. A hurricane is projected to strike the Gulf Coast region of the US, likely causing massive property damage. This will create a huge spike in claims which will in turn create an enormous load on the corporate IT infrastructure. The company's decision is to use a public cloud provider to deliver virtual machines to handle the expected demand. The company must control access between the enterprise system and the virtual machines hosted by the cloud provider, limiting access to only authorized agents of the company. The company must securely transmit any data created by cloud-based instances of the application back inside the corporate firewall. The cloud provider must ensure that no traces of the application or its data remain whenever a virtual machine is shut down. The insurance company is based in the U.S. and only has domestic offices (there are no operations outside of the U.S.). The company is using Microsoft Active Directory (AD) for authentication, with workstations running Windows 10. The claims systems are running Oracle Database 19c on Linux.
Supreeta N.
Recommended Textbooks
Computer Science and Information Technology
Introduction to Programming Using Python
Computer Science - An Overview
Transcript
Watch the video solution with this free unlock.
EMAIL
PASSWORD