Reference no: EM133959698
Security Engineering
The Security Engineering domain contains the concepts, principles, structures, and standards used to design, implement, monitor, and secure operating systems, equipment, networks, applications, and those controls used to enforce various levels of confidentiality, integrity, and availability. Information security architecture and design covers the practice of applying a comprehensive and rigorous method for describing a current and/or future structure and behavior for an organization's security processes, information security systems, personnel and organizational sub-units, so that these practices and processes align with the organization's core goals and strategic direction. Get AI-free online assignment help from experienced academic experts.
Cryptography examines the principles, means, and methods of applying mathematical algorithms and data transformations to information to ensure its integrity, confidentiality, and authenticity. Physical security focuses on the threats, vulnerabilities, and countermeasures that can be utilized to physically protect an enterprise's resources and sensitive information. These resources include people, the facility in which they work, and the data, equipment, support systems, media, and supplies they utilize.
Physical security describes measures that are designed to deny access to unauthorized personnel (including attackers) from physically accessing a building, facility, resource, or stored information, and guidance on how to design structures to resist potentially hostile acts. In addition to preventing unauthorized personnel from accessing information, a focus on physical security makes it possible to ensure protection for users from hazards like fire as well as providing for clearly marked safe passages out of the facility. Explaining the "what," "why," and "how" of this domain will help frame the rest of the chapter.