2.1.E.2Risk avoidance stops the activity that is generating the risk. If the activity is a critical part of an organization’s mission or purpose, then avoidance is not possible.Learning objective: Identify strategies for managing risk.
5.2.C.7The principle of least privilege is the idea that entities should be given exactly as much access as they need to perform their function and no more.Learning objective: Determine an appropriate access control model to protect applications and data.
AP Networking alignment
4.1.A.4When integrity is compromised, systems may contain false or inaccurate data. A breach of integrity can be identified by: • unauthorized data changes • inconsistencies in logs • unauthorized software installations • corruption…Learning objective: Identify evidence of compromised confidentiality, integrity, or availability.
4.5.B.2Security policies and procedures help reduce user-related vulnerabilities by defining acceptable behaviors and standardizing how systems and data are used. These controls can reduce misconfiguration, mishandling, or improper…Learning objective: Determine appropriate security controls to limit the impacts of common threats and vulnerabilities in a managed network.