Introduction |
|
xxvii | |
|
Part I Attacks, Threats, and Vulnerabilities |
|
|
1 | (120) |
|
Chapter 1 Social Engineering Techniques |
|
|
3 | (12) |
|
|
4 | (2) |
|
|
5 | (1) |
|
|
5 | (1) |
|
|
6 | (1) |
|
Phishing and Related Attacks |
|
|
6 | (4) |
|
|
9 | (1) |
|
|
9 | (1) |
|
Hoaxes and Influence Campaigns |
|
|
10 | (1) |
|
Principles of Influence (Reasons for Effectiveness) |
|
|
10 | (4) |
|
|
14 | (1) |
|
|
15 | (20) |
|
|
16 | (10) |
|
|
17 | (2) |
|
|
19 | (1) |
|
|
19 | (1) |
|
|
20 | (2) |
|
|
22 | (1) |
|
|
22 | (1) |
|
|
23 | (2) |
|
Potentially Unwanted Programs (PUPs) |
|
|
25 | (1) |
|
|
25 | (1) |
|
|
25 | (1) |
|
|
26 | (1) |
|
|
26 | (1) |
|
Adversarial Artificial Intelligence (AI) |
|
|
27 | (1) |
|
|
28 | (3) |
|
|
30 | (1) |
|
|
31 | (3) |
|
|
34 | (1) |
|
Chapter 3 Application Attacks |
|
|
35 | (18) |
|
|
36 | (1) |
|
Improper Software Handling |
|
|
37 | (1) |
|
|
37 | (1) |
|
|
38 | (1) |
|
|
39 | (1) |
|
|
40 | (1) |
|
|
41 | (3) |
|
|
44 | (1) |
|
|
45 | (1) |
|
Secure Sockets Layer (SSL) Stripping |
|
|
45 | (2) |
|
Application Programming Interface (API) Attacks |
|
|
47 | (2) |
|
|
49 | (3) |
|
|
52 | (1) |
|
Chapter 4 Network Attacks |
|
|
53 | (20) |
|
|
54 | (4) |
|
Short-Range Wireless Communications |
|
|
56 | (1) |
|
|
56 | (1) |
|
|
57 | (1) |
|
|
57 | (1) |
|
|
58 | (1) |
|
|
59 | (3) |
|
|
60 | (1) |
|
|
60 | (1) |
|
|
61 | (1) |
|
|
61 | (1) |
|
Domain Name System (DNS) Attacks |
|
|
62 | (2) |
|
|
62 | (1) |
|
Universal Resource Locator (URL) Redirection |
|
|
62 | (1) |
|
|
63 | (1) |
|
|
64 | (4) |
|
|
66 | (2) |
|
Malicious Code and Script Execution |
|
|
68 | (3) |
|
|
71 | (2) |
|
Chapter 5 Threat Actors, Vectors, and Intelligence Sources |
|
|
73 | (16) |
|
|
74 | (1) |
|
|
75 | (5) |
|
|
76 | (1) |
|
|
77 | (1) |
|
|
78 | (1) |
|
|
78 | (1) |
|
|
78 | (1) |
|
|
79 | (1) |
|
|
80 | (1) |
|
Threat Intelligence and Research Sources |
|
|
81 | (6) |
|
|
81 | (1) |
|
|
82 | (5) |
|
|
87 | (2) |
|
Chapter 6 Vulnerabilities |
|
|
89 | (10) |
|
Cloud-Based vs. On-Premises |
|
|
90 | (1) |
|
|
90 | (1) |
|
|
91 | (4) |
|
Improper or Weak Patch Management |
|
|
94 | (1) |
|
|
95 | (1) |
|
|
96 | (2) |
|
|
98 | (1) |
|
Chapter 7 Security Assessment Techniques |
|
|
99 | (12) |
|
|
100 | (3) |
|
Intrusive vs. Non-Intrusive |
|
|
102 | (1) |
|
Credentialed vs. Non-Credentialed |
|
|
103 | (1) |
|
|
103 | (7) |
|
Security Information and Event Management (SIEM) |
|
|
104 | (3) |
|
|
107 | (1) |
|
Security Orchestration, Automation, and Response (SOAR) |
|
|
108 | (2) |
|
|
110 | (1) |
|
Chapter 8 Penetration Testing Techniques |
|
|
111 | (10) |
|
|
112 | (6) |
|
|
115 | (1) |
|
|
115 | (2) |
|
|
117 | (1) |
|
|
118 | (1) |
|
|
118 | (2) |
|
|
120 | (1) |
|
Part II Architecture and Design |
|
|
121 | (158) |
|
Chapter 9 Enterprise Security Concepts |
|
|
123 | (22) |
|
|
124 | (2) |
|
|
126 | (13) |
|
|
127 | (1) |
|
Cloud Access Security Brokers |
|
|
128 | (1) |
|
Encryption and Data Obfuscation |
|
|
129 | (3) |
|
|
132 | (1) |
|
Hardware Security Module (HSM) |
|
|
133 | (1) |
|
Encrypted Traffic Management |
|
|
134 | (1) |
|
|
135 | (1) |
|
|
136 | (1) |
|
|
137 | (1) |
|
Geographic Considerations |
|
|
138 | (1) |
|
|
139 | (4) |
|
|
143 | (2) |
|
Chapter 10 Virtualization and Cloud Computing |
|
|
145 | (20) |
|
|
145 | (3) |
|
|
146 | (1) |
|
|
146 | (1) |
|
|
147 | (1) |
|
Type I vs. Type II Hypervisors |
|
|
147 | (1) |
|
Containers and Microservices |
|
|
148 | (2) |
|
Virtual Desktop Infrastructure (VDI) |
|
|
150 | (1) |
|
Virtual Machine (VM) Sprawl Avoidance |
|
|
151 | (1) |
|
|
151 | (3) |
|
Software-Defined Networking (SDN) |
|
|
152 | (1) |
|
Infrastructure as Code (IaC) |
|
|
153 | (1) |
|
On-Premises vs. Off-Premises |
|
|
154 | (1) |
|
|
155 | (9) |
|
|
156 | (2) |
|
|
158 | (1) |
|
|
159 | (1) |
|
|
159 | (2) |
|
|
161 | (1) |
|
|
161 | (1) |
|
|
161 | (1) |
|
|
162 | (1) |
|
|
162 | (2) |
|
|
164 | (1) |
|
Chapter 11 Secure Application Development, Deployment, and Automation |
|
|
165 | (24) |
|
|
166 | (2) |
|
|
166 | (1) |
|
|
167 | (1) |
|
Provisioning and Deprovisioning |
|
|
168 | (1) |
|
|
168 | (1) |
|
Change Management and Version Control |
|
|
169 | (1) |
|
|
170 | (10) |
|
|
172 | (1) |
|
|
173 | (1) |
|
Encryption, Obfuscation, and Camouflage |
|
|
173 | (1) |
|
|
174 | (1) |
|
Use of Third-Party Libraries and SDKs |
|
|
175 | (1) |
|
Server-Side vs. Client-Side Execution and Validation |
|
|
175 | (1) |
|
|
176 | (1) |
|
|
176 | (1) |
|
|
177 | (1) |
|
|
178 | (1) |
|
|
179 | (1) |
|
|
180 | (4) |
|
|
181 | (3) |
|
Scalability and Elasticity |
|
|
184 | (3) |
|
|
187 | (2) |
|
Chapter 12 Authentication and Authorization Design |
|
|
189 | (16) |
|
Identification and Authentication, Authorization, and Accounting (AAA) |
|
|
189 | (1) |
|
Multifactor Authentication |
|
|
190 | (2) |
|
|
192 | (3) |
|
|
193 | (1) |
|
|
194 | (1) |
|
Authentication Technologies |
|
|
195 | (9) |
|
|
195 | (3) |
|
|
198 | (2) |
|
|
200 | (1) |
|
Certificate-Based Authentication |
|
|
201 | (3) |
|
|
204 | (1) |
|
Chapter 13 Cybersecurity Resilience |
|
|
205 | (20) |
|
|
205 | (9) |
|
|
208 | (1) |
|
|
209 | (2) |
|
|
211 | (1) |
|
|
211 | (3) |
|
|
214 | (7) |
|
|
217 | (1) |
|
|
217 | (1) |
|
|
218 | (1) |
|
|
218 | (1) |
|
|
219 | (1) |
|
Revert to Known State or Good Configuration |
|
|
220 | (1) |
|
|
221 | (1) |
|
|
221 | (3) |
|
|
224 | (1) |
|
Chapter 14 Embedded and Specialized Systems |
|
|
225 | (14) |
|
|
225 | (2) |
|
|
226 | (1) |
|
|
227 | (2) |
|
|
229 | (9) |
|
Heating, Ventilation, Air Conditioning (HVAC) |
|
|
231 | (1) |
|
|
232 | (1) |
|
|
233 | (1) |
|
|
233 | (1) |
|
|
233 | (1) |
|
|
234 | (1) |
|
|
235 | (1) |
|
|
236 | (2) |
|
|
238 | (1) |
|
Chapter 15 Physical Security Controls |
|
|
239 | (22) |
|
|
239 | (4) |
|
Signs, Fencing, and Gates |
|
|
240 | (1) |
|
|
241 | (1) |
|
|
241 | (1) |
|
|
242 | (1) |
|
|
242 | (1) |
|
|
243 | (3) |
|
|
244 | (1) |
|
Motion and Infrared Detection |
|
|
244 | (1) |
|
Access Control Vestibules |
|
|
245 | (1) |
|
|
245 | (1) |
|
|
246 | (3) |
|
|
246 | (1) |
|
|
246 | (1) |
|
Locking Cabinets and Enclosures |
|
|
247 | (1) |
|
|
248 | (1) |
|
|
248 | (1) |
|
|
249 | (6) |
|
Protected Cabling, Protected Distribution, and Faraday Cages |
|
|
249 | (2) |
|
|
251 | (1) |
|
|
252 | (2) |
|
|
254 | (1) |
|
|
255 | (4) |
|
|
259 | (2) |
|
Chapter 16 Cryptographic Concepts |
|
|
261 | (18) |
|
|
262 | (10) |
|
|
262 | (1) |
|
|
263 | (1) |
|
|
264 | (2) |
|
|
266 | (2) |
|
Elliptic Curve and Emerging Cryptography |
|
|
268 | (1) |
|
|
268 | (1) |
|
Nonrepudiation and Digital Signatures |
|
|
269 | (2) |
|
|
271 | (1) |
|
Use of Proven Technologies and Implementation |
|
|
272 | (1) |
|
|
273 | (1) |
|
|
274 | (2) |
|
|
276 | (1) |
|
|
277 | (2) |
|
|
279 | (212) |
|
Chapter 17 Secure Protocols |
|
|
281 | (26) |
|
|
282 | (4) |
|
Internet Protocol Security (IPsec) |
|
|
284 | (2) |
|
Secure File Transfer Protocols |
|
|
286 | (1) |
|
|
287 | (1) |
|
Secure Internet Protocols |
|
|
288 | (5) |
|
Lightweight Directory Access Protocol (LDAP) |
|
|
289 | (1) |
|
Secure Real-Time Transport Protocol (SRTP) |
|
|
290 | (1) |
|
Simple Network Management Protocol (SNMP) |
|
|
290 | (3) |
|
Secure Protocol Use Cases |
|
|
293 | (12) |
|
|
293 | (1) |
|
Using HTTPS for Web Communications |
|
|
293 | (1) |
|
Using SSL/TLS for Remote Access |
|
|
294 | (1) |
|
Using DNSSEC for Domain Name Resolution |
|
|
294 | (1) |
|
Secure File Transfer Communication |
|
|
295 | (1) |
|
Using FTPS and SFTP for File Transfer |
|
|
295 | (1) |
|
Secure Email Communications |
|
|
296 | (1) |
|
Using S/MIME, POP3S, and IMAPS for Email |
|
|
296 | (1) |
|
Securing Internal Communications |
|
|
297 | (1) |
|
Using SRTP for Voice and Video |
|
|
297 | (1) |
|
Using LDAPS for Directory Services |
|
|
298 | (1) |
|
Using SNMPv3 with Routing and Switching |
|
|
298 | (1) |
|
Using Network Address Allocation |
|
|
299 | (3) |
|
Using Time Synchronization |
|
|
302 | (1) |
|
Using Subscription Services |
|
|
303 | (2) |
|
|
305 | (2) |
|
Chapter 18 Host and Application Security Solutions |
|
|
307 | (32) |
|
|
308 | (10) |
|
Firewalls and HIPS/HIDS Solutions |
|
|
308 | (2) |
|
Anti-Malware and Other Host Protections |
|
|
310 | (4) |
|
Endpoint Detection and Response (EDR) |
|
|
314 | (1) |
|
Data Execution Prevention (DEP) |
|
|
314 | (1) |
|
Data Loss Prevention (DLP) |
|
|
315 | (1) |
|
|
316 | (1) |
|
Application Allow/Block Lists |
|
|
317 | (1) |
|
|
317 | (1) |
|
|
318 | (4) |
|
|
319 | (1) |
|
|
319 | (1) |
|
|
319 | (2) |
|
|
321 | (1) |
|
|
321 | (1) |
|
Hardware and Firmware Security |
|
|
322 | (8) |
|
|
322 | (2) |
|
|
324 | (2) |
|
|
326 | (2) |
|
|
328 | (1) |
|
|
329 | (1) |
|
Operating System Security |
|
|
330 | (8) |
|
|
331 | (1) |
|
Disabling Unnecessary Ports and Services |
|
|
332 | (3) |
|
|
335 | (1) |
|
|
335 | (1) |
|
|
336 | (2) |
|
|
338 | (1) |
|
Chapter 19 Secure Network Design |
|
|
339 | (32) |
|
Network Devices and Segmentation |
|
|
340 | (1) |
|
|
340 | (2) |
|
Network Address Translation (NAT) |
|
|
341 | (1) |
|
|
342 | (5) |
|
|
343 | (1) |
|
Virtual Local Area Network (VLAN) |
|
|
344 | (1) |
|
|
345 | (2) |
|
Security Devices and Boundaries |
|
|
347 | (22) |
|
|
350 | (3) |
|
Web Application Firewalls |
|
|
353 | (1) |
|
|
354 | (3) |
|
Unified Threat Management (UTM) |
|
|
357 | (1) |
|
|
358 | (2) |
|
|
360 | (2) |
|
|
362 | (2) |
|
|
364 | (1) |
|
Network Access Control (NAC) |
|
|
365 | (4) |
|
|
369 | (2) |
|
Chapter 20 Wireless Security Settings |
|
|
371 | (18) |
|
|
372 | (1) |
|
Wireless Cryptographic Protocols |
|
|
373 | (4) |
|
Wired Equivalent Privacy (WEP) |
|
|
374 | (1) |
|
Wi-Fi Protected Access (WPA) |
|
|
375 | (1) |
|
Temporal Key Integrity Protocol |
|
|
376 | (1) |
|
Counter Mode with Cipher Block Chaining Message Authentication Code Protocol |
|
|
376 | (1) |
|
Wi-Fi Protected Access Version 2 (WPA2) |
|
|
376 | (1) |
|
Wi-Fi Protected Access Version 3 (WPA3) |
|
|
377 | (1) |
|
|
377 | (2) |
|
Wireless Access Installations |
|
|
379 | (8) |
|
Antenna Types, Placement, and Power |
|
|
380 | (3) |
|
|
383 | (1) |
|
|
384 | (3) |
|
|
387 | (2) |
|
Chapter 21 Secure Mobile Solutions |
|
|
389 | (32) |
|
|
389 | (4) |
|
Mobile Device Management Concepts |
|
|
393 | (12) |
|
Device, Application, and Content Management |
|
|
393 | (1) |
|
|
394 | (1) |
|
Mobile Content Management |
|
|
394 | (1) |
|
Mobile Application Management |
|
|
395 | (3) |
|
|
398 | (1) |
|
Screen Locks, Passwords, and PINs |
|
|
398 | (1) |
|
Biometrics and Con text-Aware Authentication |
|
|
398 | (1) |
|
|
399 | (1) |
|
Geolocation, Geofencing, and Push Notifications |
|
|
400 | (2) |
|
Storage Segmentation and Containerization |
|
|
402 | (1) |
|
Full Device Encryption (FDE) |
|
|
403 | (2) |
|
Enforcement and Monitoring |
|
|
405 | (7) |
|
|
405 | (1) |
|
Custom Firmware, Carrier Unlocking, and OTA Updates |
|
|
406 | (1) |
|
Third-Party App Stores and Sideloading |
|
|
407 | (1) |
|
|
408 | (1) |
|
Enforcement for Normal Device Functions |
|
|
409 | (1) |
|
Wi-Fi Methods, Tethering, and Payments |
|
|
410 | (2) |
|
|
412 | (8) |
|
BYOD, CYOD, COPE, and Corporate-Owned Devices |
|
|
412 | (1) |
|
Virtual Desktop Infrastructure |
|
|
413 | (1) |
|
|
414 | (1) |
|
Architecture/Infrastructure Considerations |
|
|
414 | (1) |
|
Adherence to Corporate Policies and Acceptable Use |
|
|
415 | (1) |
|
|
416 | (1) |
|
|
416 | (1) |
|
Data Ownership and Support |
|
|
417 | (1) |
|
Patch and Antivirus Management |
|
|
417 | (1) |
|
|
418 | (2) |
|
|
420 | (1) |
|
Chapter 22 Cloud Cybersecurity Solutions |
|
|
421 | (12) |
|
|
422 | (6) |
|
Regions and Availability Zones |
|
|
423 | (1) |
|
Virtual Private Cloud (VPC) |
|
|
423 | (1) |
|
|
423 | (1) |
|
|
424 | (2) |
|
|
426 | (1) |
|
|
427 | (1) |
|
Third-Party Cloud Security Solutions |
|
|
428 | (3) |
|
|
431 | (2) |
|
Chapter 23 Identity and Account Management Controls |
|
|
433 | (16) |
|
|
433 | (2) |
|
|
435 | (6) |
|
Onboarding and Offboarding |
|
|
435 | (1) |
|
|
436 | (1) |
|
Access Auditing and Reviews |
|
|
436 | (2) |
|
Time of Day and Location Restrictions |
|
|
438 | (1) |
|
|
439 | (2) |
|
Account Policy Enforcement |
|
|
441 | (7) |
|
|
442 | (1) |
|
|
442 | (1) |
|
|
443 | (1) |
|
|
443 | (1) |
|
|
444 | (1) |
|
Password Length and Rotation |
|
|
445 | (3) |
|
|
448 | (1) |
|
Chapter 24 Authentication and Authorization Solutions |
|
|
449 | (24) |
|
|
450 | (16) |
|
Unencrypted Plaintext Credentials |
|
|
451 | (1) |
|
|
452 | (4) |
|
|
456 | (1) |
|
|
457 | (1) |
|
|
457 | (2) |
|
|
459 | (1) |
|
AAA Protocols and Services |
|
|
459 | (2) |
|
|
461 | (3) |
|
|
464 | (2) |
|
|
466 | (6) |
|
Privileged Access Management |
|
|
469 | (3) |
|
|
472 | (1) |
|
Chapter 25 Public Key Infrastructure |
|
|
473 | (18) |
|
|
474 | (15) |
|
Certificate Authority (CA) |
|
|
475 | (1) |
|
Certification Practice Statement |
|
|
476 | (1) |
|
|
476 | (1) |
|
|
477 | (1) |
|
|
478 | (2) |
|
Public and Private Key Usage |
|
|
480 | (1) |
|
Certificate Signing Request |
|
|
481 | (1) |
|
|
482 | (1) |
|
|
482 | (2) |
|
|
484 | (2) |
|
|
486 | (1) |
|
|
487 | (1) |
|
|
488 | (1) |
|
|
489 | (2) |
|
Part IV Operations and Incident Response |
|
|
491 | (76) |
|
Chapter 26 Organizational Security |
|
|
493 | (16) |
|
Shell and Script Environments |
|
|
494 | (2) |
|
Network Reconnaissance and Discovery |
|
|
496 | (6) |
|
|
502 | (1) |
|
Packet Capture and Replay |
|
|
502 | (2) |
|
|
504 | (1) |
|
Forensics and Data Sanitization |
|
|
505 | (3) |
|
|
508 | (1) |
|
Chapter 27 Incident Response |
|
|
509 | (20) |
|
|
509 | (3) |
|
|
510 | (1) |
|
|
510 | (1) |
|
Diamond Model of Intrusion Analysis |
|
|
511 | (1) |
|
|
512 | (5) |
|
Documented Incident Type/Category Definitions |
|
|
513 | (1) |
|
Roles and Responsibilities |
|
|
513 | (1) |
|
Reporting Requirements and Escalation |
|
|
514 | (1) |
|
Cyber-Incident Response Teams |
|
|
515 | (1) |
|
Training, Tests, and Exercises |
|
|
516 | (1) |
|
Incident Response Process |
|
|
517 | (5) |
|
|
517 | (1) |
|
Incident Identification and Analysis |
|
|
518 | (1) |
|
Containment, Eradication, and Recovery |
|
|
519 | (2) |
|
|
521 | (1) |
|
Continuity and Recovery Plans |
|
|
522 | (6) |
|
|
522 | (2) |
|
Continuity of Operations Planning |
|
|
524 | (4) |
|
|
528 | (1) |
|
Chapter 28 Incident Investigation |
|
|
529 | (12) |
|
|
530 | (1) |
|
|
531 | (5) |
|
|
536 | (3) |
|
|
537 | (1) |
|
|
538 | (1) |
|
|
539 | (2) |
|
Chapter 29 Incident Mitigation |
|
|
541 | (10) |
|
Containment and Eradication |
|
|
541 | (8) |
|
|
542 | (1) |
|
|
543 | (1) |
|
|
544 | (1) |
|
|
545 | (1) |
|
Secure Orchestration, Automation, and Response (SOAR) |
|
|
546 | (3) |
|
|
549 | (2) |
|
Chapter 30 Digital Forensics |
|
|
551 | (16) |
|
Data Breach Notifications |
|
|
552 | (2) |
|
Strategic Intelligence/Counterintelligence Gathering |
|
|
554 | (1) |
|
|
555 | (1) |
|
|
555 | (1) |
|
|
556 | (3) |
|
|
559 | (6) |
|
|
560 | (1) |
|
Capture Network Traffic and Logs |
|
|
560 | (1) |
|
Capture Video and Photographs |
|
|
561 | (1) |
|
|
562 | (1) |
|
|
562 | (1) |
|
|
563 | (1) |
|
Collect Witness Interviews |
|
|
563 | (2) |
|
|
565 | (2) |
|
Part V Governance, Risk, and Compliance |
|
|
567 | (58) |
|
|
569 | (6) |
|
|
570 | (1) |
|
Functional Use of Controls |
|
|
570 | (2) |
|
|
571 | (1) |
|
|
571 | (1) |
|
|
571 | (1) |
|
|
572 | (1) |
|
|
572 | (2) |
|
|
574 | (1) |
|
Chapter 32 Regulations, Standards, and Frameworks |
|
|
575 | (8) |
|
Industry-Standard Frameworks and Reference Architectures |
|
|
575 | (4) |
|
Regulatory and Non-regulatory Requirements |
|
|
576 | (1) |
|
Industry-Specific Frameworks |
|
|
577 | (2) |
|
Benchmarks and Secure Configuration Guides |
|
|
579 | (2) |
|
Platform-and Vendor-Specific Guides |
|
|
579 | (1) |
|
|
580 | (1) |
|
|
581 | (2) |
|
Chapter 33 Organizational Security Policies |
|
|
583 | (14) |
|
|
583 | (1) |
|
Human Resource Management Policies |
|
|
584 | (8) |
|
|
584 | (1) |
|
Onboarding and Offboarding |
|
|
584 | (1) |
|
|
585 | (1) |
|
|
585 | (1) |
|
|
586 | (1) |
|
|
586 | (1) |
|
Role-Based Awareness and Training |
|
|
586 | (2) |
|
|
588 | (1) |
|
Acceptable Use Policy/Rules of Behavior |
|
|
589 | (1) |
|
|
590 | (1) |
|
|
591 | (1) |
|
Disciplinary and Adverse Actions |
|
|
591 | (1) |
|
|
592 | (1) |
|
Third-Party Risk Management |
|
|
592 | (4) |
|
Interoperability Agreements |
|
|
593 | (3) |
|
|
596 | (1) |
|
Chapter 34 Risk Management |
|
|
597 | (16) |
|
|
598 | (4) |
|
|
598 | (1) |
|
|
599 | (2) |
|
|
601 | (1) |
|
|
602 | (4) |
|
Qualitative vs. Quantitative Measures |
|
|
604 | (1) |
|
|
605 | (1) |
|
Annual Rate of Occurrence |
|
|
606 | (1) |
|
|
606 | (1) |
|
|
606 | (6) |
|
|
607 | (1) |
|
Identification of Critical Systems |
|
|
607 | (1) |
|
|
607 | (1) |
|
|
608 | (1) |
|
|
609 | (1) |
|
|
610 | (2) |
|
|
612 | (1) |
|
Chapter 35 Sensitive Data and Privacy |
|
|
613 | (12) |
|
Sensitive Data Protection |
|
|
613 | (8) |
|
Data Sensitivity Labeling and Handling |
|
|
614 | (2) |
|
Privacy Laws and Regulatory Compliance |
|
|
616 | (2) |
|
Data Roles and Responsibilities |
|
|
618 | (2) |
|
Data Retention and Disposal |
|
|
620 | (1) |
|
Privacy Impact Assessment |
|
|
621 | (2) |
|
|
623 | (2) |
Glossary of Essential Terms and Components |
|
625 | (30) |
Index |
|
655 | |