CISSP考试指南笔记:3.22 站点规划过程

The objectives of the site and facility security program depend upon the level of protection required for the various assets and the company as a whole. And this required level of protection, in turn, depends upon the organization’s acceptable risk level. This acceptable risk level should be derived from the laws and regulations with which the organization must comply and from the threat profile of the organization overall.

Physical security is a combination of people, processes, procedures, technology, and equipment to protect resources. The design of a solid physical security program should be methodical and should weigh the objectives of the program and the available resources.

Threats can be grouped into categories such as internal and external threats. It is critical for a company to carry out a background investigation, or to pay a company to perform this service, before hiring a security guard.

A threat that is even trickier to protect against is collusion, in which two or more people work together to carry out fraudulent activity.

An organization’s physical security program should address the following goals:

  • Crime and disruption prevention through deterrence

  • Reduction of damage through the use of delaying mechanisms

  • Crime or disruption detection

  • Incident assessment

  • Response procedures

As with all security programs, it is possible to determine how beneficial and effective your physical security program is only if it is monitored through a performance-based approach.

剩余内容请看本人公众号debugeeker, 链接为CISSP考试指南笔记:3.22 站点规划过程

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值