Disaster Recovery Sites: Hot, Warm, Cold and Cloud
Hot, warm, cold and cloud recovery sites compared. The BIA sets the RTO, and the RTO picks the site. A CISSP insight with a manager mindset.
THE LIBRARY
Hot, warm, cold and cloud recovery sites compared. The BIA sets the RTO, and the RTO picks the site. A CISSP insight with a manager mindset.
Due diligence is finding out. Due care is acting on what you found. A CISSP insight on the prudent person rule and the evidence that proves both.
Fail safe defaults to open and protects people. Fail secure defaults to locked and protects assets. A CISSP insight on matching the default to the risk.
AH authenticates but never encrypts and breaks through NAT. ESP encrypts, authenticates and traverses NAT. A CISSP insight on the IPsec protocol choice.
SAST reads source code without running it, catching flaws at the cheapest point in the SDLC. A CISSP insight on its strengths, blind spots and CI/CD role.
Silver Ticket attacks for the CISSP exam: forging service tickets with a stolen service account hash, why the KDC bypass hides them, and how to defend.
Master the Bell-LaPadula model for CISSP exam success. Learn how clearances, No Read Up, and No Write Down keep classified information confidential.
Master the Biba model for CISSP exam success. Learn how integrity levels, No Read Down, and No Write Up protect trusted data from corruption.
Master the Brewer and Nash (Chinese Wall) model for CISSP. See how conflict of interest classes and dynamic access controls stop competitor data leaks.
Master the Clark-Wilson model for CISSP. Learn how well-formed transactions, separation of duties, and access triplets protect commercial data integrity.
Master the Graham-Denning model for CISSP. Learn the 8 operations for managing subjects, objects, and access rights, plus ownership and transfer.
The foundational certificate pinning decision: choosing between certificate fingerprints, public key hashes and chain elements. A CISSP exam insight.
Scoping makes binary yes or no calls on whether a control applies. Tailoring customises how it is implemented. A CISSP insight with a manager mindset.
Master RPO, RTO, WRT and MTD for CISSP exam success: how the four disaster recovery metrics fit on one timeline, with worked examples and exam tips.
Master Kerberoasting for the CISSP exam: how any domain user extracts service tickets, cracks service account passwords offline, and how to stop it.
Master Golden Ticket attacks for the CISSP exam: how attackers forge Kerberos TGTs with the krbtgt hash, why detection is hard, and the double reset fix.
Master Kerberos for the CISSP exam: the ticket based protocol, the AS, TGS and KDC, the six step flow, and why time synchronisation matters.