An organization is updating its enterprise security program policy for network edge enclosures located in multi-tenant facilities. The Chief Information Security Officer (CISO) requires a security architecture that combines an administrative security program element with a physical access control mechanism to prevent unauthorized physical hardware tampering by facility personnel. Which set of measures correctly pairs an administrative security program element with a physical access control to fulfill this mandate?
- Establishing a formal access authorization policy requiring pre-approved visitor lists and badge verification, paired with installing chassis intrusion sensors and lockable rack enclosures.Cevap
- BConfiguring AAA authorization profiles on a centralized TACACS+ server, paired with establishing site-to-site IPsec VPN tunnels between remote sites.
- CEnabling Port Security with sticky MAC address learning on edge switch ports, paired with configuring extended IPv4 Access Control Lists (ACLs) on default gateways.
- DDeploying DHCP Snooping to validate incoming network leases, paired with implementing an explicit deny statement at the end of interface filtering lists.
Cevap
Establishing a formal access authorization policy requiring pre-approved visitor lists and badge verification, paired with installing chassis intrusion sensors and lockable rack enclosures.
Developing a formal access authorization policy with visitor verification represents an administrative control (governance, policy, and procedure). Installing lockable enclosures with chassis intrusion detection represents a physical access control that directly prevents and monitors physical contact with hardware components.
Adım Adım Çözüm
Anahtar Kavram
Classification of Enterprise Security Controls (Administrative vs. Physical vs. Technical)