This chapter covers the following topics:
• Operations security concepts: Discusses concepts concerning maintaining security operations such as need-to-know/least privilege, separation of duties, job rotation, sensitive information procedures, record retention and monitoring special privileges.
• Resource protection: Describes procedures used to protect tangible and intangible assets. Topics include redundancy and fault tolerance, backup and recovery systems, identity and access management, media management, and network and resource management.
• Operations processes: Focuses on managing ongoing security measures. Topics include incident response management, change management, configuration management, patch management, ...