Cryptography in use
By now, you should have a solid view of how cryptography works, but where and how does cryptography fit into a contemporary information system? Remember that the primary objectives of a cryptosystem are to provide the following security services, ideally in a cost-justified manner, balancing the need for security (required protection for the valuable information assets) with the cost of implementation.
Confidentiality
Authentication
Nonrepudiation
Integrity
Secure key distribution
This balance links to the risk assessment and information classification covered in Chapter 1 and the resulting policies that dictate what satisfactory protection is for each data element based on that classification. These policies define the strength ...
Get CISSP Training Kit now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.