Chapter 21

The Importance of Frameworks, Policies, Procedures, and Controls

This chapter covers the following topics related to Objective 5.3 (Explain the importance of frameworks, policies, procedures, and controls) of the CompTIA Cybersecurity Analyst (CySA+) CS0-002 certification exam:

  • Frameworks: Covers both risk-based and prescriptive frameworks.

  • Policies and procedures: Includes code of conduct/ethics, acceptable use policy (AUP), password policy, data ownership, data retention, account management, continuous monitoring, and work product retention.

  • Category: Describes the managerial, operational, technical categories.

  • Control type: Covers the preventative, detective, corrective, deterrent, compensating, and physical control types.

  • Audits ...

Get CompTIA Cybersecurity Analyst (CySA+) CS0-002 Cert Guide, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.