Appropriate password and account policies can protect against possible password attacks.

Security practitioners should adhere to the defense in depth principle to ensure that the CIA of data is ensured across its entire life cycle.

Analyze enterprise password policies, including password length, password complexity, and password expiration.

Data at rest may require encryption to provide full protection and appropriate access control lists ACLs to ensure that only authorized users have access.

Determine whether encryption is used to transmit data.

For data transmission, secure protocols and encryption should be employed to prevent unauthorized users from being able to intercept and read data.

They are actions or rules that are tactical in nature, meaning they provide the steps necessary to achieve security.

Just like policies, standards should be regularly reviewed and revised.

If it is, determine whether the authentication information is securely transmitted.

The defense in depth principle is further described in the introduction of this book.

Pass ICDL-POWERP Syllabus Practice Lab. Make sure that all firmware, operating systems, and applications are kept up to date, based on the vendor recommendations and releases.

Disable all unnecessary services, protocols, and accounts on all devices.

Applications and services should be analyzed to determine whether more secure alternatives can be used or whether inadequate security controls are deployed.

Deploying a new technology before proper security analysis has occurred can result in security breaches that affect more than just the newly deployed technology.

If it is not, determine whether authentication can be used.

The most secure level of authentication possible should be used in the enterprise.

If it is, ensure that the level of encryption is appropriate and that the encryption algorithm ICDL-POWERP Syllabus is adequate.

Ensure that the encryption keys are protected.

Standards describe how policies will be implemented within an organization.

Finally, security practitioners should ensure that confidential and private information is isolated from other information, including locating the information on separate physical servers and isolating data using virtual LANs VLANs.

If it is not, determine whether encryption can be used.

When new technologies are deployed based on the changing business needs of the organization, security practitioners should be diligent to ensure that they understand all the security implications and issues with the new technology.

Remember that changes are inevitable How you analyze and plan for these changes is what will set you apart from other security professionals.