Legal, Regulations, Compliance, and Investigation - This domain addresses:
o Computer crime laws and regulations
o The measures and technologies used to investigate computer crime incidents
• Operations Security - Operations Security is used to identify the controls over hardware, media, and the operators and administrators with access privileges to any of these resources. Audit and monitoring are the mechanisms, tools, and facilities that permit the identification of security events and subsequent actions to identify the key elements and report the pertinent information to the appropriate individual, group, or process.
• Physical (Environmental) Security - The Physical (Environmental) Security domain provides protection techniques for the entire facility, from the outside perimeter to the inside office space, including all of the information system resources.
• Security Architecture and Design - The Security Architecture and Design domain contains the concepts, principles, structures, and standards used to design, monitor, and secure operating systems, equipment, networks, applications and those controls used to enforce various levels of availability, integrity, and confidentiality.
• Telecommunications and Network Security - The Telecommunications and Network Security domain discusses the:
o Network structures
o Transmission methods
o Transport formats
o Security measures used to provide availability, integrity, and confidentiality
o Authentication for transmissions over private and public communications networks and media
|