Topic 1 - Information Assurance Principles
Topic 1 - Information Assurance Principles
• In general, you must apply both due care and due diligence to
ensure a system is operating within acceptable social and legal
norms.
• Due care is the development and implementation of policies and
procedures to aid in performing the ongoing maintenance
necessary to keep an information assurance process operating
properly to protect assets and people from threats. Due care
prevents negligence.
• Due diligence is the reasonable investigation, research, and
understanding of the risks an organization faces before
committing to a particular course of action. The organization
should do its homework and ensure ongoing monitoring.
• Have considered
The MSR Model of Information Assurance
Basic Definitions
The 7 Information Assurance Principles
Implications from Lack of Information Assurance