Systems Security Certified Practitioner – SSCP – Question0409

Which of the following best defines add-on security?

A.
Physical security complementing logical security measures.
B. Protection mechanisms implemented as an integral part of an information system.
C. Layer security.
D. Protection mechanisms implemented after an information system has become operational.

Correct Answer: D

Explanation:

The Internet Security Glossary (RFC2828) defines add-on security as “The retrofitting of protection mechanisms, implemented by hardware or software, after the [automatic data processing] system has become operational.” Source: SHIREY, Robert W., RFC2828: Internet Security Glossary, may 2000.