1 intro Flashcards
(13 cards)
What is a system and what is security?
System is a specific IT installation with particular purpose and operational environment
Security is
What are system assets?
Hardware, software, data
Difference between data and information?
Data is the phyiscal phenomena chosen to represent conceptual world
The meaning assigned to data is information
What is security?
The protection of assets
What is unlinkability, undetectability and anonymity?
All are tied to confidentiality
Unlinkability: shouldnt be able to link two or more items of interest
Undetectability: shouldnt be able to know whether an item exists or not
Anonymity: shouldnt be able to identify subjects
What is unlinkability, undetectability and anonymity?
All are tied to confidentiality
Unlinkability: shouldnt be able to link two or more items of interest
Undetectability: shouldnt be able to know whether an item exists or not
Anonymity: shouldnt be able to identify subjects
What are the security properties besides CIA?
Accountability
Non-repudiation
Reliability
Categories of vulnerabilities?
Corrupted (integrity), Leaky (confidentiality), unavailable/slow (availability)
What is a security policy?
Plan or course of actions intended to influence and determine decisions and actions
Security policy: a statement that defines security objectives of organization. What is allowed, what is not
Two types:
- Enterprise
- System-specific
What does security policy need to address?
Scope & purpose
IT requirements
Assignments and responsibilities
Awareness training
Personnel issues
contingency planning
IDS
What categories can countermeasures be grouped into?
Deterrence
Protection and prevention
Detection
Recovery and response
What can be said about policies and mechanisms?
Policies divide into secure and not secure.
Mechanisms prevents system from entering not secure.
What is required for a security mechanism to be secure, precise and broad?
Secure if set of restricted states is subset of secure states
Precise if set of restricted states is equal to set of secure states
Broad if there is a state that is restricted and not secure