1.1 - General Security Concepts Flashcards

(28 cards)

1
Q

What is a Vulnerability

A

A weakness in software, hardware, devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Threat

A

A potential danger
Adversarial = Someone targeting that threat
Non-adversarial = not targeted e.g. flood, power outage, weather event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat Actor

A

Adversary/Someone with malicious intent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Exploit

A

When a threat actor successfully takes advantage of a vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk

A

Level of uncertainty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are Controls?

A

Tactics, mechanisms, strategies that proactively minimise risk in these ways:
Reduce or eliminate a vulnerability
Reduces or eliminates the likelihood that a threat actor will be able to exploit a vulnerability
Reduces or eliminates the impacts of an exploit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are Countermeasures?

A

Controls that have been implemented to address a specific threat

This is generally reactive to the threat
It Can be more effective but cannot be used broadly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How can controls be trustworthy?

A

They should be functional (what does it do?)
They should be effective (how well does it work?)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a Control Objective

A

A statement of desired result or purpose to be achieved by implementing a control or set of controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Security Control Diversity?

A

It is a design that implements the use of overlapping layers of diverse controls so that if a control fails the next control is successful

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Security Control Baselines?

A

A set of minimum security controls that organisations implement to protect their systems and data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How can you apply/fine tune controls?

A

Scoping, Tailoring Compensating, supplemeting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Scoping?

A

Eliminates unnecessary baseline recommendations that doesn’t apply to the organisation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Tailoring?

A

Customising the baseline recommendations to align with the organisation’s needs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Compensating?

A

Substituting recommended baseline control with a similar control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Supplementing?

A

Augmenting (adding to) the baseline recommendations

17
Q

What is Cost Benefit Analysis?

A

Process of evaluating the security investments and comparing the estimated costs and the benefits to see/determine whether it applies/beneficial to the business

18
Q

What are the 4 Control Categories?

A

Technical, Managerial, Operational, Physical

19
Q

What is the Technical control category?

A

Mechanisms/controls that are implemented using technology to reduce vulnerability in hardware, software, and/or firmware components (e.g. firewalls, cryptography, authentication systems)

20
Q

What is the Managerial control category?

A

This relates to risk management, governance, oversight, strategic alignment, and decision making (e.g. risk assessments, project management)

21
Q

What is the Operational control category?

A

Security measures/processes that are implemented/put into place and managed by people (e.g. change management, training, testing)

22
Q

What is the Physical control category?

A

These are designed to address physical interactions –> related to building and equipment (e.g. gates, barricades, locks)

23
Q

What are the 4 control classification?

A

Deterrent, preventative, detective, corrective

24
Q

What is the deterrent control classification?

A

Discourages a threat agent from acting

25
What is the preventative control classification?
Stops a threat agent from being successful
26
What is the Detective control classification?
Identifies and reports a threat agent or action
27
What is the correcive control classification?
Security measures that are taken after a security event has occurred to mitigate or reverse the damages of the event/threat agent
28
What are directive controls?
Security mesures that are designed to guide or direct indiviuals towards a specific action or outcome -> used to increase the effectiveness of other controls e.g. frameworks, models, policies, guidance statements, and training