Architecture & Design Flashcards
(153 cards)
Penalty Types
Criminal
Civil
Administrative
Private Regulations
Sources of Industry Standards
Vendors
Government Agencies
Independent/Consulting Agencies
Define Defense in Depth
Multiple layers of overlapping security controls
Security Control Types by Method
Technical
Administrative
Physical
Examples of Technical Controls
DLP Systems
NIDS/NIPS
Firewall
Examples of Administrative Controls
Background Investigations
NDAs
Security Training and Awareness
Examples of Physical Controls
Fences/Cages Locks Smart Cards Man Traps Video Surveillance Bollards Lighting Signs
Vendor Diversity Issues
Lack of Innovation
Technical Inefficiencies
Security Training and Awareness Methods
Classroom Orientation Online Vendor Surveys Reminders
Information Classification Factors
Sensitivity
Criticality
Military Classification System
Top Secret
Secret
Confidential
Unclassified
Business Classification
Highly Sensitive
Sensitive
Internal
Public
Compliance Obligations
Laws
Regulations
Standards
Password Factors
Complexity Length History Minimum age Expiration
Define Tailgating/Piggybacking
Unauthorized access to a facility by following another credentialed user when they enter
Security Zones
Intranet Internet DMZ Extranets Honeynets Ad Hoc MANET WIFI Direct
Define Intranet
Companies internal network
Define Internet
Public external network
Define DMZ
Demilitarized Zone, typically an organizations public facing assets separated from internal assets for security purposes
Define Extranets
Shared networks between separate organizations
Define Honeynets
Decoy networks for gaining threat intelligence on attackers
Define Ad Hoc Networks
Temporary networks for specific usage
Private IP Address Ranges
- 0.0.1-10.255.255.255
- 16.0.1-172.31.255.255
- 168.0.1-192.168.255.255
Define Static NAT
Translate private to public IP addresses (or visa versa) on a one-to-one basis