Chapter 1 Flashcards
(37 cards)
cia triad
- confidentiality
- integrity
- availibility
confidentiality
measures used to protect the secrecy of data, resources, objects
goal of confidentiality protection
minimize unauthorized data access
security controls for confidentiality protection
- encryption
- access control
- steganography
object
a passive element in a security relationship, e.g., files, networks, apps
subject
an active element in a security relationship, e.g., users, computers, programs
access control
management of a subject-object relationship
confidentiality attacks
- capturing network traffic
- stealing password files
- social engineering
- port scanning
- shoulder surfing
- eavesdropping
- sniffing
- escalating privileges
causes of unintentional data disclosures
- human error
- oversight
- ineptitude
countermeasures to ensure confidentiality
- encryption
- network traffic padding
- rigorous access control
- strict authentication process
- data classification
- personnel training
sensitivity
the quality of safeguarded data/info that in the event of unauthorized disclosure, may lead to damage
discretion
- minimize damage/harm by controlling info disclosure
- disclosure is influenced by an operator
criticality
- the importance of info to a mission
- more critical info should have more safeguards
concealment
- minimize disclosure by hiding info
secrecy
minimize disclosure of info
privacy
keeping PII confidential, especially to prevent harm
seclusion
reinforce confidentiality via compartmentalization and access control
isolation
keeping info seperate
integrity
ability to protect reliability and correctness of info
integrity achieved by
- preventing unauthorized access/changes
- keeping data consistent, especially internal/external
aspects of integrity
- validity
- authenticity
- completeness
- accuracy
- truthfulness
- non-repudiation
- accountability
- responsibility
- comprehensiveness
non-repudiation
situation where subject of event cannot dispute that event occured
availability
uninterrupted access to objects to all authorized subjects
usability
something that is easy to use