Cyber basics Flashcards
(128 cards)
What does CIA stand for?
Confidentiality , integrity, availability
What does confidentiality in CIA refer to?
the act of sharing or revealing information only with authorized personal
What does integrity in CIA refer to?
the ability to ensure that information or data remains unchanged and accurate
What does availability in CIA refer to?
ensuring timely and reliable access to and use of information
What does the red team do?
Test defenses, search for weaknesses, provide assesments
What does the blue team do?
Maintain security, Prevent breaches, Monitor for threats, Respond to incidents, Research technologies
What is an HVA?
High Value Asset
What are the primary roles of Cybersecurity in a business?
protect assests or HVA, protect data, protect functions and processes, protect ALL org assets.
True or False: The cost of treating risk should never meet or exceed the potential loss?
True
What does NIST stand for?
National institute of Standards and Technology
Is NIST framework required or voluntarily implemented?
A voluntary framework
What is risk?
Risk is the level of organizational assets, organizational operations, or individuals resulting from the operation of an information system given the potential impact of a threat and the likelihood of that threat occuring.
What is risk more simply?
Risk is if you have an asset with a vulnerability that has a threat of being exploited.
What does PII (pii) refer to?
Personally identifiable information
What are the security risk factors?
Threat, Vulnerability, Likelihood, Impact
What does CONTROL refer to when associated with the word RISK?
Managing risk, including policies, procedures, guidelines, practices, or org structures
What does VULNERABILITY refer to when associated with the word RISK?
Weakness in a system, system security procedures, internal controls, or implementation
What does CYBERRISK refer to when associated with the word RISK?
risk to a business due to the failure of a business function dependent on digital technologies
What does LIKELIHOOD refer to when associated with the word RISK?
A weighted factor based on subjective analysis if the probability that a given threat is capable of exploiting a given vulnerability.
What does RMF mean?
Risk Management Framework - a flexible risk based approach
In order what are the 7 phases of the RMF?
- Prepare 2. Categorize information systems. 3. Select security controls. 4. implement security controls. 5. Assess security controls. 6. authorize information systems. 7. monitor security controls.
What is an asset?
Assets can be hardware, software, or information.
What is a threat?
A potentially negative action or event often caused by taking advantage of a vulnerability
What is a risk?
probability of exposure or loss resulting from a cyber attack.