Cyber security - A security architect's perspective Flashcards

1
Q

Define Confidentiality

A

Only sender and intended receiver should “understand” message contents
- sender encrypts message
- receiver decrypts message

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define Authentication

A

Sender and receiver want to confirm identity of each other

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define Message Integrity

A

Sender and receiver want to ensure message is not altered (in transit, or afterwards) without detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define Access and Availability

A

Services must be accessible and available to users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is NIST’s definition of Computer Security

A

The protection afforded to an automated information system in order to attain the applicable objectives of preserving the integrity, availability, and confidentiality of information system resources including hardware, software, firmware, information/data, and telecomunications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Name some computer security challenges

A

Security not as simple as it seems
-Easy requirements, tough solutions

solutions can be attacked themselves
-Security policy enforcement structures as the targets

Protection of enforcement structure can complicate solutions
- Solution itself can be easy, but complicated by protection

Security architectural decisions
-Know what to do, but where to do them?

key management is really hard

protectors have to be right all the time
- attackers just once

no one likes security until it’s needed
-Seat belt philosophy

Security architectures require constant effort
-Strategic vs tactical perspectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly