Domain 1: Security and Risk Management Flashcards
(153 cards)
CIA Triad
Confidentiality, Integrity, Availability
Ex: Violation of Confidentiality
capturing network traffic, stealing password files, social engineering, port scanning, shoulder surfing, sniffing…
Sensitivity
quality of info, which could cause harm or damage if disclosed
Discretion
act or decision where an operator can influence of control disclosure to minimize damage
Criticality
level to which info is mission critical
Concealment
act of hiding or preventing disclosure
Seclusion
Storing info in an out of the way location
Ex: Violation of Integrity
Accidental deletion of files, entering invalid data, including errors in commands…
Availability
Authorized subjects are granted timely and uninterrupted access to objects
Ex: Violations of Availability
Accidental deletion of files, over utilization of HW/SW, underallocating resources…
AAA Services
Identification, Authentication, Authorization, Auditing, Accounting
Identification
who you are
Authentication
you are who you say you are
Authorization
allows and denials of resource and object access for who you are
Auditing
recording of events
Accounting/Accountability
holding subjects accountable for their actions
Nonrepudiation
ensures that the subject of an activity or event cannot deny that the event occurred, possible through AAA services
Layering
Defense in Depth, Delay an intruder
Abstraction
Similar elements are put into groups, classes, or roles and assigned security controls as a collective
Data Hiding
positioning data in a logical storage compartment not seen by subjects (think classification levels)
Encryption
art and science of hiding the meaning or intent of a communication from unintended recepients
Security Governance
Collection of practices related to supporting, defining, and directing the security efforts of an org
The best key plan is useless without ________
approval by senior mgmt
Security Plan Timeline
Strategic (5 year - risk assessment, stable, security purpose), Tactical (1 year - midterm, schedules tasks, project plans, hiring plans, budget plans), Operational (Months -short term, highly detailed, training plans, system deployment plans)