Intro to Security Risk Assessment for system design Flashcards
1
Q
Security Level Types
A
SL (T) - Target – Desired level of security for a particular system.
SL (A) - Achieved – Actual level of security for a particular system.
SL (C) - Capability – Security level that a component or system can provide with properly configured
2
Q
List down 7 Foundation Requirements
A
FR 1 - Identification and Authentication Control (IAC)
FR 2 - Use Control (UC)
FR 3 - System Integrity (SI)
FR 4 - Data Confidentiality
FR 5 - Restricted Data Flow
FR 6 - Timely Response to Events (TRE)
FR 7 - Resource Availability (RA)