Network Security Concepts Flashcards
What are six terms associate with security management?
Asset; Vulnerability; Exploit; Threat; Risk; Countermeasure
A weakness in a system or its design that could be exploited by a threat.
Vulnerability
The mechanism used to leverage a vulnerability to compromise an asset.
Exploit
A potential danger to an asset such as information or network functionality.
Threat
The likelihood that a particular threat will exploit a particular vulnerability of an asset that results in an undesirable consequence.
Risk
A protection that mitigates a potential threat or risk.
Countermeasure
To provide adequate protection of network assets, what three things must be guaranteed?
Confidentiality, Integrity, Availability (CIA)
Only authorized users can view sensitive information.
Confidentiality
Only authorized users can change sensitive information. It can also guarantee the authenticity of data.
Integrity
Authorized users must have uninterrupted access to important resources and data.
Availability
What factors should be considered when classifying data?
Value; Age; Useful Life; Personal association
The number one criteria when classifying data, and is based on the cost to acquire, develop, and replace.
Value
The importance of data usually decreases with time.
Age
The amount of time in which data is considered valuable and must be kept classified.
Useful Life
Data that involves personal information of users and employees.
Personal association
What data classifications terms are commonly used by government and military?
Unclassified; Sensitive but Unclassified (SBU); Confidential; Secret; Top Secret
Which security term refers to a person, property, or data of value to a company?
Asset
Which asset characteristic refers to the risk that results from a threat and lack of a countermeasure?
Liability
Data that has little or no confidentiality, integrity, or availability requirements, and therefore little effort is made to secure it.
Unclassified
Data that could prove embarrassing if it is revealed, but no great security breach would occur.
Sensitive but Unclassified (SBU)
Data that must be kept secure.
Confidential
Data for which significant effort is made to keep it secure. Few individuals have access to this data.
Secret
Data for which great effort and sometimes considerable cost is made to guarantee its secrecy. Few individuals on a need-to-know condition have access.
Top secret
What data classifications terms are commonly used by private sector?
Public; Sensitive; Private; Confidential