Assets Flashcards
Type of assets
Hardware (Tangible)
Software (Security System or process)
Comination (file transfer between computers)
data (personal, private, business, public)
Types of passive attack
Release of message contents
Traffic analysis
Types of active attack
Replay, Masquerade, modification of messages, denial of service
Security requirements
Access control
awareness and training
audit and accountability
certification
accreditation and security assessments
config management
contingency planning
identification and authentication
incident response
media protection
physical and enviromental protection
risk assessment
system and comms protection
system and info integrity
Network Attack surface
Vulnerabilities over a network
Software attack surface
Vulnerabilities in application, utility or OS code
Human Attack surface
vulnerabilities created by personel or outsiders
Computing Standards organisations
NIST, ISOC, ITU-T, ISO