Chapter 1 Flashcards
Define Cybersecurity
the protection of information assets by addressing threats to information processed, stored and transported by internetworked information systems
Confidentiality
protection from unauthorized access
Integrity
protection from unauthorized modification
Availability
protection from disruption to access
Define APT
Advanced Persistent Threats - attacks by adveraries with sophisticated levels of expertise and resources
5 Key Functions of Protecting Digital Assets
Identify Protect Detect Respond Recover
Define Identify
Use organizational understanding to minimize risk to systems, assets, data, and capabilities.
Define Protect
Design safeguards to limit the impact of potential events on critical services and infrastructure.
Define Detect
Implement activities to identify the occurrence of a cybersecurity event.
Define Respond
Take appropriate action after learning of a security event.
Define Recover
Plan for resilience and the timely repair of compromised capabilities and services.
CIA
Confidentiality
Integrity
Availability
Method Controls for Confidentiality
Access Controls
File Permissions
Encryption
Method Controls for Integrity
Access Controls Logging Digital Signatures Hashes Encryption
Method Controls for Availability
Redundancy
Backups
Access Controls
Define nonrepudiation
when a piece of information is genuine
How do you achieve nonrepudiation
use logs and digital signatures
What are the three cybersecurity topics?
Governance
Risk Management
Compliance
Who is responsible for governance?
the board of directors and senior management of the organization
Goals of governance
- Provide strategic direction
- Ensure that objectives are achieved
- Verify that the organization’s resources are being used responsibly
Define Risk Management
The process by which an organization manages risk to acceptable levels
risk can be financial, physical or cyber
Define Compliance
the act/ability of adhering to mandated requirements defined by laws and regulations
Cybersecurity Roles
Board of Directors
Executive Committee
Security Management
Cybersecurity Practitioner