Chapter 1 Flashcards
{BLANK} ensures that the subject of an activity or who caused an event cannot deny that the event occurred.
Nonrepudiation
Think - AAA Services
{BLANK} is the security concept that data is authentic or genuine and originates from its alleged source.
Authenticity
Think - CIA Triad
{BLANK} is the concept of the measures used to ensure the protection of the secrecy of data, objects, or resources.
Confidentiality
{BLANK} is establishing a plan, policy, and process to protect the interest of an organization.
Due Diligence
{BLANK} is knowing what should be done and planning for it.
Due Diligence
A {BLANK} defines a minimum level of security that every system throughout the organization must meet.
Baseline
{BLANK} is reviewing log files to check for compliance and violations in order to hold subjects accountable for their action especially violations of organizational security policy.
Accounting (aka Accountability)
AAA Services is a core security mechanism of all security environments. What are the five elements of AAA services?
- Identification
- Authenticication
- Authorization
- Auditing
- Accounting
An {BLANK} is responsible for reviewing and verifying that the security policy is properly implemented and the derived security solutions are adequate.
Auditor
What are the five key concepts of the decomposition process?
- Trust Boundaries
- Dataflow Paths
- Input Points
- Privileged Operations
- Detailed about Security and Approach
{BLANK} is the collection of practices related to supporting, evaluating, defining, and directing the security efforts of an organization.
Security Governance
Think - CIA Triad
{BLANK} means authorized subjects are granted timely and uninterrupted access to objects.
Availability
{BLANK} is preventing data from being discovered or accessed by a subject by positioning the data in a logical storage compartment that is not accessible or seen by the subject.
Data Hiding
A {BLANK} is the line intersection between any two areas, subnets, or environments that have different security requirements or needs.
Security Boundary
{BLANK} is practicing the individual activities that maintain the due diligence effort.
Due Care
{BLANK} is doing the right action at the right time.
Due Care
A {BLANK} offers recommendations on how standards and baselines are implemented and serves as an operational guide for both security professional and users.
Guideline
{BLANK}, also known as laying, is the use of multiple controls in a series.
Defense in Depth