Chapter 1 Flashcards
Domain 1 and 3
What are the three (3) common types of security evaluation?
Risk Assessment, Vulnerability Assessment, and Penetration Testing
What is a risk assessment?
A process of identifying assets, threats, and vulnerabilities and then using that information to calculate risk.
What is is vulnerability assessment?
A procedure that uses automated tools to locate known security weaknesses.
What is a penetration test?
A procedure using trusted individuals to stress-test the security infrastructure to find issues that may not have been discovered by other assessments.
What are the primary goals and objectives for a security infrastructure?
Confidentiality, Integrity, and Availability (CIA)
In the security CIA Triad - what is confidentiality?
The concept of ensuring secrecy of data, objects and resources.
Which basic security principle is confidentiality based upon?
Least privilege.
What is the goal of confidentiality?
To prevent or minimize unauthorized “read” access to data.
What is the corner stone of security concepts?
Confidentiality, Integrity, and Availability (CIA)
What is the opposite of Confidentiality, Integrity, and Availability (CIA)?
Disclosure, Alteration and Destruction (DAD)
Name the concepts, conditions and aspects of confidentiality
Sensitivity, Discretion, Criticality, Concealment, Secrecy, Privacy, Seclusion, and Isolation
What is sensitivity in the concept of confidentiality?
The level of damage that could be caused if the information was released without authorization
What is discretion in the concept of confidentiality?
The act of the data owner or operator that influences or controls the disclosure of the data.
What is criticality in the concept of confidentiality?
The level of to which the information is importance to the organization for continuing operations.
What is concealment in the concept of confidentiality?
The act of hiding the information to prevent unauthorized disclosure.
What is secrecy in the concept of confidentiality?
The act of keeping data or information secret or preventing its disclosure.
What is privacy in the concept of confidentiality?
The act of keeping personally identifiable information confidential.
What is seclusion in the concept of confidentiality?
Involves storing data or information in a location that is out of the way of unauthorized users.
What is isolation in the concept of confidentiality?
The act of keeping something separated from others.
In relation to the security CIA triad, what is integrity?
The concept of protecting the reliability and correctness of the data.
In practice, how does integrity protect the data?
Preventing unauthorized modifications, preventing mistakes by authorized users, and maintaining consistency and verifiability of the data
What are the concepts, conditions and aspects of integrity?
Accuracy, truthfulness, validity, accountability, responsibility, completeness, comprehensiveness
In relation to the security CIA triad, what is avilability?
The timely and uninterrupted access to data by authorized users.
What are the concepts, conditions and aspects of availability?
Usability, accessibility, and timeliness