Chapter 1: Introduction to Security Flashcards
yeeeeeeeeeee
CIA
Confidentiality, Integrity, Availability
What does Confidentiality do?
Prevents disclosure of information to outside party
Integrity
Guarantees data has not been tampered with
AAA
Authentication, Authorization, Accounting(non-repudiation)
What is Authentication?
Confirms one’s identity
e.g.) username/password, biometrics, signature etc
What is Authorization?
Allows one to access certain materials
e.g.) ACL(Access Control Lists), Linux permission bits etc
What is Accounting of Data?
Tracking of data/comp./netwrk resources usage for individuals
e.g.) Logging, auditing, data/network monitoring
Types of Threats
Malicious Software
- Unauthorized Access - System Failure - Social Engineering
Technical security plan
- Technical : Smart cards, ACLs, encryption etc
Protection Methods
- User Awareness
- Authentication
- Anti-malware
- Data Backups
- Encryption
- Data Removal
Physical security plan
- Physical : Physical security systems such as alarms, ID cards, CCTV etc
Administrative Security plan
- Administrative : Policies, procedures, DRP(Disaster recovery plan) etc