Chapter 12 Flashcards
Operating system security
1
Q
Strategies for OS security
A
- white-list approved applications
- patch third-party applications + OS vulnerabilities
- restrict administrative privileges
- create defence-in-depth system
2
Q
System security planning
A
- purpose of system , type of info stored
- categories of users of the system, privileges they have
- how users authenticated
- who will administer system + how manage system
- what access the system has to info stored on other hosts + how managed
- how access to info stored = managed
- any additional security measures required
3
Q
Setup
A
- Remove unnecessary applications + services
- configure users , groups + authentication
- configure resource controls
- Install additional security measures
- Test system security
4
Q
Security maintenance
A
- monitor + analyse logging info
- perform regular backups
- recover from security compromises
- regularly test system security
- using appropriate software maintenance process to patch + update all critical software + monitor + revise configuration as needed
5
Q
Hypervisor functions
A
- execution management of VM
- device emulation + access control
6
Q
Planned process for deployment + building OS
A
- assess risk + plan system deployment
- secure underlying OS + then key applications
- ensure critical content is secure
- ensure appropriate network protection mechanisms are used
- ensure appropriate processes are used to maintain security
7
Q
IDS
A
Intrusion detection system