Chapter 3 Flashcards

1
Q

What is a subject

A

Generally an individual, process, or device causing information to flow among objects or change to the system state.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is are characteristics of a subject

A

It is active, it initiates a request for access to resources or services.

Requests a service from an object

Should have a level of permissions that relates to its ability to access services or resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define an object

A

Anything that a subject attempts to access is a referred to as an object

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are some characteristics of objects

A

Passive - a device, process, person, user, program, server, client or other entity that responds to a request for service.

By definition, objects do not contain their own access control logic

May have a classification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is an access rule

A

An instruction developed to allow or deny access to an object by comparing the validated identity of the subject, to an ACL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are some characteristics of rules

A

Compare mulitple attributes to determine appropriate access
allow or deny access to an object
Define how much access is allowed
Apply time-based access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What do controls do

A

Limit risk to a tolerable level.

Logical and physical controls when combined, limit risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

define CPTED

A

Crime Prevention through environmental design

approaches the challenge of creating safer workspaces through passive design elements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly