CIA Triad Concept Flashcards
Prevents the disclosure of data to unauthorized people so that only authorized people have access to data.
Confidentiality
encryption uses one key, known as the secret key.
Symmetric
encryption uses two keys, known as the private key and the public key.
Asymmetric
This means that you know that data has not been altered or tampered with. We use a technique called hashing that takes the data and converts it into a numerical value called a hash or message digest.
Integrity
which allows one or two disks to fail while still keeping the data available.
RAID Redundant Array Independent Disk
two servers can access the same data, and if one fails, the other can still provide the data, a data backup,
Fail Over Cluster
regulates the temperature for critical servers. In a datacentre, if the temperature is too hot then the servers will shut down.
HVAC
where you give someone only the most limited access required so that they can perform their job role; this is known as a need-to-know basis.
Least Privilege
is the concept of protecting a company’s data with a series of protective layers so that if one layer fails, another layer will already be in place to thwart an attack.
Defense in Depth
written by managers to create organizational policies and procedures to reduce risk within companies. They incorporate regulatory frameworks so that the companies are legally compliant.
Managerial Controls
A company will have a risk register where the financial director will look at all of the risks associated with money and the IT manager will look at all of the risks posed by the IT infrastructure.
Annual Risk Assessment
is not intrusive as it merely checks for vulnerabilities,
Vulnerability Scan
is more intrusive, as it goes deeper into a computer and can exploit vulnerabilities. It could cause the system to crash unexpectantly.
Penetration Testing
are executed by company personnel during their day-to-day operations.
Operational Controls
This is an annual event in which you are reminded about what you should be doing each day to keep the company safe:
Annual Security Awareness Training