DEFI Flashcards
1
Q
Elements of Security
A
- assets,
- threats,
- vulnerabilities,
- impact,
- risk,
- safeguards,
- residual risk,
- constraints.
2
Q
Assets
A
Everything that has a value
- Information and Data,
- Hardware,
- Software,
- other Equipment,
- documents,
- services,
- “trust” in services,
- personell,
- A organization’s image
3
Q
Threats
A
Everything that potentially harms Assets
- errors,
- faults,
- misuse and theft,
- malicious code,
- hacking,
- sabotage,
- espionage,…
4
Q
Vulnerabilities
A
“Vulnerabilities are weaknesses which allow a threat to occur”
(Vulns do not neccesarily cause damage)
- Insecure Communication
- Poorly trained staff
- trivial passwords
- poor access control
- lack of back-ups
5
Q
safeguards
A
Means to reduce threats or vulnerabilities
Example: Access Control, Encryption, training of personell,…
- ETSI Baseline Security Standard
- NIST Computer Security Handbook
- ISO TC 68 Banking and Related Financial Services - Information Security Guidelines
6
Q
Risks
A
Risk is a Function of
- Assets
- Threats
- Vulnerabilities
- Safeguards
There always remains a residual Risk
7
Q
Relations
A
8
Q
Confidentiality
A
- No unauthorized access to Information
- sometimes security and confidentiality are use as synonyms
9
Q
Integrity
A
- No unauthorized modification of information/resources
- Everything is as it is supposed to be
10
Q
Availability
A
No unauthorized denial of access to information / resources
11
Q
denial of service
A
prevention of authorised access of resources or the delaying of time-critical operations
⇒ hard to prevent in real life
12
Q
Privacy and Secrecy
A
- protection of personal data
- protection of data belonging to an organisation
13
Q
property
A
- property is any attribute that can be quantitatively evaluated
- tempurature, pressur, velocity are properties
14
Q
state
A
- state of an object is its condition described by a list of properties
- temperature and pressure may describe the state of a gas
15
Q
integrity property or state
A
- integrity is a property (of data, of a system)
- data integrity is a specific state of data that is verifiable