Dion Cards Flashcards
What is the AAA of Security?
Authentication
Authorization
Accounting
What is Authentication in the AAA of Security?
When a person’s identity is established with proof or by a system
What are the 5 ways Authentication can be established?
Something you are Something you know Something you have Something you do Somewhere you are
What is Authorization in the AAA of Security?
Its when a user is given access to something - e.g. data or area of a building
What is Accounting in the AAA of Security?
The tracking of data, computer usage and network resources.
Non-repudiation occurs when you have proof someone did an action.
What are the 4 main types of security threat?
Malware
Unauthorized Access
System Failure
Social Engineering
What is malware?
Malicious software
What is Unauthorized Access threat?
Happens when someone accesses data/resources without the owner’s consent
What is System Failure as a threat?
Happens when a computer or application fails
What is the threat of Social Engineering?
Manipulation of users to give up confidential info or to perform detrimental actions
What are three types of controls/categories that can mitigate threats?
Physical Controls
Technical Controls
Administrative Controls
Give some examples of Physical Controls (6)
Fence Locked doors Alarm systems Surveillance cameras ID Cards Security Guards
Give some examples of Technical Controls (5)
Smart cards Encryption ACLs (Access Control Lists) Intrusion Detection Systems Network Authentication
Give some examples of Administrative Controls (5)
Policies Procedures Security Awareness Training Contingency Planning Disaster Recovery Planning
What are the 5 types of hacker!?
White Hat
non malicious, has company permission
Black Hat
malicious, no permission
Gray Hat
no company affliction, no permission. Trying to shame/educate, not personal gain
Blue Hat - has permission from company, but not employed by company
Elite - exploit things first