Domain 1 Flashcards
Any potential danger to an organization
threat
What is STRIDE
Identifies threats based off of major categories:
Spoofing
Tampering
Repudiation
Information disclosure
Denial of service
Elevation of privileges
A 7 step risk centric methodology that starts by identifying business objectives and technical requirements and takes into account compliance issues and business specific
PASTA
Total cost an organization can expect to occur from a given risk in a year
ALE (annual loss expectancy)
AV x EF = ?
SLE (single loss expectancy)
Controls that are proactive or preventative
safeguard
Reactive controls put in place when risks have occurred
countermeasure
Protects important business information. They do not need to be disclosed and are infinite
Trade Secrets
meant to protect some innovative or novel idea they do need to be disclosed and they only provide protection for a set period
Patent
protects the expression of an idea in some sort of fixed medium like books movies or songs disclosure is required and the protection is again only for a set period of time
copyright
protect some sort of unique color, sound, symbol used to distinguish one product or company
trademarks
the maximum tolerable data loss that an
organization can accept
RPO
the time from when the incident occurs to the point at which the business is back
RTO
the maximum time required to verify the integrity of a systems and data as they return the normal operation
work recovery time (WRT)
maximum amount of time in total that a process can be disrupted before the
business is no longer in business
MTD