Domain 1 - Security and Risk Management Flashcards
1
Q
DAD (CIA Triad Alternate)
A
Disclosure, Alteration, Distruction
2
Q
DAD - Disclosure
A
CONFIDENTIALITY. Unauthorized release of information
3
Q
DAD - Alteration
A
INTEGRITY. Unauthorized modification of information
4
Q
DAD - Destruction
A
AVAILABILITY. Making systems or data unavailable
5
Q
Non-Repudiation
A
- User cannot deny having performed a transaction
- Combines authentication and integrity
- Digital signatures
6
Q
Least Privilege
A
Users should be granted the minimum amount of access (authorization) required to do their jobs, and no more
7
Q
Need to Know
A
- More granular than least privilege
- User must NEED TO KNOW that specific piece of information
8
Q
Subject
A
An active entity on a system
- People accessing files
- Computer programs that update information
9
Q
Object
A
Any PASSIVE data within a system
- Documents (physical) or electronic records
- Database tables
- Text files