Domain 3 Flashcards
Entity that requests access to assets.
Is a user, a process, a procedure, a
client (or a server), a program, or a
device.
Requests a service from an object.
Subject
A device, process, person,
user, program, server, client, or other
entity that responds to a request for
service.
Anything that provides service to a user.
A building, a computer, a file, a
database, a printer or scanner
Object
To allow or deny access to an object by comparing the validated identity of the subject to an access control list.
Allow access to an object.
How much access is allowed.
Rules
An information security strategy that integrates people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of the organization.
Defense in depth
Each user is granted access to only the items they need and nothing further.
Least Privilege
Granted to a person, subject or group but not to others.
To create, read, update and delete.
Privileged Access Management
Beyond normal users like managers and administrators.
To have greater control over data and applications.
Privileged Accounts