Domain 5: Identification and Authentication Flashcards
Subject
Active Entity
Object
Passive Entity
Three Primary Control Types of Access Controls
Preventative, Detective, and Corrective
4 “Other” Control Types of Access Controls
Deterrent, Recovery, Directive, Compensating
Preventative Controls
attempts to stop and unwanted activity
Detective Controls
discover activity after the fact
Corrective Controls
modify environment to return to normal
Deterrent Controls
discourage unwanted activity
Recovery Controls
repair or restore resources, more complex than corrective
Directive Controls
direct the actions of subjects to force compliance
Compensating Controls
alternative when the primary control doesn’t work
Three Types Of Controls (based on how they are implemented)
Administrative, Logical/Technical, Physical
Identification
process of a subject claiming an identitiy
Authentication
verifies the identity of the sybject
Authorization
Subjects are granted access to objects based on idenitity
Accountability
provided through auditing
Type 1 Authentication Factor
Something you know
Type 2 Authentication Factor
Something you have
Type 3 Authentication Factor
Something you are or do
Cognitive Password
Series of questions
Synchronous vs Asynchronous Dynamic Password
Synchronous is time based (changes every 60 seconds(, Asynchronous changes after it is used
Type 1 Error
valid subject is not authenticated, false rejection