Exam 1 Flashcards
Which security principle is opposite of disclosure? A) integrity B) availability C) confidentiality D) authorization
Confidentiality
Opposite of corruption?
Integrity
Opposite of destruction?
Availability
Opposite of disapproval?
Authorization
Security policy
Administrative control
CCTV and locks
Physical control
Data backups
Technical control
What is a vulnerability?
An absence or weakness of a countermeasure that is in place
Threat?
Vulnerability is identified or exploited
Threat agent?
Entity that carries out a threat
Exposure?
Organizational asset exposed to losses
Countermeasure or safeguard?
Control that reduces risk
Examples of technical threats?
Hardware/ software failure
Malicious code
New technologies
Human threat agents?
Malicious and non malicious insiders and outsiders
Terrorists
Spies
Terminated personnel
Natural threat agents?
Floods Fires Tornadoes Hurricanes Earthquakes Other natural disaster or weather event
Environmental threat agents?
Power or utility failure
Traffic issues
Biological warfare
Hazardous material issues
SLE?
Single-Loss expectancy. Monetary impact of threat occurrence.
ARO
Annualized rate of occurrence. How often a threat may occur annually.
ALE
Annual lose expectancy. Expected risk factor of an annual threat event
EF
Exposure Factor. Percent value or or functionality loss after threat event
Advisory security policies?
Instruction on acceptable and unacceptable activities.
Informative security policies?
Provide info on topics and act as educational tool.
Regulatory security policies?
Address specific industry regulations, including mandatory standards.
System-specific security policies?
Address security for a specific computer, network, technology, or application.