foundations Flashcards

1
Q

Security Mindset

A

Understand past and recent.
- How things work and can be made to fail

  1. Trust, but verify
  2. Stop. Think. Connect.
  3. If you see something, say something
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Business Email Compromise

A
  • attacker obtains access to a business email account and imitates the owner
  • man in the email attack
    Archetypes:
  • false invoice scheme
  • ceo fraud
  • account compromise
  • attorney impersonation
  • data theft
    Countermeasures
  • IDS rules to flag emails
  • email rules reply different from
  • color coding employee/internal vs external
  • payment 2-factor
  • confirmation requests 2-factor
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security Principles

A

Framework for all security programs.
-Economy of mechanism
-Fail-safe defaults
-Complete mediation
-Open design
-Separation of privilege
-Least privilege
-Least common mechanism
-User-friendly interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Economy of mechanism

A

Keep things small and simple
Complexity is an enemy of security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Fail-safe

A

Anticipate how things can go wrong
Fail smart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Least privilege

A

Minimum privileges needed to do a job

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Choke points and defense in depth

A
  • only one way in or out (choke point)
  • defense in depth (layers of security)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CIA

A

Confidentiality - Integrity - Availability
Confidentiality - who can see and read sensitive information
Integrity - limit who can change sensitive information
Availability - ensuring the information is there when we need it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Standard Organizations

A

-NIST
-ISO
-IEC
-PCI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly