Human Dimension Flashcards
Define protective security
The means to:
Mitigate risk that arise directly from the potentially harmful actions of people such as criminals, terrorists, hostile states, and malicious insiders
Security risks arise from?
Purposeful adversaries
What is security? (X2)
First duty of government and
basic human need
Security builds (x2)
Trust and confidence
Is security a common good?
Yes
What is risk?
Risk = threat x vulnerability x impact
Are security risks static monoliths?
No they are dynamic and adaptive - a system created by a human can be defeated by a human
Risk funnel top tier - what combine to make the threat?
threat actors intentions
threat actors capabilities
Risk funnel middle tier - what combine to make the likelihood?
Threat and
victims vulnerability
Risk funnel bottom tier - what combine to make the risk?
Likelihood of attack
Impact of attack
What are the main threat actors? (x7)
Terrorists (Islamist, NIRT, XRW)
Hostile foreign state actors
Criminals
Insiders
Hacktivists, script kiddies and other hackers
Political extremists and violence-prone protestors
Fixated individuals
Three stages in risk management cycle?
Understand the risks
Decide on how much risk to take
Act to reduce risks
Characteristics of good security? (x8)
• Risk based (and intelligence-led)
• Proportionate
• Well governed
• Holistic
• Regularly tested
• Well measured
• Layered
• Dynamic
What is an insider?
A person who exploits, or intends to exploit, their legitimate access for unauthorised purposes
Someone who betrays the trust of others by causing harm
Types of insider?
• Insiders may be third parties (e.g. contractors, suppliers)
• Insiders may be malicious or unwitting
• Insiders may be self-starters or cultivated by external threat actors (e.g. criminal or terrorist groups, hostile foreign states)