Intro Flashcards
what does CIA stand for in cyber security
Confidentiality, integrity and availability
Describe C in CIA
C stands for confidentiality. Need to make sure data is secure when it is stored, transmitted and when being processed
What are some key components of confidentiality in CIA
Need to make sure data is hidden and visible to authorize dusers
how can you enforce confidentiality
encryption - not making data available to unauthorized users.
describe I in CIA
Data must be accurate and complete and has not been modified
how is integrity enforced?
By hashes : summary or message of original data.- and comparing both hashes
Describe A in CIA
Availability: making sure data is available as and when required
what are violation of availability
damage web server or slow downs web server . slower down process times
how can availability be enforces
By redundancy: covering all bases - install multiple communication link so if some are affected you still have back ups
what does IAM stand for
Idetity and access management
what does IAAA stand for
identification, (name- not authentication), authentication ( proof who you are- ex. secret pin), authorization ( diff levels of access), accountability ( holder is accountable)
what is the I in IAAA
Identification: a subject claims and identity e. id badge, retina,
what is the first A in IAAA
Authetication: a subject prooves identity
ex. password, pin or metric data
what are the phases in an identity lifecycle
1st- provisioning - ex. new accounts
2nd review- periodic account reviews- ex. person moves up
3rc- revocation- disable accounts of employee who leaves
what are the types of authentication pass words
type 1- password, pin
type 2- mobile, sim , badge
type 3- something that you are- fingerprint, retina