Introduction Flashcards
Asset
An asset is any tangible or intangible thing or characteristic that has
value to an organization
Threat
A threat is a potential cause of an unwanted incident, which may result in harm to a system or organization
Adversary
An adversary is any person or a thing that acts (or has the power to act) to cause, carry, transmit, or support a threat
Safety vs. Security
Security is concerned with the risks originating from the environment and potentially impacting the system, whereas safety deals with the risks arising from the system and potentially impacting the environment
Attack vector
An attack vector is a path or means by which an attacker can gain access to a computer or network server in order to deliver a malicious outcome
Vulnerability
A vulnerability is a weakness of an asset (or control) that can be exploited
Software Vulnerability
A bug with security consequences
Exploit
An exploit is a method that identifies and takes advantage of a vulnerability in an asset
Attack
An attack is an attempt to destroy, expose, alter, disable, steal or gain
unauthorized access to or make unauthorized use of an asset
CIA Triad
Confidentiality, Integrity, Availability
Confidentiality
Confidentiality is the property that information is not made available or disclosed to unauthorized individuals, entities, or processes
Integrity
Integrity is the property of safeguarding the accuracy and completeness of assets
Availability
Availability is the property of being accessible and usable upon demand by an authorized entity
Countermeasure
A countermeasure (or control / safeguard) is used to minimize or eliminate the probability of a threat exploiting a vulnerability in an asset
Risk Mitigation
Risk mitigation is the process of taking actions to eliminate or reduce the probability of compromising the confidentiality, integrity, and availability of valued information assets to acceptable levels
Acess Control (AAA Principle)
Authentication, Authorization, Accountability
Authentication
Authentication is the provision of assurance that a claimed
characteristic of an entity is correct
Authorization
Authorization is a right or permission that is granted to a system entity
to access a system resource
Accountability
Non-Repudiation/Accountability is the ability to prove the occurrence of a claimed event or action and its originating entities