Introduction- Security Concepts Flashcards
Primary 3 Goals of Network Security
Confidentiality
Integrity
Availability
Confidentiality
Encryption
Only Authorized Users can access assets
Integrity
No one modifies your information
Availability
Network must be available.
Physical Threats
Fire, water, earthquake
Electrical
Lack of Spare Parts
Poor cabling/labeling
Internal Threats
User has physical access and knowledge of the internal network.
Locks, Cameras, ID access, Data backups
Value Classifications. 5
Confidentiality Value Age Replacement Cost Useful Lifetime
Countermeasures 3
Administrative Controls
Physical Controls
Technical/Logical Controls
Administrative Control
Policy/Procedure
Training, Standards, change management, audits, background checks
Physical Controls
Security Guard, IDS, Locks, UPS, Fire Suppression
Vulnerabilities 4
Protocols
Operating Systems
Application
System Design
Network Security Policy
Rules for individuals and groups throughout the company
Access Control
Guide for Network security Engineer to configure, change, monitor, Log, and respond to attacks
Network Segmentation
Separate network by where devices are physically connected as well as VLANs
Group assets of the same type, value, security level, or risk level
Separation of Duties
No single individual has the capability to execute a set of tasks
More than one person required to complete a task
Weakest Link
Humans are the weakest link
Weak passwords or humans kindness attacks