Introduction to Security Flashcards
-Describe the challenges of securing information. -Define information security and explain why it is important. -Identify the types of attackers that are common today. -List the basic steps of an attack. -Describe the five basic principles of defense.
The three protections that must be extended over information are :
Hint : CIA
Confidentiality : It is important that only approved individuals are able to access important information.
Integrity : Intergrityensures that the information is correct and on unauthorized person or malicious software has altered the data.
Availability : Availability ensures that the data is accessible to authorized users.
Set of protections that must be implemented to secure information.
Hint : AAA
Authentication : Authentication ensures that the individual is who she claims to be and not an imposter.
Authorization : Authorization is providing permission or approval to a specific technology/space.
Accounting : Accounting provides tracking of events.
Information Security Ranking Layers
Information
- CIA
- Hardware, Software, Communication
- Products ( Physical Security )
- People ( Personnel Security )
- Procedures ( Organizational Security )
Threat
A type of action that has the potential to cause harm.
Threat Agent
A person or element that has the power to carry out a threat.
Vulnerability
A flaw or weakness that allows a threat agent to bypass security.
Threat vector
The means by which an attack could occur.
Threat likelihood
The probability that a threat will actually occur.
Risk
A situation that involves exposure to danger.
How is Risk Calculated?
Risk = Consequence * Vulnerablility * Threat Likelihood
Risk Avoidance
Identifying the risk and making the decision to not engage in the activity.
Acceptance
Acknowledging a risk but taking no action to address it.
Mitigation
Addresing a risk by making it less serious.
Deterrence
Understanding the attacker and then informing him of the consequences of the action.
Transference
Transferring the risk to a third party.