Lecture 2 - Foundations of Security Flashcards
3 Protection Measures
Prevention
Detection
Reaction
What is Security
Protection of Assets
What is a Security Policy
Document explaining what is protected and how it is protected.
CIA Concept
Confidentiality - Prevent information disclosure
Integrity - Prevent information modification
Availability - Prevent information witholding
Non-repudiation
Un-forgeable evidence
What is a Covert Channel
Carefully chosen queries that can narrow down
who has what conditions
Good security design principals
• Focus of control - Data ? User ?
• The man-machine scale - Which Layer. OS? Hardware?
• Complexity vs. Assurance - simple approach high assurance?
• Centralised or Decentralised Controls - focuesed on one layer or several
• Layer Below - A good security layer built upon an insecure
layer is useless