Lecture 6 - Risk Flashcards

1
Q

What is the balance between security and cost?

A

We need to keep the data secure, but cannot lock everything down that it becomes impossible to use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the balance between monitoring and anonymity?

A

The more we monitor, the less we allow for anonymity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the process for risk managment?

A

Risks should be recognised and assessed, and mechanisms should be put in place to mitigate those risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is information assurance?

A

Things to make sure the info we have is trustworthy
(measures to protect and defend info and info systems by ensuring their integrity, authentication, confidentiality and non repudiation.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is information protection?

A

The mechanisms to make sure the info is safe

Protection of info from unauthorised access, use, disclosure, disruption or modification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is some of the NCSC’s advice?

A
  • Accounts with admin privilege should only be used to complete admin tasks
  • Staff accounts should have only just enough access to complete their role
  • Only use software from official sources
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are preventative controls?

A

Intended to stop an incident from occuring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are detective controls?

A

Intended to identify and characterise an incident in progress

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are corrective controls?

A

Intended to limit the extent of any damage caused by an incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are ISO/IEC 27001 standards?

A

They are a broad, evolving set of standards designed to ensure info sec is under management control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What happens without the ISO/IEC standards?

A

Without this, controls tend to be lots of different and incoherent systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does component driven management focus on?

A

It focuses on technical components, and the threats and vulnerabilities they face

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What does system driven management focus on?

A

It focuses on the systems as a whole

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are characteristics of system driven management

A
  • Good for large systems
  • Can be time consuming and expensive
  • May not be appropriate in certain circumstances
How well did you know this?
1
Not at all
2
3
4
5
Perfectly