Memorization Flashcards
Data Lifecycle
- Create - classify
- Store
- Use
- Share
- Archive
- Destroy
Manage Data Life Cycle
- Collection
- Location
- Maintenance
- Retention
- Remance
- Destruction
Cyber Kill Chain
Reconnaissance
Weaponization
Delivery
Exploit
Installation
Command & Control
Actions
Incident Response
Preparation
Detection
Response
Mitigation / Containment
Reporting
Recovery
Remediation
Lessons Learned
Software Delivery Life Cycle
Initiation
Requirements
Architecture / Design
Development
Testing
Release / Deployment
Operation
Disposal
Common Criteria Evaluation Assurance Levels
Greatest to least assurance.
7 - Formally verified, designed, and tested
6 - Semi-formally verified, designed, and tested
5 - Semi-formally designed and tested
4 - Methodically designed, tested, and reviewed
3 - Methodically tested and checked
2 - Structurally tested
1 - Functionally tested
ISC2 Code of Ethics Canons
- Protect society, the common good, necessary public trust and confidence, and the infrastructure.
- Act honourably, honestly, justly, responsibly, and legally.
- Provide diligent and competent service to principals.
- Advance and protect the profession.
ISC2 Code of Ethics Canons
- Protect society, the common good, necessary public trust and confidence, and the infrastructure.
- Act honourably, honestly, justly, responsibly, and legally.
- Provide diligent and competent service to principals.
- Advance and protect the profession.
Risk assessment or risk analysis
The examination of an environment for risks, evaluating each threat event as to its likelihood of occurring and the severity of the damage it would cause if it did occur, and assessing the cost of various countermeasures for each risk.
Risk response
Evaluating countermeasures, safeguards, and security controls using a cost/benefit analysis; adjusting findings based on other conditions, concerns, priorities, and resources; and providing a proposal of response options in a report to senior management.
Single Loss Expectancy (SLE)
SLE = Asset Value (AV) * Exposure Factor (EF)
SLE = $ * %
Annualized Loss Expectancy (ALE)
ALE = Single Loss Expectancy (SLE) * annualized rate of occurrence (ARO)
or
ALE = AV * EF * ARO
Cost / Benefit Equation
[ALE pre-safeguard – ALE post-safeguard] – annual cost of safeguard (ACS) = value of the safeguard to the company
Risk Management Framework
Prepare
Categorize
Select
Implement
Assess
Authorize
Monitor
STRIDE
Spoofing
Tampering
Repudiation
Information Disclosure
Denial of Service (DoS)
Elevation of privilege