Module 1: General Security Concepts Flashcards
What is a vulnerability?
A weakness.
What is a threat?
A potential danger.
What is an exploit?
When a threat actor successfully takes advantage of a vulnerability.
What is a threat actor?
An adversary with malicious intent.
What are controls?
Tactics, mechanisms, or strategies that proactively minimize risk in one or more ways.
In what ways do controls proactively minimize risk? (Hint: 3 ways)
Reduce/eliminate vulnerabilities; reduce/eliminate the likelihood of vulnerability exploitation by threat actors; reduce/eliminate the impact of an exploit
What are countermeasures?
Controls implemented to address specific threats.
Controls are ______ and countermeasures are _______.
Proactive/Reactive
Countermeasures are ______ effective but ______ broadly efficient.
More/Less
Controls should be ________.
Verifiable (trustworthy)
What is control functionality?
What a control does.
What is control effectiveness?
How well a control works.
What makes up “effectiveness” for a control?
Consistent, complete, reliable, timely operation.
What is control assurance?
A measure of confidence that intended security controls are effective in their application.
What is a control objective?
A statement of desired result/purpose to be achieved.
What is Defense-in-Depth also known as?
Layered security or layered controls.
What is Defense-in-Depth/layered security?
The design and implementation of multiple overlapping layers of diverse controls.
Controls should not be subject to __________ and should maintain _______.
A cascade effect/independence
Diversity in controls refers to what?
Type(s) of controls and associated vendor(s).
What is a security control baseline?
The minimum standard for a given environment.
Control baselines must strategically align with what?
The needs of the organization.
Control baselines are what?
A starting point.