Other stuff Flashcards
Identification -> Assessment -> Treatment -> Tracking -> Review. What’s this?
Risk management phases
What’s the annual loss expectancy?
Single loss expectancy x annual rate of occurrence
Name the 6 types of security controls.
Physical, technical, administrative. Preventive, detective, corrective
What’s MAC?
Mandatory access control - set by administrator
What’s DAC?
Discretionary access control - set by the user
What’s RBAC?
Role-based access control
What’s a standard?
Mandatory rules that must be followed
What’s a baseline?
Provides the minimum necessary security
What’s a guideline?
Flexible, but recommended
What’s a procedure?
Step-by-step guides
Promiscuous, Permissive, Prudent, Paranoid. Explain?
Promiscuous - wide open. Permissive - only block “known bad”. Prudent - block all “known bad”, but allow based on business needs. Paranoid - no bad at all!
Name 6 of the 9 vulnerability types.
Misconfiguration, Buffer overflow, Default installation, Unpatched, Open services, Default passwords, Design flaws, OS flaws, App flaws
What’s the CC?
Common Criteria for Information Technology Security Evaluation - an itnernational standard (SIO/IEC 15408)
What’s the EAL and how can it be ranked?
Evaluation Assurance Level - from 1 to 7
What’s the TOE?
Target of evaluation - what’s being tested