P1:L1 The Security Mindset Flashcards

1
Q

Why Security?

A

We worry about security when we have something of value and there is a risk that it could be harmed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why Cyber Security?

A
  • Individuals store a lot of sensitive data online
    • If stolen, criminals can profit from it.
  • Societies rely on the internet
    - Nefarious parties could profit by controlling it
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why Cyber Security?

A

Smart grids rely on cyber systems
-Whoever controls the grid controls the community infrastructure

Business and government propriety information is often stored on the internet.
-Unauthorized access could be economically or politically disasterous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

There are 2 kinds of companies…

A

those that have been hacked and know it

and those that have been hacked and don’t know it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the security mindset

A

Who are the bad actors, what could they exploit… what will that attack be?
Threat source: who wants to do harm to us in our online lives?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Cybercriminals

A

they want to profit from our sensitive data for financial gain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Hacktivists

A

Activists who do not like something you are or something you do

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Nation-states

A

Countries do it for political advantage or for espionage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Threat actors

A

exploit vulnerabilities to launch attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Attacks

A

lead to compromises or security breaches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Vulnerabilities

A

can be found in software, networks, and humans (weakest link)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Questions to ask when in the security mindset?

For example… when Target was “breached”

A

1) what is of value? (Credit card data)
2) What is the threat source? (Cyber Criminals)
3) What vulnerability was exploited? (Phishing attack)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Hacked/stolen data worth on the black market (as of March 2015):

A

1) 3 digit security code on your credit card = $2
2) Credit card information = $5 - $45
3) PayPal/Ebay account = $27
4) Health information = $10

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

3 security requirements of sensitive information to strive for

A

1) Confidentiality (sensitive… should not be disclosed - only to authorized)
2) Integrity (Should not be changed or corrupted only to authorized)
3) Availability (Critical to use… if it goes away or can not be accessed… this is bad)

The CIA :-)\other conseqences (Stuxnet, physical)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What security requirement is violated in a “data breach?”

A

Confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What should the good guys do?

A
  • Prevention
  • Detection
  • Response
  • Recovery and remediation
  • Policy (what) vs. mechanism (how)
17
Q

What is the estimated value of the world-wide losses due to cybercrime?

A

Close to $500 Billion (US) as of 2014

18
Q

How do we address Cyber Security?

By reducing vulnerabilities by following basic design principles for secure systems:

A
  • complexity is the enemy (keep it simple (enemy of mechanism))
  • Fail-safe defaults (access is controlled
  • Complete mediation (System should never allow someone to bypass the monitor)
  • Open design (Don’t count on a complex design or for one person to know… someone could easily reverse engineer)
  • Least Privilege (Only have privileges for resources that you absolutely need)
  • Psychological acceptability (People are the weak link… don’t ask people to do anything that puts burden on them)