P1L1 Security Mindset Flashcards
What is of value that you are trying to protect from attackers?
data
What are the 2 kinds of companies?
- Companies that have been hacked and know it
2. Companies that have been hacked and DON’T know it.
Threat sources
Cyber criminals
Hacktivists
Nation States
Vulnerabilities and attacks
compromises
security breach
where are the vulnerabilities
software
networks
humans
CIA
Confidentiality
Integrity
Availability
Cyber attacks can have ________ consequences
physical
What should the good guys do?
Prevention Detection Response Recovery and remediation policy vs mechanism
Reduce vulnerabilities
Economy of mechanism–keep systems small and simple
Fail-safe defaults–means default access is denied
Complete mediation–no one should be able to bypass security measures
open design–no secrecy
Least privilege–minimum level of access needed
Psychological acceptability–don’t expect people to do what is inconvenient