Physical Security & Stuff Flashcards
a measure of the likelihood that a biometric security system will incorrectly accept an access attempt by an authorized user
FAR
a measure of the likelihood that a biometric security system will incorrectly reject an access attempt by an authorized user
FRR
a type of metric used for the evaluation of a biometric security system’s accuracy. Lower values mean more accurate biometric systems
CER
valid for only one login session, based on a cryptographic hash function and a secret cryptographic key, not vulnerable to replay attacks
HOTP
based on a shared key and the current time, not vulnerable to replay attacks, valid for only one login session
TOTP
Examples of implementation methods for certificate-based authentication
PIV card, CAC, IEEE 802.1X
an account policy that forces users to come up with a new password every time they are required to change their old password
Password history
a key document governing the relationship between two business organizations
BPA
an agreement between a service provider and users defining the nature, availability, quality, and scope of the service to be provided; an agreement that specifies performance requirements for a vendor
SLA
a type of agreement that documents technical and security requirements of the interconnection between the organizations that own and operate connected IT systems
ISA
general documents established between two or more parties to define their respective responsibilities and expectations in accomplishing a particular goal or mission
MOU & MOA