principles of security Flashcards

1
Q

confidentiality (triad)

A

protection of data from unauthorized access and missuse

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

integrity (triad)

A

condition where data is kept accurate and consistent unless authorized changes are made

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

availability (triad)

A

data is available and accessible to authorized users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

threat modelling

A

process of reviewing, improving, and testing security protocols in place at organization’s information technology infrastructure/services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

an effective threat model includes

A

threat intelligence
asset identification
mitigation capabilities
risk assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Incident Response

A

IR
*steps taken to resolve/remediate the effects of an incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

incidents are classified..?

A

using rating of urgency/impact
*urgency determined by attack type
*impact determined by affected system and repercussions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CSIRT

A

comp sec IR team
*pre-arranged group of employees with knowlege of systems/current incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

six phases of incident response

A

preparation
identification
containment
eradication
recovery
lessons learned

How well did you know this?
1
Not at all
2
3
4
5
Perfectly