Question set 1 Flashcards
- What is the CISSP Triad?
-CIA = 1. Confidentiality 2. Integrity 3. Availability
- Definition of Confidentiality
Ensures that information is not compromised or shared amongst unauthorized participants
- Definition of Integrity
Ensures that data is not damaged or modified while either in transit or storage
- Definition of Availability
Ensures that information is always available at the time authorized users need it
- What are the 3 times data is secured?
- In storage 2. In process 3. In transit
- General categories of controls
Administrative, technical, and physical
- Types of controls
Preventative, Deterrent, Corrective, Recovery, Detective, Directive, Compensation
- Preventative control
stop attack before beginning. Ex: firewalls, fence
- Deterrent control
discourage someone from trying. Ex: warning sign
- Corrective control
attack begins, but stops before damage occurs
- Recovery control
attack happens and causes damage, but control reverses damage
- Detective control
-detects attack but doesn’t do anything about attack
- Directive control
procedures to follow. Normally an administrative control
- Compensation control
No real control, but reaction after attack happens. Ex: insurance, lawyers
- What are some good operation security practices?
-separation of duties, job rotation, need to know, least privilege, personnel security, mandatory vacations, job action warnings or termination