Review Flashcards
Review Lessons (3,4,5)
1
Q
Assurance
A
How trust is provided and managed
- policies (for people and systems)
- permissions (for agent that interact w/ system)
- protections (mechanisms to enforce policies/permissions)
2
Q
Authenticity
A
The ability to determine that statements, policies, and permissions issued by persons or systems are genuine.
Objective achieved via digital signatures. This is turn creates non-repudiation.
3
Q
Anonymity Methods
A
- Aggregation: combining of data from many individuals so that disclosed data not tied to any individual
- Mixing: intertwining of data in way that cannot be traced to individual
- Proxies: web proxy
- Pseudonyms: ficitonal identities
4
Q
10 Security Principles
A
- Compromise Recording (better to record than precent sometimes)
- Work Factor (commensurate countermeasure)
- Psychological Acceptability (make it easy to use/understand)
- Least Common Mechanism
- Fail Safe Defaults
- Economy of Mechanism
- Complete Mediation
- Separation of Privelege
- Open Design
- Least Privelege