Secure design Flashcards

1
Q

What does CIA stand for?

A

confidentiality, integrity, and availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the CIA triad?

A

The CIA triad is a foundational model that helps inform how organizations consider risk when setting up systems and security policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does confidentiality mean?

A

Confidentiality means that only authorized users can access specific assets or data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Give an example of confidentiality

A

For example, strict access controls that define who should and should not have access to data, must be put in place to ensure confidential data remains safe.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does integrity mean?

A

Integrity means the data is correct, authentic, and reliable.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do security professionals maintain integrity?

A

To maintain integrity, security professionals can use a form of data protection like encryption to safeguard data from being tampered with.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does availability mean?

A

Availability means data is accessible to those who are authorized to access it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an asset?

A

An asset is an item perceived as having value to an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is value determined by?

A

value is determined by the cost associated with the asset in question.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Give an example of an asset

A

For example, an application that stores sensitive data, such as social security numbers or bank accounts, is a valuable asset to an organization. It carries more risk and therefore requires tighter security controls in comparison to a website that shares publicly available news content.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does NIST CSF stand for?

A

National Institute of Standards and Technology: The Cybersecurity Framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the NIST CSF?

A

It is a voluntary framework that consists of standards, guidelines, and best practices to manage cybersecurity risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why is it important to become familair with the NIST CSF?

A

Security teams use it as a baseline to manage short and long-term risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what are some of the most dangerous threat actors to consider?

A

disgruntled employees because they often have access to sensitive information and know where to find it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How do security professionals reduce the risk of disgruntled employees?

A

n order to reduce this type of risk, security professionals would use the principle of availability, as well as organizational guidelines based on frameworks to ensure staff members can only access the data they need to perform their jobs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly