Security Flashcards
What is the security triad?
C - Confidentiality means that resources are accessible only to authorized individuals.
I - Integrity means that resources should not be improperly changed
A - Availability, meaning that the resources are available when needed
What is a vulnerability?
Vulnerability is a weakness in a resource that exposes it to harm. Examples:
-Poor physical security
-Untrained users
-Improperly configured or installed hardware or software, design flaws
What is a threat?
Any event or action that could cause harm. Examples:
-Malware
-Attackers
-Employee mistakes
What is impact?
It’s the damage caused when the threat exploits the vulnerability. Examples:
-Data loss
-Financial loss
-Damage to the company’s reputation?
Risk
Is the probability or likelihood that a threat exploiting a vulnerability and the corresponding impact
Risk Appetite
Is the company’s comfort level regarding risk
Residual Risk
Is the risk left over when you’ve done everything that you’re going to do to address risks.
Risk Avoidance
When you abandon the risky behavior
Risk Mitigation
When you implement controls to reduce risk
Risk Transference
When you transfer the risk to a third-party and the classic example is insurance.
Risk Acceptance
When you continue the risky behavior without implementing controls