Security Concepts Flashcards
Principle of least privilege
Give people access to only the bare minimum resources needed to do their job. Requires segmenting resources appropriately from the beginning.
Need-to-know
Requires a person to have both the proper authority to access resources and a valid need to do so.
Segregation of duties (SOD)
A security mechanism that prevents a single role from having too much power.
Criticality
The impact that the loss of an asset will have or how important the asset is to the business.
Sensitivity
The impact that unauthorized access will have.
Assurance
Managing security risks by keeping vulnerabilities and threats to an acceptable level.
Total Cost of Ownership (TCO)
The true cost to own an asset: original cost, upgrades, maintenance, support, training…