Security Concepts and Models C1 Flashcards
What does CIA stands for?
- Confidentiality
- Integrity
- Availability
What does AAA stands for
- Authentication
- Authorization
- Accounting
Security Management Process
- Identification
- Implementation
- Monitoring
What is Control?
Countermeasure put in a place to counteract security risks due to threat and attacks
What is Risk?
A concept that indicates exposure to the chance of danger.
What are Vulnerabilities?
Any condition that leaves a device open to harm such as:
1. Improperly configured software or hardware
2. Bugs in OS
3. Poor physical security
4. Weak and insecure passwords
5. Untested softwares
What is Threat
Any event or action that could potentially cause damage to an asset
Operations Vulnerabilities
- Untrained Users
- Lack of Planning for critical business processes
- System Sprawl
What are attacks
A technique used to exploit a vulnerability in an application or physical computer system
Risk Management
- Face the risk
- Avoid
- Transfer
Principle of Least Privilege
Users and software should have minimal level of access that is necessary for them to perform their tasks