security engineering 3rd edition Flashcards

1
Q

What is the focus of Security Engineering?

A

the use of tools, processes, and methods with a cyber-security lens

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 44 things necessary for a dependable system?

A

Policy
mechanis,
assurance
incentive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the concept of “security theater”?

A

The implementation of security measures that are visible, but less performant than other solutions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a subject?

A

a physical person in any role (operator, principal or victim)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a person?

A

a physical person, or a legal person such as a company or government

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

With regards to security systems, what is a principal?

A

an entity that participates in a security system. Could be a person, smartphone, laptop etc

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the distinction between groups and roles?

A

a group is a set of principals, and a role is a set of functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an example of someone who is trusted, but not trsutworthy?

A

An NSA agent selling information to a foreign agent. The NSA agent may be trusted with the secrets, but they are now trustworthy of the secrets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is secrecy?

A

the effect of mechanisms used to limit the number of principals access to information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is confidentiality?

A

An obligation to protect a persons secrets if they are known

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Privacy?

A

The ability to protect your personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is authenticity?

A

integrity plus freshness, so that a replay of previous messages does not have authenticity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Bruce Schneier’s definition of a hack?

A

An activity that a system’s rules permit, but which has unanticipated and unwanted effects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a vulnerability?

A

property of a system or environemnt which, in conjunction with an internal or external threat, can lead to a security failure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly