security engineering 3rd edition Flashcards
What is the focus of Security Engineering?
the use of tools, processes, and methods with a cyber-security lens
What are the 44 things necessary for a dependable system?
Policy
mechanis,
assurance
incentive
What is the concept of “security theater”?
The implementation of security measures that are visible, but less performant than other solutions
What is a subject?
a physical person in any role (operator, principal or victim)
What is a person?
a physical person, or a legal person such as a company or government
With regards to security systems, what is a principal?
an entity that participates in a security system. Could be a person, smartphone, laptop etc
What is the distinction between groups and roles?
a group is a set of principals, and a role is a set of functions
What is an example of someone who is trusted, but not trsutworthy?
An NSA agent selling information to a foreign agent. The NSA agent may be trusted with the secrets, but they are now trustworthy of the secrets
What is secrecy?
the effect of mechanisms used to limit the number of principals access to information
What is confidentiality?
An obligation to protect a persons secrets if they are known
What is Privacy?
The ability to protect your personal information
What is authenticity?
integrity plus freshness, so that a replay of previous messages does not have authenticity
What is Bruce Schneier’s definition of a hack?
An activity that a system’s rules permit, but which has unanticipated and unwanted effects
What is a vulnerability?
property of a system or environemnt which, in conjunction with an internal or external threat, can lead to a security failure