SESSION 04: Policy Goal and Mechanisms Flashcards
1
Q
Three goals of cybersecurity?
A
- Protect data confidentiality
- Maintain data integrity
- Make data available to authorized users.
2
Q
CIA triad?
A
Confidentiality
Integrity
Availability
3
Q
What is confidentiality?
A
Keeping sensitive information secret and only available to authorized individuals.
4
Q
How to ensure confidentiality?
A
- User strong password
- Encrypt data
- Access control
- Secure communication
5 Regular updates - Provide proper training and awareness 7. Data minimization
5
Q
Tools for confidentiality?
A
- Encryption of data
- Data Masking
- Establish a confidentiality policy
- Authentication
5.Authorization - Access control
- Two-factor or multi-factor authentication
6
Q
What is Integrity?
A
Accuracy and consistency of data.
Ensures that information remains unaltered.
7
Q
How to ensure Integrity?
A
- Access control
- Data encryption
- Regular backups
- Data validation
- Version control
8
Q
Tools for integrity?
A
- Backups
- Data validation
- Checksums and hashing
- Audit trails
- Data correcting codes
9
Q
What is Availability?
A
Ensuring that information and resources are accessible and operational when needed.
10
Q
Tools for availability?
A
- Physically protection of data
- Disaster recovery plan
- Computational redundancy
- Failover
11
Q
What is Security mechanism?
A
A set of processes that handle recovery from security attacks.
12
Q
What are the types of security mehanisms?
A
- Encryption
- Access control
- Data Integrity
- Digital signature
- Bit stuffing