Week 1 Flashcards

1
Q

What are the 4 parts of the framework for cybersecurity and resilience?

A

Policy

Mechanism

Incentives

Assurance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Explain Policy

A

Specify objectives (Impact assessment, CIA, security levels)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Explain mechanism

A

Implement security measures (physical, technical, encryption, organizational, security architecture)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Explain Incentives

A

Motives for people (social engineering, fraud triangle, business model, risk appetite, proportionality)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Explain assurance

A

Confidence that measures are meeting objectives (regulatory supervision, audit, monitoring, forensics, learning)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Explain confidentiality

A

Confidentiality : Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Explain Integrity

A

Integrity : Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Explain Availability

A

Availability : Ensuring timely and reliable access to and use of information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Explain Auditability

A

Auditability: ensuring that evidence of all crucial transactions is stored reliably for auditing purposes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Difference between Information Security vs. Cybersecurity

A

Cybersecurity only concerns protection from threats that use cyberspace [narrower], and moreover, does not only cover information assets, but also physical assets, infrastructure, or social effects on society [wider].

Information security focuses on individual organizations; external risks are internalized. Cybersecurity looks at risks in the network as a whole.

Traditionally, information security focuses mostly on prevention, whereas cybersecurity focuses on resilience.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a cyber-physical system (CPS)?

A

A cyber-physical system (CPS) is a mechanism that is controlled or monitored by computer-based algorithms, tightly integrated with the Internet and its users. Many of these examples involve Internet of Things (RFID technology) as sensors and actuators.

Examples: smart grid, autonomous vehicles, medical monitoring, public transport, process control, robotics.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is resilience?

A

Resilience: ability of assets, networks and systems to anticipate, absorb, adapt to (i.e. respond) and/or recover from a disruptive event or incident (PAS 555, 2.25)

Resilience is hard to measure, because safety means absence of incidents, so there is no data available. Resilience is about the capacity or ability, to deal with the unforeseen. Resilience is about trade-offs, for instance between flexibility and redundancy and aspects like cost, environmental impact and risk reduction.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is business resilience?

A

Business resilience: level of resilience against cyber-attack commensurate with the services, its assessed risk, and risk appetite.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what is resilience preparedness?

A

Resilience preparedness: anticipation, assessment, prevention and preparation for recovery after an incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The total impact of an attack depends on the ability to: (name 4)

A
  • prepare: readiness
  • absorb: detect and respond to contain the damage
  • recover: get back to business
  • adapt: learn from mistakes (increase initial level of security)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly