Week 9 Flashcards
flow of information between a subject and object
jpresuello
Access
What is IA3?
jpresuello
Identification, Authentication, Authorization, Accountability
Entering public information is …..; Entering private information is …..;
jpresuello
identification; authentication
A flaw in software whereby actions can be preformed out of sequence
jpresuello
Race Condition
broad term that encompasses the use of different
products to identify, authenticate, and authorize users through automated means.
jpresuello
Identity Management
single database for user attributes
jpresuello
Directory
stores attributes from many sources in one location
jpresuello
Meta Directory
LDAP stands for
jpresuello
Lightweight Directory Access Protocol
One password used across multiple systems
jpresuello
Password Synchronization
Two types of biometric authentication
jpresuello
Physical and behavioral
Authorization Principles
jpresuello
Deny by Default and Principle of Least Privilege
Three primary authorization models
jpresuello
Object Capability, Security Labels, Access Control lists
A protocol for authenticating service requests between trusted hosts across an untrusted network
jpresuello
Kerberos
provisioning methodology that elevates users to the
necessary privileged access to perform a specific task.
jpresuello
Just in Time Access