Perspektiv på IT och säkerhet

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/26

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:46 PM on 6/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

27 Terms

1
New cards

Three perspectives (information security)

- Society

- Organizations

- Individuals

2
New cards

BCP priorities

1. Safety

2. Continuity of critical business operations

3. Continuity of components

3
New cards

DRP

1. Threat analysis

2. Impact scenarios

3. Recovery requirement documentation

4
New cards

Disaster recovery steps

1. Ensure everyones safety

2. Respond to the disaster before recovery

3. Follow DRP

5
New cards

Validating DRP

- Checklist test

- Structured walk-through

- Simulation test

- Parallel test

- Full interruption test

6
New cards

Risk factors (of attack)

1. Outdated software and systems

2. Human error and lack of training

3. Weak passwords and poor access control

4. Unsecure networks and IoT devices

7
New cards

Best practices (to prevent attacks)

- Regular software updates

- Multi-factor authentication

- Network segmentation

- Secure backups

- Endpoint protections and firewalls

8
New cards

Evidence types (forenscics9

- Real evidence (physical)

- Documentary evidance

- Testimonial evidence

- Demonstrative evidance

9
New cards

Types of computer crimes

- Identity theft

- Exfiltrating data

- Cyberstalking/harassment

- Online fraud

- Nonaccess computer crimes

- Cyberterrorism

10
New cards

Forensic methodologies (principles)

- Minimize original data handling

- Enforce the rules of evidence

- Do not exceed your knowledge

- Develop an analysis plan first

- Consider data volatility

11
New cards

DFIM - Digital Forensic Invstigation Model

- Acquiring evidence

- Authenticate evidence

- Analyzing evidence

12
New cards

DFRWS - Digital Forensic Research Workshop

- Identification

- Preservation

- Collection

- Examination

- Analysis

- Presentation

13
New cards

ADFM - Abstract Digital Forensic Model

- improved DFRWS

- Added Preparation, Approach strategy and Return of Evidence

14
New cards

CERIAS - Center for education and research in information assurance and security model

- The Readiness phase

- Operations Readiness

- Infrastructure Readiness

- The Deployment Phase

- Detection and notification

- Confirmation and authorization

- The Physical crimes scene investigation Phase

- The Digital crime scene investigation Phase

- The Presentation Phase

15
New cards

EU-förordningar

- GDPR

- NIS/NIS2

- Ai-förordningen

- CER-direktivet

- CRA

- CSL - Cybersäkerhetslagen

- DORA-förordningen

16
New cards

Threats

- Humans, Tech, Nature

- Internal + external

- Intentional + unintentional

- Directed + undirected

17
New cards

Aktörer (motiv)

- Stater + statsunderstödda aktörer

- Extremiströrelser

- Hackergrupperingar

- Terroristorganisationer

- Ensamagerande

- Insiders

18
New cards

NIST cybersecurity framework (CSF)

- Govern

- Identity

- Protect

- Detect

- Respond

- Recover

19
New cards

Digital kryptering

- TLS

- HTTPS

- VPN

- DNSSEC

- SIMIME

- WPA2 + WPA3

20
New cards

System Card

1. Cyberkapacitet

2. Biologi och kemi

3. Agentiskt riskbeteende

4. Strategisk manipulation

5. Aggresivt affärsbeteende

21
New cards

Vad gör LLM bra på sårbarhetsforskning?

1. Verifierarens lag

2. Agentisk loop

3. Reasoning + execution

22
New cards

Nya hot

- Patch paradoxen skärps

- Disclosure modellen skärps

- Industriell exploit-produktion

- Sandbox-breakout + spårdöljning

- Vendor Fatigue

23
New cards

God praxis

- Real time vulnerability response

- Defensiv AI i lockstep

- Anta att patchen är advisory

- Cyber essentials först

- Hot modellering för AI-assisterad angripare

- Responsible disclosure under press

24
New cards

Sic accepted bases for processing (data protection)

- Consent (strictest basis, allows people to withdraw)

- Performance of a contract

- Compliance with a legal obligation

- Protect the vital interest

- Legitimate interest (greatest latitude)

25
New cards

Recipratory effects

- The individual effects

- The Dyadic effect

- Social Perception

- Mutuality

- Congruence

- Accuracy

26
New cards

Taxonomy for risk assessment

- Assets

- Cyber

- Cyber physical

- Physical

- Risk management

- Threat

- Vulnerabilities

- Controls

- Attacker motivation

- Political

- Socio-cultural

- Economic

- Thrill seeking

27
New cards

7 domains of IT infrastructure

1. User domain

2. Workstation

3. LAN

4. LAN-to-WAN

5. WAN

6. Remote Access

7. System/Application