1/60
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
cia
confidential, integrity, availibility
confidential
The fundamental security goal of keeping information and communications private and protecting them from unauthorized access.
integrity
means that the data is stored and transferred as intended, and any modification is unauthorized unless explicitly authorized through proper channels.
availability
means that information is readily accessible to those authorized to view or modify it.
Note:
nonrepudiation
The security goal of ensuring that the party that sent a transmission or created data remains associated with that data and cannot deny sending or creating that data.
hat a person cannot deny doing something, such as creating, modifying, or sending a resource.
nsit 5 functions
Identify—develop security policies and capabilities. Evaluate risks, threats, and vulnerabilities and recommend security controls to mitigate them.
Protect—procure/develop, install, operate, and decommission IT hardware and software assets with security as an embedded requirement of every stage of this operation's lifecycle.
Detect—perform ongoing, proactive monitoring to ensure that controls are effective and capable of protecting against new types of threats.
Respond—identify, analyze, contain, and eradicate threats to systems and data security.
Recover—implement cybersecurity resilience to restore systems and data if other controls are unable to prevent attacks.

security controls
A technology or procedure put in place to mitigate vulnerabilities and risk and to ensure the confidentiality, integrity, and availability (CIA) of information.
gap analysis
is a process that identifies how an organization's security systems deviate from those required or recommended by a framework.
IAM
A security process that provides identification, authentication, and authorization mechanisms for users, computers, and other entities to work with organizational assets like networks, operating systems, and applications. Also referred to as identity management (IdM), and access management.
identification
authentication
authorization
accounting
identification
The process by which a user account (and its credentials) is issued to the correct person. Sometimes referred to as enrollment.
authentication
A method of validating a particular entity's or individual's unique credentials.
proving that a subject is who or what it claims to be when it attempts to access the resource.
authorization
determining what rights subjects should have on each resource, and enforcing those rights.
accounting
Tracking authorized usage of a resource or use of rights by a subject and alerting when unauthorized use is detected or attempted.
security control
is designed to give a system or data asset the properties of confidentiality, integrity, availability, and non-repudiation. can be divided into four broad categories based on the way the control is implemented:
managerial
operational
technical
physical

managerial control
the control gives oversight of the information system. Examples could include risk identification or a tool allowing the evaluation and selection of other security controls.
operational control
the control is implemented primarily by people. For example, security guards and training programs
technical control
A category of security control that is implemented as a system (hardware, software, or firmware). may also be described as logical controls.
firewalls, antivirus software, and OS access control models
physical control
controls such as security cameras, alarms, gateways, locks, lighting, and security guards that deter and detect access to premises and hardware are often placed in a separate category from technical controls.
preventative
A type of security control that acts before an incident to eliminate or reduce the likelihood that an attack can succeed.
detective
A type of security control that acts during an incident to identify or record that it is happening.
may not prevent or deter access, but it will identify and record an attempted or successful intrusion
corrective
A type of security control that acts after an incident to eliminate or minimize its impact.
A good example is a backup system that restores data that was damaged during an intrusion.
directive
the control enforces a rule of behavior, such as a policy, best practice standard, or standard operating procedure (SOP).
deterrent
—the control may not physically or logically prevent access, but it psychologically discourages an attacker from attempting an intrusion. This could include signs and warnings of legal penalties against trespass or intrusion.
compensating
A security measure that takes on risk mitigation when a primary control fails or cannot completely meet expectations.
security policy
a formalized statement that defines how security will be implemented within an organization. It describes the means the organization will take to protect the confidentiality, availability, and integrity of sensitive data and resources.
CIO
Company officer with the primary responsibility for management of information technology assets and procedures.
CTO
Company officer with the primary role of making effective use of new and emerging computing platforms and innovations.
CSO
Typically the job title of the person with overall responsibility for information assurance and systems security.
ISSO (information systems security officer)
Organizational role with technical responsibilities for implementation of security policies, frameworks, and controls.
soc (security operations center)
The location where security professionals monitor and protect critical information assets in an organization.
devops
A combination of software development and systems operations, and refers to the practice of integrating one discipline with the other.
devsecops
A combination of software development, security operations, and systems operations, and refers to the practice of integrating each discipline with the others.
CIRT (computer incident response team)
Team with responsibility for incident response.
must have expertise across a number of business domains (IT, HR, legal, and marketing, for instance).
risk
is a measure of the likelihood and impact of a threat actor being able to exploit a vulnerability in your organization's security systems.
vulnerability
A weakness that could be triggered accidentally or exploited intentionally to cause a security breach.
threat
A potential for an entity to exercise a vulnerability (that is, to breach security)
threat actor attributes
internal/external
sophistication/capability
resources/funding
service disruption
A type of attack that compromises the availability of an asset or business process.
data exfiltration
The process by which an attacker takes data that is stored inside of a private network and moves it to an external network.
disinformation
A type of attack that falsifies an information resource that is normally trusted by others.
hacker
describes an individual who has the skills to gain access to computer systems through unauthorized or unapproved means
hacktivist
A threat actor that is motivated by a social issue or political cause.
ATP (advanced persistent threat)
Threat actors with the ability to craft novel exploits and techniques to obtain, maintain, and diversify unauthorized access to network systems over a long period.
nation state actors
A type of threat actor that is supported by the resources of its host country's military and security services.
unintentional insider threat
A threat actor that causes a vulnerability or exposes an attack vector without malicious intent.
shadow it
Computer hardware, software, or services used on a private network without authorization from the system owner.
attack surface
is all the points at which a malicious threat actor could try to exploit a vulnerability. Any location or method where a threat actor can interact with a network port, app, computer, or user
threat vector
A specific path by which a threat actor gains unauthorized access to a system.
vulnerable software
contains a flaw in its code or design that can be exploited to circumvent access control or to crash the process.
unsecured network
Configuration that exposes a large attack surface, such as through unnecessary open service ports, weak or no authentication, use of default credentials, or lack of secure communications/encryption.
lacks CIA
lure
An attack type that will entice a victim into using or opening a removable device, document, image, or program that conceals malware.
ex: removable devices, exe file, doc file, image file
message based vector
any features that allow direct messaging to network users must be considered as part of the potential attack surface. email, sms, im, social media, 0 click
supply chain
An attack that targets the end-to-end process of manufacturing, distributing, and handling goods and services.
procurement management
Supplier—obtains products directly from a manufacturer to sell in bulk to other businesses. This type of trade is referred to as business to business (B2B).
Vendor—obtains products from suppliers to sell to retail businesses (B2B) or directly to customers (B2C). A vendor might add some level of customization and direct support.
Business Partner—implies a closer relationship where two companies share quite closely aligned goals and marketing opportunities.
human vector
People—employees, contractors, suppliers, and customers—represent part of the attack surface of any organization.
social engineering
Using persuasion, manipulation, or intimidation to make the victim violate a security policy. The goal might be to gain access to an account, gain access to physical premises, or gather information.
pretexting
Social engineering tactic where a team will communicate, whether directly or indirectly, a lie or half-truth in order to get someone to believe a falsehood.
phishing
A email-based social engineering attack in which the attacker sends email from a supposedly reputable source, such as a bank, to try to elicit private information from the victim.
vishing-voice
smishing-sms
pharming
An impersonation attack in which a request for a website, typically an e-commerce site, is redirected to a similar-looking, but fake, website.
business email compormise
An impersonation attack in which the attacker gains control of an employee's account and uses it to convince other employees to perform fraudulent actions.
watering hole
An attack in which an attacker targets specific groups or organizations, discovers which websites they frequent, and injects malicious code into those sites.