1/50
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
data integrity (A. Edris)
the accuracy, consistency, and trustworthiness of data across its entire lifecycle.
Technical Controls (Tonye E.)
Written and implemented by the information technology (IT) team; firewall settings, antivirus/antimalware, screensaver/login policies, IDS/IPS
Most Secure Storage Option(Nate E)
Network storages systems like RAID, SAN, NAS
Deterrent Controls (Tonye E.)
Splash screen, demotion, warning signs, reception desks
Protecting availability of data in transit (Nathan Kim)
Implement mutual authentication systems to counter hijackers.
This makes sure the users device can tell when it is being contacted or receiving data requests from attackers.
Storage Area Network (SAN) - (J Victoria)
A network-BASED storage system that connects multiple servers to a centralized storage repository.
Sneaker Net - (J Victoria)
Using removable media to transfer data between hosts.
Detective controls(Jayden E.)
Does not prevent an intrusion but will identify/record any intrusion attempts
ex: Login reports or motion detectors
Direct-Attached Storage (DAS) - (J Victoria)
A hard drive or USB flash drive that is directly connected to a host.
Direct-Attached Storage (DAS) Challenges (Liza N.)
-->vulnerable to malicious attacks on local host
--> one of the most difficult types of data storage to manage/control
Network Attached Storage (NAS) - (J Victoria)
A network-CONNECTED storage device that allows both storage and retrieval of data from a centralized location by authorized users.
Protecting confidentiality of data in transit (Camden Buchacz)
Cybersecurity personnel must follow steps to encrypting data for transit. Ex. VPNs, SSL, and IPsec.
Hardware BASED technology examples (Tyler S)
Firewalls
Proxy servers
Hardware-based access controls
Network Switches
Data in storage definition (Prajwal S.)
A method of recording and saving data on either a device or in the cloud.
NIST Attack Vector(Eesa.F)
A way that hackers can use to get past security and enter a computer, network, or an app.
Examples : Web, Email, Theft, Impersonation, Media, or Attrition.
Redundant Array of Independent Disks (RAID) - (J Victoria)
A professional storage solution that combines multiple disks for the operating system to see it as a single disk.
Incident response stakeholders examples (Jason C.)
- Management
- IT support
- legal department
- human resources
- public affairs and media relations
Ways to Insure Availability (Jason C.)
- Equipment maintenance
- backup testing
- disaster planning
- activity monitoring
- availability testing
Data At Rest (Najeem S.)
the state when no user is accessing, repeating, or ammending the data.
data is not being proccessed or moved.
Software firewalls (Arnav K)
-control remote access to systems
-OS's normally have these
-Users can download/purchase third party
-Ex: Windows Defender
protocol analyzers (Arnav K)
*signature analyzers*
-monitor and stash info on internet traffic
-signify problems in performance, config's, and applications
-establishes traffic patterns
-debugs communication issues
Host-Based intrusion detection systems (Arnav K)
-host system activity
-sends alarms and note down files
-used in sensitive/crucial storing systems
-Ex: OSSEC
vulnerability scanners (Arnav K)* (pls be more specific on definition)
assesses weak spots on networks and computers
Network and port scanners (Arnav K)
They find and keep an eye on available ports on hosts or servers
Post-Incident Activities (Favour A)
The final phase of incident response where a team analyzes a past cyber incident and plan/implement prevention methods to defend against such an incident in the future.
Cyber security Cube principles(M. Ksit)
Goals ; CIA Triad, Confidentiality(If your data stays encrypted), Integrity(If your data stays the same), Availability(if you can get your data when you need it)
Protecting integrity of data in transit examples (Spencer McMillan)
Hashing, data validation checks, data consistency checks and access controls
Corrective Controls (Eesa.F)
Restorative measures that restore the system after a disaster or an event.
Examples: Data Backup, Recovery Systems, and Incident Response Plan
Examples of compnesative controls are... (Avanish P.)
- Security policies
- Personal Supervision
- Monitoring and work task procedures that substitutes a missing ideal control.
NIST Incident Response step 1 (Daniel P)
Preparation - prepare an organization for potential attacks, such as defining incident response policies and training employees to respond to an attack.
NIST incident response life cycle phase 3rd step (Shemmy T)
Containment: isolate and shut off affected devices and block incoming traffic from those devices
Eradicate: Delete malware and patch vulnerabilities
Recovery: Restore data using available backups and turn on any clean devices.
Information Rights Management (IRM) (Tyler J.)
way to ensure confidentiality of an email or file by allowing a document owner, organization, or one of its members to control or manage access to a document.
Things that accomplish a comprehensive Security Policy (J. Logatoc)
- demonstrates an organization's commitment to security.
- sets the rules for expected behavior.
- ensures consistency in system operations and software and hardware acquisition, use, and maintenance.
- defines the legal consequences of violations.
- gives security staff the backing of management.
Digital Rights Management (DRM) (Tyler J.)
way to ensure confidentiality by protecting copyrighted digital media, such as music, films, or books.
Remote Access policy ( Bright A)
-how remote users access a network
-what is accessible from remote locations.
Tokenization (Tyler J.)
Type of way to ensure confidentiality by using a substituting technique that isolates data from exposure to other systems. Uses random value to replace original data.
Cybersecurity Cube Safeguards (J. Logatoc)
Software firewalls, Network/port scanners, protocol analyzers, vulnerability scanners, host-based intrusion detection systems (IDS)
Identification and Authentication Policy ( Bright A)
-authorized persons that can access network resources
-verification procedures
NIST incident response life cycle phase 2nd step (Akriti O)
- detection and analysis
- CSIRT constantly monitoring to identify, analyze, and confirm
- organizations need to be prepared for any incident
- best to focus on common attack vectors
Acceptable Use Policy (Bright A)
-identify network resources that are acceptable to the organizations
-scalable consequences for policy violation
what are some Examples of Software Safeguards? (Arnav K)
-Software firewalls
-network and port scanners
-protocol analyzers
-vulnerability scanners
-host-based intrusion detection systems (IDS)
Cybersecurity Cube Data States (Eddy J.)
Data in transit, Data at rest, Data in process
Security Policy (Bright A)
- displays the security objectives
- expected behavior and required system conditions that members must follow
Ways to establish culture of Cybersecurity awareness (Julian T)
Education and training (implementing security awareness training), and security awareness programs
Physical control examples (Shemmy T)
Door locks, Warning signs, Motion detector, Power generator, Sign: "Authorized Personnel Only"
Administrative control examples (Nikan B)
-File storage policies
- Compliance policies
- Security Policy training
- Sign: Authorized personel only
NIST Attack Evidence Examples (Yasser B)
- Location of the recovery and storage of all evidence
- Identifying criteria for all evidence (serial #, Mac Address, etc)
- ID information for all people that participated in collecting the evidence
- Time and date that the evidence was collected
- Educate how to preserve evidence properly
What is the order of the NIST response life cycle phases? (Avanish P.)
1. Preparation
2. Detection & Analysis
3. Containment, Eradication, and Recovery
4. Post-Incident Activiities
Managerial Controls Definition (Akriti O)
Administrators write and implement, often associated with security design.
3 types of PII
personal, business and classified
Operational Controls (Emmanuel G)
Controls that are implemented by people instead of systems for day to day operations. Examples Include: Security training, Management changes, and Business continuity