CSE Module 10 CIA triad, CTM Incident Response, controls

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/50

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:02 AM on 9/30/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

51 Terms

1
New cards

data integrity (A. Edris)

the accuracy, consistency, and trustworthiness of data across its entire lifecycle.

2
New cards

Technical Controls (Tonye E.)

Written and implemented by the information technology (IT) team; firewall settings, antivirus/antimalware, screensaver/login policies, IDS/IPS

3
New cards

Most Secure Storage Option(Nate E)

Network storages systems like RAID, SAN, NAS

4
New cards

Deterrent Controls (Tonye E.)

Splash screen, demotion, warning signs, reception desks

5
New cards

Protecting availability of data in transit (Nathan Kim)

Implement mutual authentication systems to counter hijackers.

This makes sure the users device can tell when it is being contacted or receiving data requests from attackers.

6
New cards

Storage Area Network (SAN) - (J Victoria)

A network-BASED storage system that connects multiple servers to a centralized storage repository.

7
New cards

Sneaker Net - (J Victoria)

Using removable media to transfer data between hosts.

8
New cards

Detective controls(Jayden E.)

Does not prevent an intrusion but will identify/record any intrusion attempts

ex: Login reports or motion detectors

9
New cards

Direct-Attached Storage (DAS) - (J Victoria)

A hard drive or USB flash drive that is directly connected to a host.

10
New cards

Direct-Attached Storage (DAS) Challenges (Liza N.)

-->vulnerable to malicious attacks on local host

--> one of the most difficult types of data storage to manage/control

11
New cards

Network Attached Storage (NAS) - (J Victoria)

A network-CONNECTED storage device that allows both storage and retrieval of data from a centralized location by authorized users.

12
New cards

Protecting confidentiality of data in transit (Camden Buchacz)

Cybersecurity personnel must follow steps to encrypting data for transit. Ex. VPNs, SSL, and IPsec.

13
New cards

Hardware BASED technology examples (Tyler S)

Firewalls

Proxy servers

Hardware-based access controls

Network Switches

14
New cards

Data in storage definition (Prajwal S.)

A method of recording and saving data on either a device or in the cloud.

15
New cards

NIST Attack Vector(Eesa.F)

A way that hackers can use to get past security and enter a computer, network, or an app.

Examples : Web, Email, Theft, Impersonation, Media, or Attrition.

16
New cards

Redundant Array of Independent Disks (RAID) - (J Victoria)

A professional storage solution that combines multiple disks for the operating system to see it as a single disk.

17
New cards

Incident response stakeholders examples (Jason C.)

- Management

- IT support

- legal department

- human resources

- public affairs and media relations

18
New cards

Ways to Insure Availability (Jason C.)

- Equipment maintenance

- backup testing

- disaster planning

- activity monitoring

- availability testing

19
New cards

Data At Rest (Najeem S.)

the state when no user is accessing, repeating, or ammending the data.

data is not being proccessed or moved.

20
New cards

Software firewalls (Arnav K)

-control remote access to systems

-OS's normally have these

-Users can download/purchase third party

-Ex: Windows Defender

21
New cards

protocol analyzers (Arnav K)

*signature analyzers*

-monitor and stash info on internet traffic

-signify problems in performance, config's, and applications

-establishes traffic patterns

-debugs communication issues

22
New cards

Host-Based intrusion detection systems (Arnav K)

-host system activity

-sends alarms and note down files

-used in sensitive/crucial storing systems

-Ex: OSSEC

23
New cards

vulnerability scanners (Arnav K)* (pls be more specific on definition)

assesses weak spots on networks and computers

24
New cards

Network and port scanners (Arnav K)

They find and keep an eye on available ports on hosts or servers

25
New cards

Post-Incident Activities (Favour A)

The final phase of incident response where a team analyzes a past cyber incident and plan/implement prevention methods to defend against such an incident in the future.

26
New cards

Cyber security Cube principles(M. Ksit)

Goals ; CIA Triad, Confidentiality(If your data stays encrypted), Integrity(If your data stays the same), Availability(if you can get your data when you need it)

27
New cards

Protecting integrity of data in transit examples (Spencer McMillan)

Hashing, data validation checks, data consistency checks and access controls

28
New cards

Corrective Controls (Eesa.F)

Restorative measures that restore the system after a disaster or an event.

Examples: Data Backup, Recovery Systems, and Incident Response Plan

29
New cards

Examples of compnesative controls are... (Avanish P.)

- Security policies

- Personal Supervision

- Monitoring and work task procedures that substitutes a missing ideal control.

30
New cards

NIST Incident Response step 1 (Daniel P)

Preparation - prepare an organization for potential attacks, such as defining incident response policies and training employees to respond to an attack.

31
New cards

NIST incident response life cycle phase 3rd step (Shemmy T)

Containment: isolate and shut off affected devices and block incoming traffic from those devices

Eradicate: Delete malware and patch vulnerabilities

Recovery: Restore data using available backups and turn on any clean devices.

32
New cards

Information Rights Management (IRM) (Tyler J.)

way to ensure confidentiality of an email or file by allowing a document owner, organization, or one of its members to control or manage access to a document.

33
New cards

Things that accomplish a comprehensive Security Policy (J. Logatoc)

- demonstrates an organization's commitment to security.

- sets the rules for expected behavior.

- ensures consistency in system operations and software and hardware acquisition, use, and maintenance.

- defines the legal consequences of violations.

- gives security staff the backing of management.

34
New cards

Digital Rights Management (DRM) (Tyler J.)

way to ensure confidentiality by protecting copyrighted digital media, such as music, films, or books.

35
New cards

Remote Access policy ( Bright A)

-how remote users access a network

-what is accessible from remote locations.

36
New cards

Tokenization (Tyler J.)

Type of way to ensure confidentiality by using a substituting technique that isolates data from exposure to other systems. Uses random value to replace original data.

37
New cards

Cybersecurity Cube Safeguards (J. Logatoc)

Software firewalls, Network/port scanners, protocol analyzers, vulnerability scanners, host-based intrusion detection systems (IDS)

38
New cards

Identification and Authentication Policy ( Bright A)

-authorized persons that can access network resources

-verification procedures

39
New cards

NIST incident response life cycle phase 2nd step (Akriti O)

- detection and analysis

- CSIRT constantly monitoring to identify, analyze, and confirm

- organizations need to be prepared for any incident

- best to focus on common attack vectors

40
New cards

Acceptable Use Policy (Bright A)

-identify network resources that are acceptable to the organizations

-scalable consequences for policy violation

41
New cards

what are some Examples of Software Safeguards? (Arnav K)

-Software firewalls

-network and port scanners

-protocol analyzers

-vulnerability scanners

-host-based intrusion detection systems (IDS)

42
New cards

Cybersecurity Cube Data States (Eddy J.)

Data in transit, Data at rest, Data in process

43
New cards

Security Policy (Bright A)

- displays the security objectives

- expected behavior and required system conditions that members must follow

44
New cards

Ways to establish culture of Cybersecurity awareness (Julian T)

Education and training (implementing security awareness training), and security awareness programs

45
New cards

Physical control examples (Shemmy T)

Door locks, Warning signs, Motion detector, Power generator, Sign: "Authorized Personnel Only"

46
New cards

Administrative control examples (Nikan B)

-File storage policies

- Compliance policies

- Security Policy training

- Sign: Authorized personel only

47
New cards

NIST Attack Evidence Examples (Yasser B)

- Location of the recovery and storage of all evidence

- Identifying criteria for all evidence (serial #, Mac Address, etc)

- ID information for all people that participated in collecting the evidence

- Time and date that the evidence was collected

- Educate how to preserve evidence properly

48
New cards

What is the order of the NIST response life cycle phases? (Avanish P.)

1. Preparation

2. Detection & Analysis

3. Containment, Eradication, and Recovery

4. Post-Incident Activiities

49
New cards

Managerial Controls Definition (Akriti O)

Administrators write and implement, often associated with security design.

50
New cards

3 types of PII

personal, business and classified

51
New cards

Operational Controls (Emmanuel G)

Controls that are implemented by people instead of systems for day to day operations. Examples Include: Security training, Management changes, and Business continuity