1/119
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Cybersecurity
Protects electronic systems, networks, & data
Information Security
Protects all information (digital, physical, intellectual)
Difference b/w Cybersecurity & Information Security
Cybersecurity = Digital only & Information Security = All information
Confidentiality (CIA Triad)
Only authorized people can access data
Integrity (CIA Triad)
Data remains accurate & unaltered
Availability (CIA Triad)
Authorized users can access data when needed
Authentication (AAA)
Prove who you are
Authorization (AAA)
What you’re allowed to do
Accounting (AAA)
Records/logs activity
Deterrent (Security Controls)
Discourage attack
Preventive (Security Controls)
Stop attack
Directive (Security Controls)
Guide Behavior
Detective (Security Controls)
Discover attack
Compensating (Security Controls)
Alternate protection
Corrective (Security Controls)
Fix damage
Organized Crime (Threat Actors)
Money
Nation-State (Threat Actors)
Government-sponsored attacks
Hacktivists (Threat Actors)
Political/ideological motives
Insiders (Threat Actors)
Employees/contractors
Shadow IT (Threat Actors)
Unauthorized technology purchases
APT (Threat Actors)
Long-term stealthy attack
Attack surface (Attack surfaces)
Area where attackers can gain access
Mainstream Attack Surfaces (Attack Surfaces)
Software, Hardware, Networks
Communication Threat Vectors (Attack Surfaces)
Email, texts, IM, voice calls
Supply Chain Attack (Attack Surfaces)
Compromising products through suppliers/vendors
Vulnerability (Vunerability)
Weakness that can be exploited
Software Vulnerability (Vulnerability)
Weakness in software
Hardware Vulnerability (Vulnerability)
Weakness in hardware/firmware
Misconfiguration (Vulnerability)
Incorrect settings causing weakness
Zero-Day (Vulnerability)
Exploited before defenders know it exists
Framework (Information Security Resources)
Security blueprint (NIST)
Regulation (Information Security Resources)
Required rules organization must follow
Legislation (Information Security Resources)
Security-related laws
Standard (Information Security Resources)
Agreed-upon guideline (PCI DSS)
Benchmark (Information Security Resources)
Secure configuration guide
Information Sources (Information Security Resources)
RFCs, vulnerability feeds, TTPs, NVD
Social Engineering (Social Engineering Attack)
Manipulate people to reveal information or weaken security
Phishing (Social Engineering Attack)
Fake email/message pretending to be legitmate
Spear Phishing (Social Engineering Attack)
Phishing targeting a specific person
Vishing (Social Engineering Attack)
Voice phishing via phone call
Smishing (Social Engineering Attack)
Phishing through text message
Business Email Compromise (Social Engineering Attack)
Fake business email requesting money transfer
Impersonation (Social Engineering Attack)
Pretending to be someone else to gain trust
Redirection (Social Engineering Attack)
Sending victims to a fake website
Misinformation (Social Engineering Attack)
False information regardless of intent
Disinformation (Social Engineering Attack)
False information intended to deceive
Watering Hole Attack (Social Engineering Attack)
Infecting a website frequently visited by targets
Data Reconnaissance (Social Engineering Attack)
Gathering information before an attack
Dumpster Diving (Social Engineering Attack)
Searching trash for useful information
Shoulder Surfing (Social Engineering Attack)
Watching someone enter sensitive information
Google Dorking (Social Engineering Attack)
Advanced Google searches to find exposed data
What are phishing red flags?
Fake sender
Urgent tone
Requests credentials
Generic greeting
Mismatched links
Random attachments
Industrial Camouflage (Perimeter Defenses)
Hiding a facility’s true purpose
Barier (Perimeter Defenses)
Physical obstacle preventing access
Fence (Perimeter Defenses)
Keep unauthorized people out
Barricade (Perimeter Defenses)
Stops vehicle traffic
Bollard (Perimeter Defenses)
Prevents vehicle ramming attacks
Security Guards (Perimeter Defenses)
Active human security monitoring
IR sensor (Perimeter Defenses)
Detects infared enregy
Microwave Sensor (Perimeter Defenses)
Uses radio waves like radar
Ultrasonic sensor (Perimeter Defenses)
Measures object distance
Pressure Sensor (Perimeter Defenses)
Detects physical presence/movement
Mantrap (Perimeter Defenses)
Two-door security checkpoint
Reception Area (Perimeter Defenses)
Medium-security buffer
Waiting Room (Perimeter Defenses)
(Perimeter Defenses)
Electronic Lock (Perimeter Defenses)
Keypad lock with access logs
Fingerprint Lock (Perimeter Defenses)
Uses biometric authentication
Data Leakage
Sensitive data escaping unauthorized control
Faraday Cage (Preventing Data Leakage)
Blocks electromagnetic signals from entering or leaving
Faraday Bag (Preventing Data Leakage)
Portable version of a Faraday cage
Protected Distribution System (Preventing Data Leakage)
Secure conduit for transmitting classified information
Hardened Carrier PDS (Preventing Data Leakage)
Sealed metal conduit protecting cables
Alarmed Carrier PDS (Preventing Data Leakage)
Detects tampering through sensors
Cable Lock (Preventing Data Leakage)
Physically secures portable devices
Confidential (Data Classification)
Highest sensitivity
Private (Data Classification)
Need to know basis
Sensitive (Data Classification)
Could seriously harm company if disclosed
Critical (Data Classification)
Must be avaible for business operations
Public (Data Classification)
Safe for anyone to view
Restricted (Data Classification)
Not public; use caution
Regulated Data (Data Types)
Governed by external rules & regulations
Intellectual Property (Data Types)
Creative works or inventions
Trade Secret (Data Types)
Proprietary information not publicly disclosed
Legal Information (Data Types)
Information related to laws & legal processes
Financial Information (Data Types)
Enterprise monetary data
Human-Readable Data (Data Types)
Easily understood by people
Machine-Readable Data (Data Types)
Intended for computers to interpret
Data in Processing (Data States)
Currently being used
Data in Transit (Data States)
Moving across a network
Data at Rest (Data States)
Stored on device or media
Data Minimization (Data States)
Collect only the necessary data
Tokenization (Data States)
Replace sensitve data with tokens
Restrictions (Data States)
Limit access by user or location
Segmentation (Data States)
Separate sensitive data into protected areas
What’s the difference between Steganography & Cryptography?
Steganography hides the message that exists while Cryptography scrambles the message
Cipher
Mathematical algorithm used to encrypt & decrypt data
Transposition Cipher
Rearranges letters
Substitution Cipher
Replaces letters with other letters
Key
Mathematical value used by an algorithm to produce ciphertext
Plaintext (Text Type)
Orginal data