Up to Date Professor messer notes

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/24

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:36 PM on 7/20/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

25 Terms

1
New cards

Control Categories

Technical: controls implemented using technical systems

Managerial: security that involve policies, planning and management

Operational: people instead of systems and day to day operations

Physical: limits physical access

2
New cards

Example of Technical Control

Firewalls, antivirus

3
New cards

Example of Managerial Control

security policies

4
New cards

Example of Operation controls

security guards. awareness program

5
New cards

example of physical controls

guard shack, fence, card readers

6
New cards

Control types

Preventative: prevents a security incident before it occurs

Deterrent: discourage an intrusion attempt

Detective: tell and log an intrusion attempt

Corrective: restore systems after an attack

Compensating: Alternatives when existing control does not work

Directive: directs people on what they should do to maintain security

7
New cards

CIA Triad

Confidentiality: Prevent disclosure of info to unauthorized users

Integrity: information cannot be modified without detection

Availability: information and system are available when needed

8
New cards

Example of Confidentiality

Encryption: encode messages to the person who can decrypt it

Access controls: limit access to certain information

Two-Factor Authentication: confirmation before information is given

9
New cards

Examples of Integrity

Hashing: converts data into a fixed-length value to verify its integrity

Digital Signatures: verifies the sender and confirms the data has not been changed

Certificates: verifies the user’s identity

Nonrepudiation: prevents someone from denying they performed an action

10
New cards

Examples of Availability

redundancy and fault tolerance

11
New cards

Nonrepudiation

Can’t deny what they did or say

12
New cards

Identification

who you claim to be, username

13
New cards

AAA

Authentication: prove who you are

Authorization: gain access based on your identification and authentication

Accounting: logs of what happened

14
New cards

CA

Certificate Authority: issues and manage all certificates

15
New cards

Abstraction

hides unnecessary details and show only essential information

16
New cards

Gap Analysis

Finding the difference of where you are and where you need to be

17
New cards

Zero Trust

Authenticate yourself every time you try to access a resource. never trust

18
New cards

Two types of Plane

Data Plane: handles and moves data based on control plane’s decisions

Control plane: makes decision and manage how things operate

19
New cards

Adaptive Identity

uses context and risk factors to decide how much authentication is required

20
New cards

policy-driven access control

uses policies to determine who can access resources and what actions they can perform

21
New cards

security zones

divide a network into sections to control access and limit impact of attacks

22
New cards

PEP

policy enforcement point: the point where access is actually allowed or denied

23
New cards

PDP/Policy Engine

policy decision point: decides whether access should be allowed or denied

24
New cards

PA

Policy Administrator: applies and send the PDP’s decision to the PEP

25
New cards