1/36
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Confidentiality
Information should be read by authorized users only
Integrity
Data is stored and transferred as intended and any modification is authorized
Availability
Information is accessible to those authorized to view or modify it
Non-Repudiation
Persons cannot deny creating or modifying data
Cybersecurity Framework
Identify, Protect, Detect, Respond, Recover
Managerial (Security Control Category)
Give oversight of system
Operational (Security Control Category)
Relies on a person for implementation
Technical (Security Control Category)
Implemented in operating systems, software, and security appliances
Physical (Security Control Categoy)
Devices that mediate access to premises and hardware
Preventive (Security Control Functional Types)
Physically or logically restricts unauthorized access
Operates before an attack
Detective (Security Control Functional Types)
Identifies attempted or successful intrusions
Operated during an attack
Corrective (Security Control Functional Types)
Responds to and fixes an incident and may prevent its recurrences
Operates after an attack
Directive (Security Control Functional Types)
Enforces a rule of behavior
Deterrent
Psychologically discourages intrusions
Compensating
Substitutes for principal control
Associated with framework compliance measures
Chief Information Officer (Information Security Roles)
CIO (Overall Responsibility)
Chief Security Officer (Information Security Roles)
CSO (Overall Responsibility)
Managerial (Information Security Roles)
Oversees the implementation and management of an organization's IT security policies, personnel, and resources.
Information Systems Security Officer (Information Security Roles)
ISSO (Technical)
Non-technical (Information Security Roles)
Employees and personnel who help protect information by following security policies, procedures, and safe security practices, even if they do not manage or configure IT systems.
Due care/liability (Responsibilities)
The responsibility of an organization or individual to take reasonable steps to protect information systems and be legally accountable if negligence or failure to fulfill that responsibility results in security breaches or damages.
Risk assessment and testing
Information Security Competencies (1)
Specifying, sourcing, installing, and configuring secure devices and software
Information Security Competencies (2)
Access Control and User Privileges
Information Security Competencies (3)
Auditing Logs and Events
Information Security Competencies (4)
Incidence response and reporting
Information Security Competencies (5)
Business Continuity and Disaster Recovery
Information Security Competencies (6)
Security Operations Center
SOC
Development, security, and operations
DevSecOps
Cyber Incident Response Team
CIRT
Gap Analysis
A business tool used to compare a company's current performance or state with a desired future goal
Access Control
Identification, Authentication, Authorization, and Accounting
Identification
The system owner confirms the user’s identity and creates an account to represent the user
Authentication
Entering the credentials and comparing it to the hashed credential
Authorization
For each action, the account performs a permission list is checked to allow or deny the action
Accounting
The system tracks permission usage in a log. The user cannot prevent this auditing