1/44
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Confidentiality
Ensuring data is not disclosed to unauthorized people, entities, or processes
Integrity
Ensuring data has not been altered in an unauthorized manner
Availability
Ensuring systems and data are accessible to authorized users when needed
CIA Triad
Confidentiality, Integrity, Availability — the three core goals of information security
Authentication
Verifying a user's claimed identity (e.g. password, biometric)
Authorization
Granting an authenticated user permission to access specific resources
Accounting
Tracking and logging user activity for auditing purposes
AAA
Authentication, Authorization, Accounting — framework for controlling and monitoring access
Managerial Control
Administrative controls like policies and procedures set by management
Operational Control
Controls implemented by people in day-to-day operations (e.g. security awareness training)
Technical Control
Controls implemented through technology (e.g. firewalls, encryption)
Physical Control
Controls that physically restrict access (e.g. locks, fences, guards)
Deterrent Control
Discourages an attacker from attempting an attack (e.g. warning signs)
Preventive Control
Stops an attack before it happens (e.g. firewall rules)
Detective Control
Identifies that an attack occurred (e.g. IDS, logs)
Compensating Control
An alternative control used when the primary control isn't feasible
Corrective Control
Restores systems after an attack (e.g. backups, patches)
Directive Control
Directs or mandates a behavior through policy (e.g. acceptable use policy)
Threat Actor
Any person or entity responsible for a security incident
Attributes of Actors
Characteristics used to classify threat actors: sophistication, resources, internal/external
Unskilled Attacker
Low-skill attacker using existing tools/scripts (aka "script kiddie")
Hacktivist
Attacker motivated by political or philosophical beliefs, aims for disruption/chaos
Organized Crime
Threat actor group motivated primarily by financial gain
Nation-State Actor
Highly resourced attacker sponsored by a government, motivated by espionage or war
Insider Threat
Threat actor who is an employee/contractor, motivated by revenge, financial gain, or blackmail
Shadow IT
Unauthorized IT systems/software used within an organization without approval
Data Exfiltration
Unauthorized transfer/theft of data out of a system
Service Disruption
Attack goal of taking down or degrading a service
Attack Surface
All the points where an unauthorized user could try to enter or extract data
Vulnerable Software
Software containing exploitable weaknesses (client-based or agentless)
Unsupported Systems
Systems/apps no longer receiving security updates (legacy/EOL)
Removable Devices
USB drives and similar media that can introduce malware or exfiltrate data
Unsecure Networks
Networks lacking proper protections (e.g. open Wi-Fi)
Open Service Ports
Network ports left open and exploitable by attackers
Default Credentials
Factory-set usernames/passwords that attackers try first
Message-Based Vector
Attack delivered via SMS or instant messaging
Supply Chain
The network of suppliers, vendors, and providers an org depends on
Managed Service Provider (MSP)
Third-party company managing IT infrastructure/services for a client
OS-Based Vulnerability
A weakness in an operating system that can be exploited
Malicious Update
A software update that has been tampered with to deliver malware
Firmware Vulnerability
A weakness in low-level device software
Legacy Platform
Outdated system still in use despite lacking modern security support
End-of-Life (EOL)
Point at which a vendor stops supporting/patching a product
Misconfiguration
Improperly set up system/security settings that create vulnerabilities
Zero-Day
A vulnerability unknown to the vendor with no patch available yet