1/92
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
performance testing
evaluate Web application, speed, stability and scalability varying under loads and network conditions
compatibility testing
Is designed to verify that a web application can function correctly across different web, browsers or operating systems, regardless of the device or platform used to access the application
security testing
Identifies the applications, vulnerabilities, weaknesses, and security flaws and ensures. The data is secure from unauthorized access.
comprehensive testing
GAT covers functional usability, accessibility, localization, and compatibility testing
GAT
Global app testing
functional testing
Examines core features
non-functional testing
Assesses performance, security, and usability
unit testing
Design to help mitigate the risks of code changes
integration testing
Involves combining individual software modules and testing them as a group to verify their harmonist and intended functionality
System testing
Validates a complete integrated web application to verify that it meets all specified criteria
regression testing
Aims to identify issues in previously tested code or configuration after changes or modifications
acceptance testing
Evaluates invalidates the web applications functionality from an end users perspective
UI testing
Check whether the web applications user interface works as intended, and is visually appealing to end user
Usability testing
Involves customer feedback observing how they’re interrupt and navigate web applications and identifying usability issues
threat model
A systematic proactive cyber security practice for identifying potential threats, vulnerabilities, and risks in software systems and business processes to inform mitigation strategies and improve security posture
AST
Application security tools
DAST
Dynamic application security testing
OWASP TOP 10 2021
This is the standard for anything cyber security
Broken access control
restrictions on what authorize users are allowed to do are often not properly enforced attackers can exploit these flaws to access unauthorized functionality and or data such as access to other users account view, sensitive files, modify other users, data, change, assets, rights, etc
cryptographic failures
Failure to sufficiently protect data and transit or rest from exposure to unauthorized individuals. This can include poor usage of encryption or lack of it all together.
injection
Injection flaws, such as SQL, NoSQL, OS, And Elda injections occur when Untrust data is sent to an interpreter as part of a command query the attackers hostile data can trick the interpreter into executing unintended command or accessing data without proper authorization
insecure design
Failing to build security into the application early in the process through Threat modeling and secure design patterns, and principles
security mitigation
Security misconfiguration is commonly a result of insecure, default, configurations, incomplete or ad hoc configurations open cloud storage misconfigured HTTP headers and verb error messages containing sensitive information
vulnerable and outdated components
Components, such as libraries, framework and other software modules run with some privileges as the application if a vulnerable component is exploited, such as an attack can facilitate serious data loss, or server takeover
identification and authentication factors
Application functions related to authentication in session management are often implemented incorrectly, allowing the attackers to compromise password, keys, or session, tokens, or other implementation flaws to assume other users, identities, temporarily or permanently
software and data integrity, failures
Code infrastructures that does not properly protect against integrity failures like using plug-ins from
insufficient Logging and monitoring
Insufficient, logging and monitoring coupled with missing or ineffective integration with incident response allows attackers to further attack systems, maintain persistence, pivot to more systems, and temper or destroy data
server side request forging
SSRF occurs when an application fetches resources without validating the destination URL, this can be taken advantage of by attacker who is able to enter destination of their choosing
Security
according to Fischer And Green security implies a stable, relatively predictable environment in which an individual group may pursue its ends without disruption or harm and without fear of disturbance or injury
cyber security
The practice of protecting networks devices and data from unauthorized access or criminal use and ensuring the confidentiality, integrity, and availability of information
vulnerability
Is any weakness and acid that makes it susceptible to an attack or failure?
attack
Is an intentional action that can reduce the value of assets
Failure and errors
Unintentional actions that can reduce the value of an asset
threats
Attacks, failures and errors or actions that we collectively referred to his threats
finding your security goals
determine what assets we want to protect
Learn how the assets Works and interact with other things
Determine how our assets values reduced directly/indirect
CIA Triad
Confidentiality, integrity, and availability
Confidentiality
Ensures that sensitive information is accessible to authorize individuals
integrity
ensures the data is accurate and unaltered, safeguarding it from unauthorized modifications or corruptions
availability
Ensures that the data and services are accessible to authorize users when needed
when we protect something valuable, that’s protecting its _____?
Confidentiality
when it’s something that produces value, it’s _____?
Integrity
when we protect some thing that Provides access to value its _____?
Availability
The protection of info in a computer system
Economy of mechanism, Fail-safe default, Complete mediation, Open design, Separation of privilege, Least privilege, Least common mechanism, Psychological acceptability
TTPs
techniques, tactics, and process
economy of mechanism
Keeping it simple complexity is enemy of security
Fail-Safe default
Fail and error scenarios should fall back to most secure option
complete mediation
Check every access to a resource for authority
Open design
There is no security through security
separation of privilege
Two keys are red present to access key info
least privilege
access to do your job and no more
least common mechanism
Reducing the shared components in the system
psychological Acceptability
Systems need to be designed so people expected behavior provides security. Security is hard. People will find another way.
Secure software development framework
A set of fundamental sound secure software development practices based on established documents from organizations such as the BSA, OWASP ISO, POI, BSIMM, and safe code
It provides a common language for describing secured development practices, which can be used to foster communications for procurement processes, and other management activities
PO: Prepare the organization
Ensure readiness at both the organizational project levels for secure software development
PS: Protect the software
Secure all software components from tampering and unauthorized access
PW: Produce well sourced software
Develop software with minimal security vulnerabilities
RV: Respond to vulnerabilities
identifying address vulnerabilities in release software
customizing practices
The SSDF provides the starting point to organizations can customize and evolve over the time to fit their unique needs rather than serving as a rigid checklist
automating security
Consider auto mobility when implementing SSDF practices, especially for Scaling practices across large or complex environments
CSF
The NIST cyber security framework helps organizations to better understand and improve their management of cyber security risks
The CSF 2.0 is suitable for both initiating and changing cyber security programs

6 characteristics of CSF
governance, identify, protect, detect, respond, recover
identify
Develop an understanding of the organization system
Protect
Implement safeguards to ensure delivery of critical services
detect
Implement activities to identify the occurrence of a cyber security event
respond
Implement activities to take action regarding a detective cyber security incident
Recover
Implement activities to restore any capabilities or services that would impair due to a cyber security incident
adoption of the six functions
Organization start by integrating the six core functions of the CSF 2.0 into their cyber security programs
guidance utilization
Utilizing the resources in overview guide that helps organizations understand the rules and responsibilities associated with each function, serving as implementation blueprint
Setting specific outcomes
Organizations use these outcomes as benchmarks to gauge their progress and effectiveness in imagining cyber security risks
supplementary resources
To achieve the detailed outcomes organizations referred to as additional NIST resources that explains specific actions needed to realize these outcomes by adopting best practices
assessment and prioritization
Organizations assess their current cyber security practices against the CSF 2.0 standards to identify gaps and areas of improvement
internal and external communication
The CSF 2.0 used as a two for fostering better communication among internal teams (IT, security, operations, executive leadership, and with external partners)
integration with risk management
Organizations integrate the CSF 2.0 into their broader risk management strategies to ensure that cyber security risks are considered alongside other business risks
risk management framework (RMF)
The NIST RMF provides a process that integrates security privacy and cyber supply chain risk management activities into the system development lifecycle
why NIST RMF?
Evolving technology and edge computing increase the complexity of the interconnected systems
Hayton, security and privacy risks accompany this increased complex
NIST develop the RMF to address these challenges
The RMF is essential for protecting the integrity of systems and data across both public and private sectors
Ensure resilience and trustworthiness throughout the SDLC
The increasing cyber security threat landscape and National imperatives
Complexity and attack surface, supply chain, risk, defense, science board report, executive orders, and policies
complexity and attack surface
The risk in complexity of hardware software and systems participating in critical infrastructure increase vulnerability to attacks
Supply chain risk
Adversaries exploit supply chains to compromise systems the need for robust supply chain, risk management (SCRM)
defense science board report
Highlight the urgent need for improved cyber deterrence, and proactive risk management
executive orders, and policies
EO 13800 mandates federal agencies to ensure Bus risk management practices while office of management and budget (OMB)
7 stages of the RMF
Prepare, categorize, select, implement, assess, authorize, monitor
prepare
Identify rules, risk strategy, risk tolerance, and develop organizational risk assessment and continues monitoring
Categorize
Document system characteristics and classifies security impact
select
Choose, Taylor, and documents, security controls, establish continuous monitoring, and review security plans
Implement
Apply the chain controls. Update, security and privacy plans.
assess
Evaluate control, effectiveness and address deficiencies. Update security plans based on assessments.
authorize
Senior officials decide on risk acceptance. Provide authorization packages and risk mitigation.
Monitor
Maintain ongoing awareness of security posture. Use continues monitoring, inform risk management decisions.
NIST risk management framework (RMF)
Enhance security awareness: engineers are more aware of security risks and responsibilities
Structure development process: follows a systematic approach to risk assessment and management
Compliance requirements: insures adherence to organizational and regulatory security standards
NIST cyber security framework (CSF)
Holistic security integration: integrates security practices into daily development activities
Proactive threat mitigation: focuses on identifying and mitigating potential threats easily in the development cycle
Continuous improvement: encourages ongoing assessment and improvement of security measures
NIST secure software development framework (SDF)
Secure coding practices: emphasizes secure, coding standards and practices
Secure testing: incorporates, regular security, testing, and vulnerability assessments
documentation and transparency: insures, detailed documentation of security measures and decisions
what the CSA does
Promoting best practices, education, search, certification, consulting program guidance and roadmap, user certifications, meta-framework of cloud specifics, security controls, and collaborations
Best practices for 14 domains
Cloud, computing concept and architectures
governance and enterprise risk management,
legal issues, contracts, and electronic discovery
Compliance and audit management
Information governance
Management plan and business continuity
Infrastructure security
Virtualization and containers
Incident response
Application security
Data security and encryption
Identity, entitlement, and access management
Security as a service
related cloud technologies