Chapter1

Risk Management 

Acceptance- I accept the risk that something will happen 

Migitgation – Reducing risk to an acceptable level. Firewall, IDS, Antivirus 

Risk Avoidance - what the name says lol 

Transfer – Getting insurance 

 

Risk Classification 

Low- Probably gonna accept it 

Medium- Something we have to address 

High- need to do something to mitigate it 

 

Threat agent – The catalyst that causes a threat to be realized 

Assets – Information, data, hardware, employees that we want to keep protected 

Insider threats – 90% of attacks come from the inside 

CIA properties 

-confidentiality : keeping the data hidden from unauthorized eyes. 

-Integrity : making sure data isn’t altered 

-Availability: making sure those who need to have access to the data can access it. 

Principle of least privilege 

-Give people the privileges needed to get their job done 

Zero Day attacks 

-An attack that relied on a vulnerability hasn’t been patched yet and has just been discovered. 

Types of attacks 

DOS 

DDOS- multiple sources