Chapter1
Risk Management
Acceptance- I accept the risk that something will happen
Migitgation – Reducing risk to an acceptable level. Firewall, IDS, Antivirus
Risk Avoidance - what the name says lol
Transfer – Getting insurance
Risk Classification
Low- Probably gonna accept it
Medium- Something we have to address
High- need to do something to mitigate it
Threat agent – The catalyst that causes a threat to be realized
Assets – Information, data, hardware, employees that we want to keep protected
Insider threats – 90% of attacks come from the inside
CIA properties
-confidentiality : keeping the data hidden from unauthorized eyes.
-Integrity : making sure data isn’t altered
-Availability: making sure those who need to have access to the data can access it.
Principle of least privilege
-Give people the privileges needed to get their job done
Zero Day attacks
-An attack that relied on a vulnerability hasn’t been patched yet and has just been discovered.
Types of attacks
DOS
DDOS- multiple sources