Braineos
DiscoverChallenges
Sign in
← Back to decks
Sign in to save your progress, vote, and build your own decks.Sign in

sit182

cyber sec

34 cards·by soulime
Study this deck
Hacking
The deliberate accessing of computer systems and networks without authorization
Phreaking
"Hacking" of systems/ computers to operate the telephone network.
Computer Security
(In general) The methods, techniques and tools used to ensure a computers system is safe.
Network Security
The protection of the multiple computers and other devices that are connected together.
Information Security
Focus on the information/ data being processed in the computer. (not hardware)
Information Assurance
The availability of the system/information when we want it.
Communication Security
The security of telecommunications systems.
C.I.A of security
Confidentiality, Integrity and Availability
Additional goals of C.I.A
Authentication, Non Repudiation, Auditability.
Operational Model of Operating Security
Protection = Prevention + (Detection + Response)
Host Security
Protecting each computer individually instead of the network as a whole.
Least Privilege
A subject should have only the necessary rights/permission to perform its tasks/
Separation of Duties
For any given task more than one individual needs to be involved.
Implicit Deny
If no other rule would allow access, access is denied.
Job Rotation
Rotating all I.T staff through different I.T roles/positions.
Layered Security
answer
Diversity of Defence
Making a system with dissimilar levels of security.
Security through Obscurity
Making the environment and protection mechanisms confusing/not generally known.
Keep it Simple
Reduce complexity in security
Access Control
The ability to control whether a subject can interact with an object.
Social Engineering
The process of convincing an authorised individual to provide confidential information or access to an unauthorized individual.
Data aggregation
Gathering information and expressing it in a summary form.
Security Policies
High level statements created by management that lay out the organisation's position on security and its security goals.
Change management Policy
Ensuring proper procedures are followed when modifications to the IT infrastructure are made.
Classification of Information
Different pieces of information have different levels of sensitivity, so they should be categorised as such.
Acceptable use Policy(AUP)
What the organisation considers to be the appropriate use of company resources.
Internet Usage Policy
What sites employees can access.
Email Usage Policy
What kind of content employees can send with company email. Includes attachments.
Due Care
Standard of care a reasonable person is expected to exercise in all situations.
Due Diligence
Standard level of care a business is expected to exercise in preparation of a business transaction.
Due Process
Guarantee of fundamental fairness, justice and liberty in relation to the individual's legal rights.
Need to Know (access)
To obtain access to information the individual must have a justified reason to know. They will only be given the minimum privilege for task.
Disposal and Destruction Policy
Making sure all data is securely disposed/destroyed so no one can gain access to it.
Service Level Agreement (SLA)
Contractual agreements between entities that describe specified levels of service that the servicing entity guarantees to provide.