click below
click below
Normal Size Small Size show me how
1.2
Summarizing Security Concepts
| Term | Definition |
|---|---|
| CIA Triad - C | Confidentiality |
| CIA triad - I | Integrity |
| CIA triad - A | Availability |
| Non-repudiation | Ensures that a party in a transaction cannot deny having performed an action |
| AAA 1 | Authentication |
| AAA 2 | Authorization |
| AAA 3 | Accounting |
| CIANA pentagon - N | Non-repudiation |
| CIANA pentagon - A | Authentication |
| Accounting | Auditing, ensuring all user activity is tracked |
| Control pane (zero trust) | overall framework that lays out policies and procedures |
| Adaptive identity (which pane) | Control |
| Adaptive identity (definition) | MFA using users' device, location, etc. |
| Threat scope reduction (which pane) | control |
| Threat scope reduction (definition) | limit users' access to only work related stuff |
| Policy driven access control (which pane) | control |
| Policy driven access control (definition) | developing, managing, enforcing, least privilege |
| Secured zones (which pane) | control |
| Secured zones (definition) | isolated environments in a network for sensitive data |
| Policy engine (which pane) | control |
| Policy engine (definition) | cross references the access requirements with its predefined policies (rulebook) |
| Policy administrator (which pane) | control |
| Policy administrator (definition) | establishes and manages access policies |
| Data plane (zero trust) | ensures the policies are executed |
| Subject/system (which pane) | data |
| Subject/system (definition) | entity trying to gain access |
| Policy enforcement point (which pane) | data |
| Policy enforcement point (definition) | gatekeeper to network where access is allowed or denied |
| Gap analysis | evaluating the differences between an organization's current and desired performance |
| Types of gap analysis | Technical and business |
| Honeypot | decoy system/server to attract potential attackers to learn the how/why |
| Honeynet | an entire network of decoy systems |
| Honeyfiles | decoy files |
| Honeytokens | fake pieces of data (ex. user credential) to alert admins when they are used in a system |
| Tactics, techniques, and procedures (TTPs) | specific methods and patterns of activity associated with a particular group/threat actor |
| Dynamic page generation | presents dynamic website content to confuse and slow down an attacker |
| Port triggering | specific services/ports on a network device remain closed until needed |
| Fake telemetry data | system can respond to an attackers' network scan attempt by sending out fake data |
| Bollards | short vertical posts designed to counter vehicular threats in the area |
| Types of surveillance systems | video, security guards, lighting, sensors |
| Sensors | detect and respond to external changes in the environment and convert the info into data |
| Types of sensors | infrared, pressure, microwave, ultrasonic |
| Access control vestibule | system with two doors that are electronically controlled to ensure only one door can be opened at a given time |
| Tailgating | unauthorized person follows a legitimate employee to the secure space without their knowledge/consent |
| False acceptance rate (FAR) (door locks) | rate that the system authenticates a user as valid even though that person should not have been granted access to the system |
| FAR solution | increase sensor sensitivity |
| False rejection rate (door locks) | any time the biometrics system denies a user who is valid |
| Equal/crossover error rate | solution to both false rates by making them equal value |
| Cipher lock | a keyless door lock that opens when you enter a specific code on a push-button keypad (not electronic) |