click below
click below
Normal Size Small Size show me how
Vulnerability manage
Vulnerability management
| Question | Answer |
|---|---|
| Identifying vulnerabilities | Systematic practice of spotting and categorizing weaknesses in a system, network, or application that could potentially be exploited |
| Vulnerability scanning | Automated method of probing networks, systems, an application to discover potential vulnerabilities |
| Application security | Used to safeguard the software from being manipulated during its life cycle |
| Static analysis | Used to analyze an application's source code without executing it |
| Dynamic analysis | Evaluate an application as it is being run to determine if there are any vulnerabilities in the application |
| Package monitoring | Ensures that the libraries and components that the application depends on our secure and up-to-date |
| Penetration testing | Used to simulate a real world attack on a system to evaluate it security posture |
| system and process audits | Process that involves conducting a comprehensive review of the information systems, security policies, and procedures |
| Identifying vulnerabilities | Systematic practice of spotting and categorizing weaknesses in a system, network, or application that could potentially be exploited |
| Threat intelligence | Continue process used to understand the threats faced by an organization |
| threat intelligence feed | Continuous stream of data related to potential or current threats to an organization security |
| Open source intelligence (OSINT) | Intelligence that is collected from publicly available sources including reports, forms, news articles, blogs, and social media posts |
| proprietary or third-party feeds | Threat intelligence feeds that are provided by commercial vendors, usually under a subscription service type of business model |
| dark web | Part of the Internet that is intentionally hidden and inaccessible through standard web browsers |
| responsible disclosure | Term used to describe the ethical practice where a security researcher discloses information about vulnerabilities in a software, hardware, or online service |
| common vulnerabilities and exposures (CVE) | System that provides a standardized way to uniquely identified in reference known vulnerabilities and software and hardware |
| healthcare vulnerabilities | Risk patient data and safety |
| Financial institution vulnerabilities | Lead to monetary losses and regulatory scrutiny |
| exposure factors (EF) | Used as a quantifiable metric to help a cybersecurity professional understand the exact percentage of an asset that is likely to be damaged or affected if a particular vulnerability is exploited |
| Risk tolerance | Refers to the level of risk that an organization is willing to accept in pursuit of its objectives and before action is the necessary to mitigate the risk |
| vulnerability response and remediation | Strategies that identify, assess, and address vulnerabilities in a system or network to strengthen an organizations security posture |
| Patching | Applying Software Update updates to fix security vulnerabilities |
| purchasing cyber security insurance policies | Procuring insurance policies to mitigate financial losses from cyber incidents |
| network segmentation | Dividing a network into smaller segments for improved security and performance |
| Implementing compensating controls | Alternative security measures is used for situations where standard controls are not feasible or effective |
| exception | Temporarily relaxes security controls for operational business needs |
| Exemption | Permanently waves controls for specific reasons, such as when using a legacy system |
| configuration auditing | Checks for misconfigurations |
| patch auditing | Verifies proper patch application |
| vulnerability reporting | Process of documenting and communicating details about security weaknesses identified in software or systems to the individuals or organizations responsible for addressing the issue |
| internal reporting | Involve identification, documentation, and communication of the organizations vulnerabilities within the organizational structure of the organization |
| External reporting | Involves discussions with the vendors, partners, customers, or the Public at large, depending on the specific vulnerability involved |
| responsible disclosure reporting | art of disclosing vulnerabilities ethically and judiciously to the affected stakeholders before making the announcement to the Public at large |
| System monitoring | Observation of computer system, including the utilization and consumption of its resources. |
| baseline | Established performance metrics and data points for standard behavior of a system, network, or application |
| Application monitoring | Emphasizes the management and monitoring of software Application performance and availability. |
| infrastructure monitoring | Observation of the performance and availability of an organization's physical and virtual infrastructure |
| Log aggregation | Process of collecting and consolidating log data from various sources into a centralized location |
| alerting | Involves setting up notifications to inform relevant stakeholders when specific events or conditions occurred |
| scanning | Involves examining systems, networks, or applications to identify vulnerabilities, configuration issues, or other potential problems |
| vulnerability scan | Checks for vulnerabilities in systems, networks, or applications by comparing the system's state against databases of vulnerabilities |
| configuration scan | Checks for misconfigurations that could impact system performance or security |
| code scan | Checks the source code of an application for potential issues, such as security vulnerabilities or coding errors |
| reporting | Involves generating summaries or detailed reports based on the collected and analyzed data |
| archiving | Involves storing data for long-term retention and future reference, including organizations log data, performance data, and incident data |
| alert response and remediation or validation | Involves taking appropriate actions in response to alert alerts and ensuring that the identified issues have been effectively addressed |
| quarantining | Isolating a system, network, or application to prevent the spread of a threat and limit its potential impact |
| alert tuning | Adjusting alert parameters to reduce errors, false positives, and to improve the overall relevance of the alerts being generated by a given system |
| simple network management protocol (SNMP) | Internet protocol for collecting and organizing information about managed devices on IP networks and from modifying the information to change device behavior |
| Granular | Sent trap messages get a unique objective identifier to distinguish each message as a unique message being received |
| management information base (MIB) | Used to describe the structure of the management data of a device subsystem using a hierarchical namespace containing object identifiers |
| Verbose | SNMP traps may be configured to contain all the information about a given alert or event as a payload |
| SIEM | Solution that provides real-time or near-real-time analysis of security alerts that are generated by network hardware and applications |
| Agent | Software agent installed on each system, such as a server or workstation, from which SIM needs to collect log data |
| Agentless | Under this approach, the SIEM system directly collects log data from each system using standard protocols such as SNMP or WMI |
| splunk | Market-leading big data information gathering and analysis tool that can import machine-generated data via a connector or a visibility add-on |
| elastic stack (ELK) | Collection of free and open-source SIEM tools that provide storage, search, and analysis functions |
| ArcSight | SIEM log management and analytics software that can be used for compliance reporting for legislation and regulations like HIPAA, SOX, and PCI DSS |
| QRadar | SIEM log management, analytics, and compliance reporting platform created by IBM |
| security information and event management system (SIEM) | The central hub for the consolidation to provide a holistic view of an organization's security landscape |
| antivirus software | Fundamental security tool that protects systems against malware, including viruses, worms, Trojans, ransom, and spyware |
| Data loss prevention systems | Used to monitor and control data endpoints, network traffic, and data stored in the cloud to prevent potential data breaches from occurring |
| network intrusion detection systems (NIDS) | Passively identifies any potential threats |
| network intrusion prevention systems (NIPS) | Actively blocks or prevents these potential threats |
| firewalls | Serve as a barrier between a trusted internal network and an untrusted external network |
| vulnerability scanners | Tools that identify security weaknesses in a system, including missing patches, incorrect configurations, and other types of known vulnerabilities |
| security content automation protocol (SCAP) | Open standards that automate vulnerability management, measurement, and policy compliance for systems in an organization |
| Open vulnerability and assessment language (OVAL) | XML schema for describing system security states and querying vulnerability reports and information |
| extensible configuration checklist description format (XCCDF) | XML schema for developing and auditing best-practice configuration checklists and rules |
| asset reporting format (ARF) | XML schema for expressing information about assets and the relationships between assets and reports |
| common configuration enumeration (CCE) | Scheme for provisioning secure configuration checks across multiple sources |
| common platform enumeration (CPE) | Scheme for identifying hardware devices, operating system systems, and applications |
| common vulnerabilities and exposures (CVE) | List of records where each item contains a unique identifier used to describe a publicly known vulnerability |
| common vulnerability scoring system (CVSS) | Used to provide a numerical score to reflect the severity of a given vulnerability |
| 0 = | None |
| 0.1 - 3.9 = | Low |
| 7.0 - 8.9 = | High |
| 9.0 - 10.0 = | critical |
| benchmark | Set of security configuration rules for some specific set of products to provide a detailed checklist that can be used to secure systems to a specific baseline |
| full packet capture (FPC) | Captures the entire packet, including the header and the payload for all traffic entering and leaving a network |
| Flow analysis | Relies on a flow collector, which records Metadata and statistics rather than recording each frame that passes through the network |
| NetFlow | A Cisco-developed means of reporting network flow info to a structured database |
| IP flow information export (IPFIX) | Defines traffic flows based on shared packet characteristics |
| Zeek | Passively monitors a network like a sniffer, but only logs full packet capture data of potential interest |
| Multi router traffic grapher (MRTG) | Creates graphs showing traffic flows through the network interfaces of routers and switches by polling the appliances using SNMP |
| Single pane of glass | A central point of access for all the information, tools, and systems |
| defining the requirements | Involves Identifying the information, tools, and systems |
| identifying and integrating data sources | Involves identifying the data sources that the security team needs to access |
| customizing the interface | Involves designing the user interface and configuring panels and views to display information and data |
| developing standard operating procedures and documentation | Ensures that the security teams know how to use the single paint of glass and understand the process and procedures |
| Continuously monitoring and maintaining the solution | Include regular reviewing of the data and information |