Matching questions
1-80 of 80
Click a term to match it with a definition
which are the tools and systems you use to deny or allow access. (Granting, denying,
limiting, revoking)
Give this one a try later!
Access controls
often concerned with controlling the movement of individuals and vehicles. Access
controls for individuals typically regulate their movement in and out of buildings or
facilities, often using badges that open a facility's doors
Give this one a try later!
Physical Access Controls
,The Bell–LaPadula model implements a combination of discretionary
and mandatory access controls (DAC and MAC) and is primarily
concerned with the confidentiality of the resource in question—in
other words, making sure unauthorized people can’t read it. Generally,
in cases where you see these two models implemented together,
MAC takes precedence over DAC, and DAC works within the accesses
allowed by the MAC permissions.
For example, you might have a resource that is classified as secret and
a user who has a secret level of clearance; under a mandatory access
model, the user would have access to the resource. However, you
might also have an additional layer of DAC under the MAC access so
that if the resource owner has not given the user access, they would
not be able to access it, despite the MAC permissions. In Bell–
LaPadula, two security properties define how information can flow to
and from the resource.3
The Simple Security Property The level of access granted to an
individual must be at least as high as the classification of the resource
in order for the individual to access it. In other words, an individual
cannot read a resource classified at a higher level, but they can read
resources at a lower level.
The * Property (or Star Property) Anyone accessing a resource can
only write (or copy) its contents to another resource classified at the
same level or higher.
You can summarize these properties as “no read up” and “no write
down,” respectively, as shown in Figure 3-6.
In short, this means that when you’re handling classified information,
you can’t read any higher than your clearance level, and you can’t
write classified data down to any lower level.
Give this one a try later!
The Bell-LaPadula Model (type of multi level access control)
, assess the overall risk. risk is the conjunction of a threat and a vulnerability. A
vulnerability with no matching threat or a threat with no matching vulnerability does
not constitute a risk.
Give this one a try later!
Assess Risks
protect the physical environment in which your systems, sit, or where your data is
stored. ex, fences, gates, locks, guards, cameras etc.
Give this one a try later!
Physical Controls
is a geographically based authentication factor. This factor operates differently than
the other factors, as it requires a person to be present in a specific location. For
example, when changing an ATM PIN, most banks will require you to go into a branch,
at which point you will also be required to present your identification and account
number. If the bank allowed the PIN to be reset online, an attacker could change your
PIN remotely and proceed to clean out your account. Although potentially less useful
than some of the other factors, this factor is difficult to counter without entirely
subverting the system performing the authentication.
Give this one a try later!
Where you are ( authentication factor)
1-80 of 80
Click a term to match it with a definition
which are the tools and systems you use to deny or allow access. (Granting, denying,
limiting, revoking)
Give this one a try later!
Access controls
often concerned with controlling the movement of individuals and vehicles. Access
controls for individuals typically regulate their movement in and out of buildings or
facilities, often using badges that open a facility's doors
Give this one a try later!
Physical Access Controls
,The Bell–LaPadula model implements a combination of discretionary
and mandatory access controls (DAC and MAC) and is primarily
concerned with the confidentiality of the resource in question—in
other words, making sure unauthorized people can’t read it. Generally,
in cases where you see these two models implemented together,
MAC takes precedence over DAC, and DAC works within the accesses
allowed by the MAC permissions.
For example, you might have a resource that is classified as secret and
a user who has a secret level of clearance; under a mandatory access
model, the user would have access to the resource. However, you
might also have an additional layer of DAC under the MAC access so
that if the resource owner has not given the user access, they would
not be able to access it, despite the MAC permissions. In Bell–
LaPadula, two security properties define how information can flow to
and from the resource.3
The Simple Security Property The level of access granted to an
individual must be at least as high as the classification of the resource
in order for the individual to access it. In other words, an individual
cannot read a resource classified at a higher level, but they can read
resources at a lower level.
The * Property (or Star Property) Anyone accessing a resource can
only write (or copy) its contents to another resource classified at the
same level or higher.
You can summarize these properties as “no read up” and “no write
down,” respectively, as shown in Figure 3-6.
In short, this means that when you’re handling classified information,
you can’t read any higher than your clearance level, and you can’t
write classified data down to any lower level.
Give this one a try later!
The Bell-LaPadula Model (type of multi level access control)
, assess the overall risk. risk is the conjunction of a threat and a vulnerability. A
vulnerability with no matching threat or a threat with no matching vulnerability does
not constitute a risk.
Give this one a try later!
Assess Risks
protect the physical environment in which your systems, sit, or where your data is
stored. ex, fences, gates, locks, guards, cameras etc.
Give this one a try later!
Physical Controls
is a geographically based authentication factor. This factor operates differently than
the other factors, as it requires a person to be present in a specific location. For
example, when changing an ATM PIN, most banks will require you to go into a branch,
at which point you will also be required to present your identification and account
number. If the bank allowed the PIN to be reset online, an attacker could change your
PIN remotely and proceed to clean out your account. Although potentially less useful
than some of the other factors, this factor is difficult to counter without entirely
subverting the system performing the authentication.
Give this one a try later!
Where you are ( authentication factor)