Wgu C706 - Secure Software Design (February 2023) 2023/24 Updated & Graded A
CIA Triad Confidentiality, Integrity, Availability Confidentiality Confidentiality is the concept of the measures used to ensure the protection of the secrecy of data, objects, or resources. Concepts, conditions, and aspects of confidentiality include the following: Sensitivity Discretion Criticality Concealment Secrecy Privacy Seclusion Isolation Integrity Integrity is the concept of protecting the reliability and correctness of data. Concepts, conditions, and aspects of integrity include the following: Accuracy Truthfulness Validity Accountability Responsibility Completeness Comprehensiveness Availability Availability means authorized subjects are granted timely and uninterrupted access to objects. Concepts, conditions, and aspects of availability include the following: Usability Accessibility Timeliness DAD Triad Disclosure, Alteration, and Destruction. The opposite of the CIA triad. Authenticity Authenticity is the security concept that data is authentic or genuine and originates from its alleged source. Nonrepudiation Nonrepudiation ensures that the subject of an activity or who caused an event cannot deny that the event occurred. AAA Services Refers to five elements: Identification - Claiming an identity Authentication - Proving identity Authorization - Defining allows/denies for an identity Auditing - Recording log of events Accounting - Review log files Defense in Depth Employing multiple layers of controls to avoid a single point-of-failure. Also known as layering. Abstraction Similar elements are put into groups, classes, or roles that are assigned security controls, restrictions, or permissions as a collective. Data Hiding Preventing data from being discovered or accessed by a subject by positioning the data in a logical storage compartment that is not accessible or seen by the subject. Security Through Obscurity Relying upon the secrecy or complexity of an item as its security, instead of practicing solid security practices. Different from data hiding. Encryption A process of encoding messages to keep them secret, so only "authorized" parties can read it. Security Boundary The line of intersection between any two areas, subnets, or environments that have different security requirements or needs. Security Governance The collection of practices related to supporting, evaluating, defining, and directing the security efforts of an organization. Third-Party Governance The system of external entity oversight that may be mandated by law, regulation, industry standards, contractual obligation, or licensing requirements. Documentation Review Process of reading the exchanged materials and verifying them against standards and expectations. Authorization to Operate (ATO) A formal declaration by a Designated Approving Authority (DAA) that authorizes operation of a Business Product and explicitly accepts the risk to agency operations. Security Function The aspect of operating a business that focuses on the task of evaluating and improving security over time. Security Policy A formalized statement that defines how security will be implemented within a particular organization. Business Case To demonstrate a business-specific need to alter an existing process or choose an approach to a business task. Top-Down Approach Upper, or senior, management is responsible for initiating and defining policies for the organization. Information Security (Infosec) Team The team or department responsible for security within an organization. Chief Information Security Officer (CISO) Typically considered the top information security officer in an organization. The CISO is usually not an executive-level position, and frequently the person in this role reports to the CIO. Chief Information Officer (CIO) The senior manager responsible for the overall management of information resources in an organization Chief Executive Officer (CEO) Corporate officer who has overall responsibility for managing the business and delegates responsibilities to other corporate officers. Chief Technical Officer (CTO) Focuses on ensuring that equipment and software work properly to support the business functions. Strategic Plan The long-term plan for future activities and operations, usually involving at least five years. Tactical Plan Midterm plan, developed to provide more details on accomplishing the goals set forth in the strategic plan. Useful for about a year. Operational Plan Short-term, highly detailed plan based on the strategic and tactical plans. Valid only for a short time. must be updated often.
Document information
- Uploaded on
- September 2, 2023
- Number of pages
- 47
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers