• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 17 pages
Other

C836 EXAM AND REVIEW UPDATED 2022/2023 CHAPTER 1 TO chapter 6

Document preview thumbnail
Preview 3 out of 17 pages

CHAPTER 1 Define the confidentiality, integrity, availability (CIA) triad. - -gives a model by which we can think about and discuss security concepts, tends to be very focused on security, as it pertains to data. Differentiate confidentiality, integrity, and availability. Confidentiality - similar but not the same as privacy - necessary component of privacy and refers to our ability to protect data from those who are not authorized to view it Integrity - Refers to the ability to prevent our data from being changed in an unauthorized or undesirable manner - This could mean the unauthorized change or deletion of our data or portions of our data, or it could mean an authorized but undesirable change or deletion of data - To maintain integrity, we not only need to have the meansto prevent unauthorized changes to our data but also need the ability to reserve the authorized changes that need to be undone Availability - -refers to the ability to access our data when we need it - -loss of availability can refer to a wide variety of breaks anywhere in the chain that allows us access tour data - Issues can result from power loss, operating system or application problems, network attacks, compromise of a system, or other problems Define information security. - -protecting information and information systemsfrom unauthorized access, use, disclosure, disruption modification, or destruction - It means we want to protect our data (where ever it is) and system assets from those who would see to misuse it Define the Parkerian Hexad and its principles. - Consist of CIA triad as well as possession or control, authenticity, and utility for a total of six principles - It is not widely known as the CIA triad - Integrity does not account for authorized but incorrect modification of data and instead focuses on the state of the data itself in the sense of completeness - Possession or control refers to the physical disposition of the media on which data is stored. This enables us without involving other factors such as availability to discuss our loss of the data in its physical medium. The principle of lOMoAR cPSD| possession would enable us to more accurately describe the scope of the incident. - Authenticity allows us to talk about the proper attribution as to the owner or creator of the data in question. Authenticity can be enforced through the use of digitalsignatures. Nonrepudiation prevents someone from taking an action such as sending an email and then later denying that he or she has done so. - Utility refers to how useful the data is to us. It is the only principle that is not necessarily binary to nature. We can have a variety of degrees of utility depending the data format. Identify the four types of attacks(i.e., interception, interruption, modification, and fabrication). - Interception attacks allow unauthorized users to access our data, applications, or environments, and are primarily an attack against confidentiality. Interception might take the form unauthorized file viewing or copying, eavesdropping on phone conversations, or reading e-mail, and be conducted against data at rest or in motion. Properly executed, interception attacks can be very difficult to detect. - Interruption attacks cause our assetsto become unusable or unavailable for our use, on a temporary or permanent basis. Interruption attacks often affect availability but can be an attack on integrity as well. - Modification attacksinvolve tampering with our asset. Such attacks might primarily be considered an integrity attack but could also represent an availability attack. - Fabrication attacksinvolve generating data, processes, communications, or other similar activities with a system. Fabrication attacks primarily affect integrity but could be considered an availability attack as well. - Confidentiality (Interception), Integrity (Interruption, Modification, Fabrication), Availability (Interruption, Modification, Fabrication) Compare threats, vulnerabilities, risk, and impact. - Threat is something that has the potential to cause us harm. Threats tend to be specific to certain environments particularly in the world of information security. - Vulnerabilities are weaknesses that can be used to harm us. In the essence they are holes that can be exploited by threats in order to cause us harm. A vulnerability might be a specific operating system or application that we are running, a physical location where we have chosen to place our office building, a data center that is populated over the capacity of its air-conditioning system, a lack of backup generators, or other factors. - Risk is the likelihood that something bad will happen. In order for us to have a risk in a particular environment, we need to have both a threat and vulnerability that the specific threat can exploit. - Impact is considering the value of the asset being threatened to be a factor, this may change whether we see a risk as being present or not.


Document information

Uploaded on
March 10, 2024
Number of pages
17
Written in
2023/2024
Type
Other
Person
Unknown
$10.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
15
Followers
8
Items
233
Last sold
1 year ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions

Whoops! We can’t load your doc right now. Try again or contact support.