100% de satisfacción garantizada Inmediatamente disponible después del pago Tanto en línea como en PDF No estas atado a nada 4.2 TrustPilot
logo-home
Notas de lectura

Brunel - Computer Science - CS3609 Cybersecurity Lecture Notes (Exam Revision)

Puntuación
-
Vendido
11
Páginas
62
Subido en
28-02-2022
Escrito en
2020/2021

These are the lecture notes I created which I used to revise for the CS3609 Cybersecurity exam at Brunel University in which I received a First Class in.

Institución
Grado











Ups! No podemos cargar tu documento ahora. Inténtalo de nuevo o contacta con soporte.

Escuela, estudio y materia

Institución
Estudio
Grado

Información del documento

Subido en
28 de febrero de 2022
Número de páginas
62
Escrito en
2020/2021
Tipo
Notas de lectura
Profesor(es)
David bell
Contiene
Todas las clases

Temas

Vista previa del contenido

Module: CS3609
Lecture Topic: Information and Risk
Week: 2

Risk Management

Risk management is the process of understanding and responding to factors that may lead to a
failure in the confidentiality, integrity, or availability of an information system.




Confidentiality is about keeping information confidential and not allowing people who shouldn’t see
it, access that information.

Integrity is about ensuring that information is not altered or tampered with. (Blockchain e.g.)

Availability is who should have access to that information who can see it.

Risk is a situation or event that exposes an asset to harm, and the probability of that risk being
realised. If it is, that can cause a loss of money. (Fines: could be 4% of turnover, poor security or not
declaring breaches)

, Information security is the preservation of CIA. Other properties such as
authentication, authorization, non-reputation, audit and accountability
can also be involved.




Why risk management? It’s not a matter of IF but WHEN…
No organization is exempt from data breaches.

Tesco bank was fined 16.8 million pounds 2016-2019 for data breaches.
You must continuously identify and quantify risk; you need to access the effectiveness of deployed
goals to reduce impact.




(This one always included in the exam)

,These 7 factors need to be understood.

Stakeholders are risk owners, system owners, asset owners, or anyone who has a stake in the
information system or the asset.

An asset is anything that has value, tangible, people, information, intellectual property. Consider
what assets are at Risk in your network topology in terms of the vulnerabilities.

Threats is a single potential cause of an unwanted instant. These come from Threat agents.

Controls are implemented to mitigate Vulnerabilities, which is a weakness in an asset or the
absence of a security control that can be exploited by a threat. (e.g. insufficient maintenance, single
point of absence, as well as floods/fire)

Controls are the means of managing risk and can place limits on the activities that might pose a risk,
such as proactive, as safeguards, or counter measures, once an incident occurs – how to detect,
contain and recover from an incident.



CVE – Common Vulnerabilities and Exposures

Cve.mitre.org

You can explore the threats. The CVE system provides a reference method for publicly known
information security vulnerabilities and exposures.

Mitre attack framework.

, Risk Analysis

Risks can be analysed by either Quantitative or Qualitative risk methodologies




Quantitative relies on specific numbers, which makes it more precise, allows decision makers to
make better decisions about risk and quantify the risk. Usually involves money (£/$). Relies on the
accuracy and completeness of the numerical values. Quantifies the loss.

Qualitative you don’t have hard data, ask people what they think based on their experience,
subjective data, based on risk perception by the stakeholders. Quantitative gives a handle on risk
which is not covered by the hard numbers. This allows you to think about the risk register.

Ideally, you would take a hybrid approach and use both.
$9.35
Accede al documento completo:

100% de satisfacción garantizada
Inmediatamente disponible después del pago
Tanto en línea como en PDF
No estas atado a nada


Documento también disponible en un lote

Conoce al vendedor

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
cslbrunel Brunel University
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
63
Miembro desde
3 año
Número de seguidores
34
Documentos
29
Última venta
4 meses hace
Brunel Computer Science (1st Class Honours)

I achieved a First Class Honours degree in Computer Science from Brunel University - I will be uploading some of my work. Please do not purchase any documents looking for the solution to your assignments or deliverables. No refunds / exchanges.

5.0

2 reseñas

5
2
4
0
3
0
2
0
1
0

Recientemente visto por ti

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes