In this post I would like to describe main concepts of information security.
CIA triad:
4 A's:
CIA triad:
- confidentiality
- integrity
- availability
- Administrative control
- Technical control
- Physical control
4 A's:
- authentication - verifies unique identification
- authorization - check user rights
- access control - check resource rights
- auditing - tracks activities
Security consists of three main areas:
- Physical security
- Operational security
- Management and policies
Main goals if information security are:
- prevention
- detection
- response
- processes
- procedures
- policies
- design goals
- security zones
- technologies
- business requirments
- confidentiality
- integrity
- authentication
- accountability
- availability
- internet
- extranet
- DMZ
- intranet
- identifying assets
- assessing risks - consists of identifying assests, threat assesment and impact assesment. During impact assesment you are determining potential monetary losts. During threat assesment you are determining probability that threat can occur. Risk assesment may be qualitative and quantitative. Qualitative is descriptive assesment. It needs short time and small budget.
- identifying threats
- evaluating vulnerabilities
- access attack: dumpster diving, eavesdropping, snooping, interception,
- modification or repudiation attack
- denial of service attack: ping of death, buffer overflow, TCP SYN flood, smurth attack
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Follow-up
No comments:
Post a Comment