Quantitative Analysis (ALE=SLE x ARO) ALE = Annualized Loss Expectancy (A dollar amount that estimates the loss potential from a risk in a span of year) SLE = Single Loss Expectancy (A dollar amount that is assigned to a single event that represents the company’s potential loss) ARO = Annualized Rate of Occurrence (Frequency of… Read more »
Posts Categorized: CISSP
After-action review (AAR): a detailed examination of events that occurred from incident detection to recovery Identify areas of the BC/DR plans that worked, didn’t work, or need improvement AAR’s are conducted with all participants in attendance AAR is recorded for use as a training case AAR brings the BCP/DRP teams’ actions to a close
Result contains: Identified critical functions and required resources
Identify organization’s critical business functions
Review the BIA BIA contains the prioritized list of critical business functions Should be reviewed for compatibility with the BC plan
Project Initiation and Management Develop and Document Project Scope and Plan
Computer/Cyber Crime CryptoLocker Ransomware – Spreads via email and propagates rapidly. Encrypts various file types and then a pop-up window appears to inform user about the actions performed on computer and, therefore demand a monetary payment for files to be decrypted.
Computer as incidental to other crimes Involves crimes where computers are not really necessary for such crimes to be committed. Instead computers facilitate these crimes and make them difficult to detect. Examples of crimes in this category may include money laundering and unlawful activities on bulletin board systems.
Oversight Committee Representation
Organizational or corporate governance has existed since time immemorial to ensure the efficient running via control structures.
Wireless Communications WAP (Wireless Applications Protocol) –Developed for wireless (PDA’s, mobile phones, pagers, etc. devices to communicate)
Tunneling is a method of transferring data from one network to another by encapsulating the packets in an additional header. The additional header provides routing information so that the encapsulating payload traverse the intermediate networks.
IPSec IPSec is an architecture or framework for security services for IP networks. It works at the Network Layer of the OSI Model. It is actually a standard for secure data transmission. It provides mechanisms for authentication and encryption. Defined by RFC 4301 and carries a set of functions, it is mandatory in IPv6. IPSec… Read more »
Open Systems Interconnect (OSI) Model
One advantage of a honeypot includes:
WANS and Their Components Wide area networks (WANs) are considerably different than LANs. Organizations usually own their own LANs, but WAN services are typically leased; it’s not feasible to have your network guy run a cable from New York to Dallas.
RADIUS provides which of the following?
IDS systems are considered what type of control?
Which of the following is the best answer: TACACS+ features what?
A local area network (LAN) is a critical component of a modern data network. A LAN is comprised of one or more computers, a communication protocol, a network topology, and cabling or a wireless network to connect the systems.
Mark has just completed his new peer-to-peer network for the small insurance office he owns. Although he will allow Internet access, he does not want users to log in remotely. Which of the following models most closely matches his design?
When registering for a new service, you were asked the following questions. “What country were you born in? What’s your pet’s name? What is your mother’s maiden name?” What type of password system is being used?
Which of the following is considered a DDoS tool?
No system or architecture will ever be completely secure; there will always be a certain level of risk.
What are the two primary components of a DAC?
Which of the following biometric systems would be considered the most accurate?
Which of the following is not a valid defense against emanation leakage?
Security Models of Control Security models of control are used to determine how security will be implemented, what subjects can access the system, and what objects they will have access to. Simply stated, they are a way to formalize security policy.
Although a robust architecture is a good start, real security requires that you have security mechanisms in place to control processes and applications. Some good security mechanisms are described in the following sections.
Computer System Architecture At the core of every computer system is the CPU and hardware that make it run.
Penetration testing is a series of activities undertaken to identify and exploit security vulnerabilities.
Single sign-on is an attempt to address a problem that is common for all users and administrators.
Data access controls are established to control how subjects can access data, what they can access with it, and what they can do with it once accessed. Three primary types of access control are discussed in this section. Mandatory Access Control (MAC)
The two law systems that form the basis of legal systems in most countries are:
Kerberos is a network authentication protocol created by the Massachusetts Institute of Technology (MIT) that uses secret-key cryptography. Kerberos has three parts: a client, server, and trusted third party (KDC) to mediate between them.
Types of Attacks Denial of Service (DoS) Smurf Fraggle SYN Flood Teardrop Distributed Denial of Service (DDoS) Ping Sweep Port Scan Salami attack Man-in-the-Middle Session or TCP Hijacking Replay Buffer Overflow Scareware and Ransomeware Password attack Covert channels Web Attacks SQL Injection – An injection of SQL query through input data from client to application (database)…. Read more »
Asymmetric Systems –Uses a pair of keys (private and public) for encryption and decryption
An IDS is designed to function as an access-control monitor. It can monitor network or host activity and record which users attempt to access specific network resources.