Sign in to save your progress, vote, and build your own decks.Sign in
Info Teco Chpt 1
54 cards·by Firebird
Definition: When the company that made a device provides no support for the device.
lack of vendor support
Definition: System for which vendors have dropped all support for security updates due to the
system’s age.
end-of-life systems
Definition: The out-of-the-box security configuration settings.
default configurations
Definition: Configuration options that provide limited security choices.
weak configuration
Definition: An incorrectly configured device.
misconfiguration
Definition: Account set up for a user that might provide more access than is necessary.
improperly configured accounts
Definition: Deficiencies in software due to poor design.
architecture/design weaknesses
Definition: Software that allows the user to enter data but does not validate or filter user
input to prevent a malicious action.
improper input handling
Definition: Software that does not properly trap an error condition and provides an attacker
with underlying access to the system.
improper error handling
Definition: A software occurrence when two concurrent threads of execution access a shared
resource simultaneously, resulting in unintended
race condition
Definition: A situation in which a hardware device with limited resources (CPU, memory, file
system storage, etc.) is exploited by an attack
resource exhaustion
Definition: A situation in which an attacker manipulates commonplace actions that are
routinely performed; also called business process comp
Vulnerable business processes
Definition: Devices that are not formally identified or documented in an enterprise.
undocumented assets
Definition: The widespread proliferation of devices across an enterprise.
system sprawl
Definition: An attack in which there are no days of warning.
zero day
Definition: A threat that has not been previously identified.
new threat
Definition: Users with little or no instruction in making security decisions.
untrained users
Definition: Security actions that ensure that only authorized parties can view the
information.
Confidentiality
Definition: Security actions that ensure that the information is correct and no
unauthorized person or malicious software has altered the da
Integrity
Definition: Security actions that ensure that data is accessible to authorized users.
Availability
Definition: An item that has value.
asset
Definition: A type of action that has the potential to cause harm.
threat
Definition: A person or element that has the power to carry out a threat.
threat actor
Definition: A flaw or weakness that allows a threat agent to bypass security.
vulnerability
Definition: A situation that involves exposure to danger.
risk
Definition: Different options available when dealing with risks.
risk response techniques
Definition: A response to risk that acknowledges the risk but takes no steps to address it.
accept
Definition: A response to risk that allows a third party to assume the responsibility of the
risk.
transfer
Definition: A response to risk that identifies the risk and the decision is made to not engage
in the risk-provoking activity.
avoid
Definition: Addressing risks by making risks less serious.
mitigate
Definition: Characteristic features of different groups of threat actors.
attributes
Definition: Threat actors that have developed a high degree of complexity.
sophisticated
Definition: An attribute of threat actors that can vary widely.
funding and resources
Definition: The location within an enterprise in which some threat actors perform.
internal
Definition: The location outside an enterprise in which some threat actors perform.
external
Definition: The reasoning behind attacks made by threat actors.
intent and motivation
Definition: Individual who lacks advanced knowledge of computers and networks and so uses
downloaded automated attack software to attack inf
Script kiddies
Definition: Freely available automated attack software.
open-source intelligence
Definition: A group of threat actors that is strongly motivated by ideology.
hactivists
Definition: State-sponsored attackers employed by a government for launching computer
attacks against foes.
nation state actors
Definition: A new class of attack that uses innovative attack tools to infect a system and then
silently extracts data over an extended peri
Advanced Persistent Threat (APT)
Definition: Employees, contractors, and business partners who can be responsible for an
attack.
insiders
Definition: Threat actors that launch attack against an opponents’ system to steal
classified information.
Competitors
Definition: Threat actors that are moving from traditional organized criminal activities
to more rewarding and less risky online attacks
Organized crime
Definition: Instructing employees as to the security reasons behind security
restrictions.
user training
Definition: Using security products provided by different manufacturers.
vendor diversity
Definition: Having different groups responsible for regulating access to a system.
control diversity
Definition: Using technology that is carried out or managed by devices as a basis for
controlling the access to and usage of sensitive data.
technical controls
Definition: Security controls for developing and ensuring that policies and procedures are
carried out; regulating the human factors of secu
administrative controls
Definition: Frameworks/architectures that are specific to a particular industry or market
sector.
industry-specific frameworks
Definition: Information security frameworks/architectures that are required by
regulatory
Definition: Information security frameworks/architectures that are not required.
non-regulatory
Definition: Information security framework/architectures that are worldwide.
international
Definition: Information security framework/architectures that are domestic.
national