f# cia triad :

  • confidentiality- data is accessed by those with the right permit . eg - encryption , biometric 2fa/mfa , passwords
  • integrity- data has not been tampered or altered in any way . eg - hashing , checksums
  • availability- data/resources are available to be accessed or shared

aaa : authentication , authorization , accounting

dad triad (opposite of cia triad): disclosure , alteration , deniability

privacy - person has the right to keep their info to themselves
non repudiation - subject cannot deny something that they have done


NIST framework
identify- evaluate risks , threats , vulnerabilities and recommend security controls to mitigate them
protect- develop , install operate it hardware & software assets with security as an embedded requirement at every stage
detect- proactive monitoring to ensure security controls are effective and capable of protection against new types of threats
respond-identify , analyze , contain , eradicate threats to systems and data security
recover- implement cyber security resilience to restore systems and data if other controls are unable to prevent attacks


control , tactics that proactively minimize risk by reducing or eliminating

  • a vulnerability
  • threat actor
  • impact of an exploit

countermeasures- controls implemented to address a specific threat

  • more effective but less broadly efficient

control should be verifiable (trustworthy)

  • functionality
  • effectiveness
  • assurance
  • cost-benefits

Control objectives

  • security awareness training
  • security policy
  • upgrade firewalls , anti-malware etc

Defence in depth - design and implementation of multiple overlapping layers of diverse controls

  • control should not be subject to cascade effect
  • diversity of controls should be considered

Security control baselines - these express the minimum standards for a given environment

  • serve as a starting point
  • should be sensitive towards classification of the assest being protected (principle of proportionality)

Fine tuning Controls

  • scoping- eliminating unnecessary baseline recommendations
  • tailoring- customizing baseline recommendations to align with objectives
  • compensating- substituting a recommended baseline control with a similar control
  • supplementing- adding to the baseline recommendations

Security control Categories

  • Technical - implement as a system such as firewalls , anti malware and OS access control . Also referred as logical controls
  • operational- primarily by people eg - security guards
  • managerial- gives oversight of the information system eg- risk identification tools or security policies

Security control function types

  • preventive- eliminate or reduce the likelihood that an attack can succeed . eg - antimalware | SOPs (standard operating procedures) can be regarded as administrative version of preventative controls
  • detective- identifies successful intrusion . eg- logs & audits
  • corrective- acts to eliminate or reduce the impact of an intrusion event . eg- backups , patch management
  • physical- includes alarms, security cameras , guards , all the physical access to premises and hardware
  • deterrent- psychologically discouraged an attacker from attempting an intrusion . eg - signs and warnings
  • compensating- substitution of security standards for protection using different methodology or technology