f# cia triad :
- confidentiality- data is accessed by those with the right permit . eg - encryption , biometric 2fa/mfa , passwords
- integrity- data has not been tampered or altered in any way . eg - hashing , checksums
- availability- data/resources are available to be accessed or shared
aaa : authentication , authorization , accounting
dad triad (opposite of cia triad): disclosure , alteration , deniability
privacy - person has the right to keep their info to themselves
non repudiation - subject cannot deny something that they have done
NIST framework
identify- evaluate risks , threats , vulnerabilities and recommend security controls to mitigate them
protect- develop , install operate it hardware & software assets with security as an embedded requirement at every stage
detect- proactive monitoring to ensure security controls are effective and capable of protection against new types of threats
respond-identify , analyze , contain , eradicate threats to systems and data security
recover- implement cyber security resilience to restore systems and data if other controls are unable to prevent attacks
control , tactics that proactively minimize risk by reducing or eliminating
- a vulnerability
- threat actor
- impact of an exploit
countermeasures- controls implemented to address a specific threat
- more effective but less broadly efficient
control should be verifiable (trustworthy)
- functionality
- effectiveness
- assurance
- cost-benefits
Control objectives
- security awareness training
- security policy
- upgrade firewalls , anti-malware etc
Defence in depth - design and implementation of multiple overlapping layers of diverse controls
- control should not be subject to cascade effect
- diversity of controls should be considered
Security control baselines - these express the minimum standards for a given environment
- serve as a starting point
- should be sensitive towards classification of the assest being protected (principle of proportionality)
Fine tuning Controls
- scoping- eliminating unnecessary baseline recommendations
- tailoring- customizing baseline recommendations to align with objectives
- compensating- substituting a recommended baseline control with a similar control
- supplementing- adding to the baseline recommendations
Security control Categories
- Technical - implement as a system such as firewalls , anti malware and OS access control . Also referred as logical controls
- operational- primarily by people eg - security guards
- managerial- gives oversight of the information system eg- risk identification tools or security policies
Security control function types
- preventive- eliminate or reduce the likelihood that an attack can succeed . eg - antimalware | SOPs (standard operating procedures) can be regarded as administrative version of preventative controls
- detective- identifies successful intrusion . eg- logs & audits
- corrective- acts to eliminate or reduce the impact of an intrusion event . eg- backups , patch management
- physical- includes alarms, security cameras , guards , all the physical access to premises and hardware
- deterrent- psychologically discouraged an attacker from attempting an intrusion . eg - signs and warnings
- compensating- substitution of security standards for protection using different methodology or technology