Using multiple layers so that one failure is not enough
defense in depth
90 days
How long a private report of a bug should take.
Identify assets, Define treats and vulnerabilities, Calculate likelihoods and impacts, Select risk response options and controls
4 steps of risk analysis
Enables a host to discover another host's MAC address
ARP (Address Resolution Protocol)
The rules for filtering traffic
needs an implicit deny
Firewall ACL's
The CIA triad stands for
Confidentiality
integrity
availability
publishing bug vs report privately
Full disclosure vs coordinated
Subjective vs. objective
Qualitative - high/low
vs
quantitative - ALE
SYN
SYN ACK
ACK
three-way handshake
Stateless/static, stateful, web application, next generation, host based, network edge vs. internal segmentation, standalone vs. shared device, hardware vs. software
Types of firewalls
confidentiality
only the right people can see the information
serving both peaceful/defensive and military/offensive purposes
Dual use
ALE = SLE * ARO
SLE = AV*EF
formula for ALE
The levels of the OSI model
physical, data link, network, transport, session, presentation, application
IDS vs IPS
solution that observes copies and alerts on anomalous activity
vs.
solution situated "in line" with network traffic and can block anomalous activity
A structured way to identify what can go wrong in a system and deciding what to do before attackers cause harm
threat modeling
Competence, Integrity, non-maleficence
Major duties of code of ethics
physical, procedural/administrative, technical, legal
vs.
Directive, preventative, detective, corrective, forensic
security controls by nature vs. by time
Protocol for automatically assigning network configuration parameters vs. Protocol for translating IP addresses to FQDNs
DHCP vs. DNS
WEP - insecure
WPA2/802.11i
WPA3 - secure/preferred
Types of wireless security protocols
stride stands for
Spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege
What is allowed at RIT in regard to AI?
brainstorming concepts, or debugging hints after getting permission
asks Who is accountable for cybersecurity in this organization?
govern function from NIST CSF 2.0
proxy between clients and internet to manage outbound vs. proxy sitting between internet and backend servers to manage inbound traffic
forward vs. reverse proxy
can't secure the physical medium
no static network perimeter, external business requirements, cloud-based applications
possible threats