Posts

Showing posts with the label Knowledge

Security Engineering

Security Models 1) Bell-laPadula Model 2) Biba Model 3) Clark-Wilson Model 4) Noninterference Model 5) Brewer and Nash Model 6) Graham Denning Model 7) Harrison-Ruzzo_Ullman Model Types of Symmetric Systems 1) Data Encryption Standard 2) Triple-DES 3) Advanced Encryption Standard 4) International Data Encryption Algorithm 5) Blowfish 6) RC4 7) RC5 8) RC6 Types of Asymmetric Systems 1) Diffie-Hellman Algorithm 2) RSA 3) El Gamal 4) Elliptic Curve Cryptosystems 5) Knapsack 6) Zero Knowledge Proof Message Integrity 1) The One-Way Hash 2) MD4 3) MD5 4) SHA 5) Digital Signature Standard PKI 1) CA 2) Certificates 3) RA Attacks on Cryptography 1) Ciphertext-Only Attacks 2) Known-Plaintext Attacks 3) Chosen-Plaintext Attacks 4) Chosen-Ciphertext Attacks 5) Differential Cryptanalysis 6) Linear Cryptanalysis 7) Side-Channel Attacks 8) Replay Attacks 9) Algebraic Attacks 10) Analytic Attacks 11) Statistical Attacks 12) Social Engineering Attacks 13) Meet-in-the-Middle Attacks

Security and Risk Management

Fundamental Principles of Security     Availability     Integrity     Confidentiality     Balanced Security Security Definitions Control Types Security Frameworks     ISO/IEC 27000 Series     Enterprise Architecture Development     Security Controls Development     Process Management Development     Functionality vs. Security The Crux of Computer Crime Laws Complexities in Cybercrime     Electronic Assets     The Evolution of Attacks     International Issues     Types of Legal Systems Intellectual Property Laws     Trade Secret     Copyright     Trademark     Patent     Internal Protection of Intellectual Property     Software Piracy Privacy     The ...

Communication and Network Security

Open Systems Interconnection Reference model Protocol Application Layer Presentation Layer Session Layer Transport Layer Network Layer Data Link Layer Physical Layer Functions and Protocols in the OSI Model Tying the Layers Together Multilayer Protocols TCP/IP Model TCP IP Addressing IPv6 Layer 2 Security Standards Converged Protocols Types of Transmission Analog and Digital Asynchronous and Synchronous Broadband and Baseband Cabling Coaxial Cable Twisted-Pair Cable Fibre-Optic Cable Cabling Problems Networking Foundations Network Topology Media Access Technologies Transmission Methods Network Protocols and Services Domain Name Service E-mail Services Network Address Translation Routing Protocols Networking Devices Repeaters Bridges Routers Switches Gateways PBXs Firewalls Proxy Servers Honeypot Unified Threat Management Content Distribution Networks Software Defined Networ...

Security Program Development

Security Program Development ISO/IEC 27000 Series : International standards on how to develop and maintain an ISMS developed by ISO and IEC. Enterprise Architecture Development:     Zachman Framework : Model for the development of enterprise architectures developed by John Zachman.     TOGAF : Model and methodology for the development of enterprise architectures developed by The Open Group.     DoDAF : U.S. Department of Defense architecture framework that ensures interoperability of systems to meet military mission goals.     MODAF : Architecture framework used mainly in military support missions developed by the British Minsitry of Defence.     SABSA Model : Model and methodology for the development of information security enterprise architectures.      Security Controls Development:     COBIT 5 : A business framework to allow for IT enterprise management and gov...

COSO Internal Control-Integrated Framework

COSO Internal Control-Integrated Framework COBIT was derived from the COSO Internal Control-Integrated Framework, developed by the Committee of Sponsoring Organizations (COSO) that sponsored the Treadway Commission in 1985 to deal with fraudulent financial activities and reporting. The COSO IC framework, first released in 1992 and last updated in 2013, identifies 17 internal control principles that are grouped into five internal control components as listed here. Control Environment 1. Demonstrates commitment to integrity and ethical values 2. Exercises oversight responsibilites 3. Extablishes structure, authority, and responsibility 4. Demonstrates commitment to competence 5. Enforces accountability Risk Assessment 6. Specifies suitable objectives 7. Identifies and analyzes risk 8. Assess fraud risk 9. Identifies and analyzes significant change Control Activities 10. Selects and develops control activities 11. Selects and develops  general controls over technology 12. Deploys thr...

Functions and Protocols in the OSI Model

Functions and Protocols in the OSI Model Application Layer The protocols at the application layer handle the file transfers, virtual terminals, network management, fulfilling networking requests of applications. FTP - File Transfer Protocol TFTP - Trivial FTP SNMP - Simple Network Management Protocol SMTP - Simple Mail Transfer Protocol Telnet HTTP - Hypertext Transfer Protocol Presentation Layer The services of the presentation layer handle translation into standard formats, data compression and decompression, and data encryption and decryption. No protocol work at this layer, just services. Presentation layer standards are as below :- ASCII - American Standard Code for Information Interchange EBCDIC - Extended Binary-Coded Decimal Interchange Mode TIFF - Tagged Image File Format JPEG - Joint Photographic Experts Group MPEG - Motion Picture Experts Group MIDI - Musical Instrument Digital Interface Session Layer The session layer protocols set up connections between ...

Quanitative Risk Analysis

Quantitative Risk Analysis Assign Asset Value (AV) -> Calculate Exposure Factor (EF) -> Calculate Single Loss Expectancy (SLE) -> Assess the Annualized Rate of Occurrence (ARO) -> Derive the Annualized Loss Expectancy (ALE) -> Perform Cost/Benefit analysis of countermeasures Exposure Factor = % Asset Value (AV) Single Loss expectancy (SLE)  SLE = AV * EF Annualized rate of occurrence (ARO) = # / year Annualized loss expectancy (ALE) = SLE * ARO or ALE = AV * EF * ARO Annual cost of the safeguard (ACS) = $/year Value or benefit of a safeguard = (ALE before safeguard - ALE after safeguard) - ACS

Asset Security

Asset Security Information Life Cycle     Acquisition     Use     Archival     Disposal      Information Classification Classification Levels - Commercial Business - highest to lowest     Confidential     Private     Sensitive     Public      Classification Levels - Militarty purpose - highest to lowest     Top Secret     Secret     Confidential     Sensitive but unclassified     Unclassified      Classification Controls Layers of Responsibility     Executive Management     CEO     CFO     CIO     CPO     CSO/CISO     Data Owner     Data Custodian     System Owner  ...