001 - Cybersecurity Fundamentals Security Principles
001 - Cybersecurity Fundamentals Security Principles
Security Principles
Risk Management
Security Concepts
Process
Governance Elements
Security Controls
and Process
Security
Concepts
• The CIA Triad
• CIA Triad Deep Dive
• Authentication
• Methods of Authentication
• Non-repudiation
• Privacy
Security
Concepts :
The CIA
Triad
Security Concepts : CIA Triad Deep Dive
• Single-factor authentication
• Multi-factor authentication
• Common best practice is to implement at least
two of the three common techniques for
authentication:
o Knowledge-based
o Token-based
o Characteristic-based
Security Concepts : Non-repudiation
The right of an individual to control the General Data Protection Regulation (GDPR)
distribution of information about themselves.
Security Concepts : Summary
Risk
Management Asset : something in need of
Process : protection.
Risk
Management Vulnerability : a gap or weakness
RISK
MANAGEMENT Identify risk to communicate it clearly.
PROCESS :
RISK Employees at all levels of the organization are
responsible for identifying risk.
IDENTIFICATION
Identify risk to protect against it.
RISK MANAGEMENT PROCESS :
RISK ASSESSMENT
Controlling, directing or preventing the movement of people and equipment throughout a specific physical
location
Protection and control over entry onto the land surrounding the buildings, parking lots or other areas that are
within the organization’s control
Physical controls are supported by technical controls as a means of incorporating them into an overall security
system.
SECURITY CONTROL : TECHNICAL CONTROL
Support security
Facilitate detection of
requirements for
security violations
applications and data.
Directives, guidelines or advisories
aimed at the people within the
organization
The International Organization for Standardization (ISO) develops and publishes international standards on a variety of technical
subjects, including information systems and information security, as well as encryption standards. ISO solicits input from the
international community of experts to provide input on its standards prior to publishing.
The National Institute of Standards and Technology (NIST) is a United States government agency under the Department of
Commerce and publishes a variety of technical standards in addition to information technology and information security
standards. Many of the standards issued by NIST are requirements for U.S. government agencies and are considered
recommended standards by industries worldwide.
From Internet Engineering Task Force (IETF), there are standards in communication protocols that ensure all computers can
connect with each other across borders, even when the operators do not speak the same language.
The Institute of Electrical and Electronics Engineers (IEEE) also sets standards for telecommunications, computer engineering and
similar disciplines.