1. Cybersecurity déf-Protection of information assets by addressing threats to information
processed,
inition stored and transported by internetworked information systems
2. APT Attacks Attacks by an adversary with sophisticated levels of expertise, who has time,
patience and significant resources. Create opportunities to achieve its
objectives using multiple attack vectors.
3. Primary Protection of assets from threats
concern for
security
These use single, secret, bidirectional keys that encrypt and decrypt.
4. Symmetric
key systems
These use pairs of unidirectional, complementary keys that only encrypt or
5. Asymmetric
de- crypt. Typically, one of these keys is secret, and the other is publicly
key systems
known.
6. Information
Se- curity Deals with information, regardless of its format (paper documents, digital
and intellectual property in people's minds and verbal or visual
7. Most communications
common
symmetric Data Encryption Standard (DES) 56bits plus 8 for parity checking, block
key system cypher then replaced by AES (Advanced Encryption Standard)
8. Cybersecurity Concerned with protecting digital assets (encompassed within network
hardware, software and information that is processed, stored within
isolated systems or transported internetworked information
environments)
9. Two main advan- 1) User has to know only one to encrypt and decrypt
tages to symmet- 2) Less complicated, less processing power, good for bulk data
encryption
ric key systems
1/
30
,10. Cybersecurit Protection of information assets by addressing threats to information
y guide processed, stored and transported by internetworked information
definition
systems
2/
30
, CSX EXAM
Study online at https://quizlet.com/_6vaxxq
11. Disadvantages of 1) Diflculty distributing keys
symmetric key 2) Limitations of shared secret, cannot be used to sign electronic documents
encryption or messages
12. NIST identify Use organisational understanding to minimise risks to systems, assets, data
&
capabilities
13. digital Data
signature integrity
ensures
Authenticatio
n
Authorisatio
n
14. NIST protect Design safeguard to limit the impact of potential events on critical services
&
infrastructures
15. IPSec 1) Transport mode : encrypts the data portion, referred as the ESP -
(Internet Encapsulation Security Payload
Protocol 2) Tunnel mode : ESP and its header are encrypted
Securi- ty) : 2
modes for
establishing
en- cryption
16. NIST detect Implement activities to identify the occurrence of a Cybersecurity event
17. Security An agreement between the two IPsec peers about the cryptographic
Associa- tion parameters to be used in an ISAKMP (Internet Security Association and
(SA)
Key Management Protocol) session.
18. NIST respond Take appropriate action after learning of a security event
3/
30