Security Concepts
Assets:
- Something that has value to an organization
- Physical devices
- Electronic information, data on a server
- Credit card numbers, SSN, etc.
Threats:
- Anything that has the potential cause loss of an asset
- Not an actual loss of an asset, just the potential to
- Trojan horse, hacker, etc.
Threat agents:
Vulnerability
- Weakness in the system
- Could be a pissed employee
- Open ports
- Permissions
Exploits
- Sequence of steps, stiftware that takes advantage of vulnerability to do an attack
Security Controls