Security Certifications (Lesson 25)
Top 5 certification names - correct answer - CompTIA Security+
-CEH: Certified Ethical Hacker
- GSEC: SANS GIAC Security Essentials
- CISSP: Certified Information Systems Security Professional
- CISM: Certified Information Security Manage
What are the problems with certificaiton - correct answer First, the security field is
always changing, with new technologies and applications to protect, new threats to
address, and emerging
means of protection
Discretionary Access Controls - correct answer The basis of this kind of security is
that an
individual user, or program operating on his behalf, is allowed to specify
explicitly the types of access other users may have to information under
his control. Discretionary security differs from mandatory security in
that it implements an access control policy on the basis of an
individual's need-to-know as opposed to mandatory controls which are
driven by the classification or sensitivity designation of the
information.
Mandatory Access Controls - correct answer Mandatory security refers to the
enforcement of a set of access control rules that constrains a subject's access to
information on the basis of a comparison of that individual's clearance/authorization
to the information, the classification/sensitivity designation of the information, and
the form of access being mediated
Orange, Red, and Yellow Book - correct answer Orange: Trusted Computer System
Evaluation Criteria
Red: Trusted Network Interpretation
Yellow: Guidance for applying Orange Book
What is the ITSEC and why are we not using the rainbow thing and what were they
replaced by - correct answer The Information Technology Security Evaluation Criteria
(ITSEC)
Similar to Rainbow series except in that it set up criteria for evaluating computer
security
within products and systems.
First published in May 1990 in France, Germany, England, and the Netherlands.
Like the Rainbow Series, it has been basically replaced by the Common Criteria.
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller flyhigher329. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for £10.55. You're not tied to anything after your purchase.