CISSP Cheat Sheet
CISSP Cheat Sheet
C1 Discretionary Security Protection Identification and authentication Separation of users and data Discretionary protection of resources C2 Controlled Access Protection More finely grained DAC Individual accountability through login procedures Object reuse Protect audit trail Resource isolation Required System Documentation and user manuals.
Bell-LaPadula (MAC) Biba (Integrity) NO WRITE DOWN NO WRITE UP NO READ UP NO READ DOWN USER<=File to write USER =>File to Write
Clark-Wilson Integrity Separation of Duties App Authentication 1. Least Privelege 2. Separation of Duty 3. Rotation of duties Concept Exposure Factor Singel Loss Expectancy Annualized Rate of Occurance (ARO) Annualized Loss of Expectancy (ALE)
Formula % of Loss caused by threat Asset Value x Exposure Factor (EF) Frequency of threat occurance per year Single Loss Expectancy (SLE) x Away Pizza Sausage Take Not Do Please A Priest Saw Ten Nuns Doing Pushups OSI Application Presentation Session Transport Network Datalink Physical
EAL 1 Functionally tested EAL 2 Structurally tested EAL 3 Methodically tested and checked EAL 4 Methodically designed, tested, and reviewed EAL 5 Semiformally designed and tested EAL 6 Semiformally verified design and tested EAL 7 Formally verified design and tested EAL measures how the needs are met Protection Profiles describe objectives, and the environmental, functional, and assurance level expectations Target of Evaluation (TOE) Product proposed to provide the needed security solution Security Target Written by vendor explaining mechanisms that meet security and assurance requirements Evaluated Products List EPL- list of evaluated products Threat Agents Can Exploit A Vulnerability Resulting in A Risk Virus Lack of antivirus software Virus Infection Hacker services running on a server Unauthorized access to information Fire Lack of fire extinguishers System malfunction CANONS Protect society, the commonwealth, and the infrastructure Act honorably, honestly, justly, responsibly, and legally Provide diligent and competent service to principals
TCP/IP Application