What are the 4 Code of Ethics Canons?
What is Confidentiality?
Measures the attackers ability to get unauthorized data or access to information from an applicant or system
What is Integrity?
Measures an attackers ability to manipulate, change or remove data at rest and data in transit
What is Availability ?
Measures the attackers ability to disrupt or prevent access to services or data in a client-server or distributed environment
What is Authenticity?
The property of being genuine and being able to be verified and trusted; confidence in the validity of a transmission, message and message originator
What are Solutions for Authenticity?
Integrated Identity Platforms:
-Passwordless (QR code on endpoints), bring your own identity (BYOI), Zero Trust
-Zero Trust Network Access (ZTNA) - a technology that makes it feasible to implement zero trust security model. ZT is an IT security initiative that accepts that threats exist inside and outside of a network. ZTNA demands strict authentication and identification for every subject before authorizing them to access internal resource objects
What is Non-repudiation?
the inability to refuse participation in a digital transaction, contract, or email communication (S/MIME)
What are solutions for Availability?
What are solutions for Integrity?
Involves implementing cryptographic hashing, hash-based message authentication codes (HMAC), and digital signing mechanisms to assure only authorized subjects can change sensitive information
What is the Clark-Wilson integrity models?
is a mandatory access control model that provides a structure for describing and analyzing an integrity policy for computing systems based on:
-Established transitions from one reliable state to another reliable state
-The principle of separation of duties - the guarantor of the transition and the deployer of the transaction are two separate participants
-Security policies that relate directly to transition integrity
What are solutions for Confidentiality?
-WPA3 cryptography - 192 bits crypto machismo in WPA3-enterprise mode. Dictates CCMP-128 as the minimum level encryption
-Confidentially computing - WAS Nitro enclave is a hardened and heavily insulated compute environment that is initiated and connected to the consumers instance of a virtual machine like windows, Linux, or macOS. No user, including admin or root, nor any application running on the virtual machine =has interactive access to the enclave
What is the Organizational Code of Ethics?
is a set of core guiding principles to notify how and why decisions are made and informs all stakeholders how the company delivers the core ethics