Week6_2
Week6_2
• Everything is a file
• Three types of permissions in UNIX
• Read, write, and execute
• Three classes of subjects
• Owner, group, and world
• Each file has 9* bits to set
• A generalization of ABAC
• Relies on three things
• Subject attributes (think RBAC roles)
• Object attributes (think RBAC permissions)
• Environment attributes
• Should a bank teller access money at 1AM?
• You should know it exists. We won’t cover here
Social
Engineering
Social Engineering
• Link: https://www.youtube.com/watch?v=lc7scxvKQOo
Tactics
• Authority
• ”This is the CEO of your company, and I need something from
you...”
• Intimidation
• “Do this or something bad will happen to you”
• Consensus
• “99% of users rate 5 stars!”
• Scarcity
• “Hurry, there’s only 3 left!”
Tactics, Cont.
• Familiarity
• “Hi, it’s Dave, and I called earlier about the routine IT
update...”
• Urgency
• “This has to be done within the next two hours”
How To Lie Steps
How To (Establishing an Effective Lie)
Premises security
• Also known as corporate or facilities security
• Protects the people and property within an entire area, facility, or
building(s), and is usually required by laws, regulations, and fiduciary
obligations
• Provides perimeter security, access control, smoke and fire detection, fire
suppression, some environmental protection, and usually surveillance
systems, alarms, and guards
Physical Security Overview
Concerns include
information system
Prevent damage to
hardware, physical
physical infrastructure
facility, support facilities,
Involves two and personnel
complementary
requirements: Prevent physical Includes vandalism, theft
infrastructure misuse of equipment, theft by
that leads to the misuse copying, theft of
or damage of protected services, and
information unauthorized entry
Common Natural Disasters
Common Temperature Thresholds
Water Damage
Due diligence
Floodwater
should be
leaving a muddy
performed to
residue and
ensure that water
suspended
from as far as two
material in the
floors above will
water
not create a hazard
Takeaways