Domain 3 · 13% of the exam
Security Architecture and Engineering
Security professionals must understand the principles of secure system design and the different tools and techniques that can be used to protect information and systems. This includes not only technical controls, such as cryptography and access controls, but also security models, testing methodologies, and the measures necessary to protect systems and equipment from physical threats.
Learning objectives
- Explain the significance of basic secure design principles.
- Compare and contrast the key security characteristics of security models.
- Explain the hardware foundations of security. (
- Apply security principles to different information systems and their environments.
- Determine the best application of cryptographic approaches to solving organizational information security needs.
- Manage the use of certificates and digital signatures to meet organizational information security needs.
- Apply different cryptographic management solutions to meet organizational information security needs.
- Describe defenses against common cryptanalytic attacks.
- Apply the lessons of Crime Prevention through Environmental Design (CPTED)| to information systems security design and operation.
- Identify information security implications of various physical facilities, systems and infrastructure.
Key topics
- Secure Design Principles
- Security Models
- Controls & Systems Security Requirements
- Security Capabilities
- Vulnerabilities of Security Architectures & Designs
- Cryptographic Solutions
- Cryptanalytic Attacks
- Secure Site & Facility Design
- Site & Facility Security Controls
- Information System Life Cycle
Lessons
Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.
- 01Least PrivilegeThe principle of least privilege states that no employee should have access to or authority over any system or data unless it is necessary for the employee to perform their job function.2 slides · 1 min read
- 02Shared ResponsibilityEach shared design responsibility aspect represents the potential for the compromise of an information system.2 slides · 1 min read
- 03Zero TrustThe zero-trust concept is that organizations should not trust without first verifying access.2 slides · 1 min read
- 04Sending Confidential MessagesBecause the keys are mutually exclusive but related to each other mathematically using a one-way function, any message that is encrypted with a public key can only be decrypted with the corresponding other half of the key pair, the private key.8 slides · 3 min read
- 05Hybrid CryptographyHybrid cryptography is where we use the advantages of both symmetric and asymmetric key cryptography.4 slides · 1 min read
- 06Hybrid Cryptography ExamplesHybrid cryptography blends symmetric and asymmetric methods, combining strengths to provide secure, efficient encryption for data exchange.7 slides · 3 min read
- 07Ciphertext-based AttacksThe ciphertext-only attack is one of the most difficult because the attacker has so little information with which to start.5 slides · 1 min read
- 08Fire Prevention, Detection, and SuppressionFire protection safeguards systems by combining preventive measures, staff training, and response strategies to minimize damage and ensure operational continuity.7 slides · 4 min read
- 09Fire Prevention, Detection, and Suppression - Water and Gas BasedWater-based suppression is generally effective for Class A fires.6 slides · 3 min read
- 10Essential Characteristics of Cloud ComputingCloud computing offers on-demand resources with self-service, broad network access, rapid elasticity, resource pooling, and measured usage.2 slides · 1 min read
- 11Hashing - Asymmetric Encryption for Data and Message IntegrityHashing: Asymmetric Encryption for Data and Message Integrity5 slides · 1 min read
- 12Privacy by DesignPrivacy by design is an approach to incorporate privacy into information technology throughout the entire system development life cycle.3 slides · 1 min read
- 13Graham-DenningGraham-Denning is primarily concerned with how subjects and objects are created, how subjects are assigned rights or privileges, and how ownership of objects is managed.6 slides · 1 min read
- 14Bell–LaPadulaThe Bell-LaPadula model is a security framework that enforces data confidentiality by restricting access based on security clearance levels and preventing unauthorized information flow.4 slides · 1 min read
- 15Security Models - BLP and Biba Model PropertiesThough there is a lot to understand in security models, take a moment to compare and contrast the BLP and Biba model properties.3 slides · 1 min read
- 16One Time Pad1. Each party has a book (pad) of symmetric keys. Each key is at least as long as the message to be encrypted.8 slides · 2 min read
- 17BibaThe Biba model is a security framework that enforces data integrity by preventing users from modifying data at higher integrity levels or reading from lower ones.3 slides · 1 min read
- 18Evidence Storage and the Chain of CustodyEvidence storage facilities or rooms are special-access areas with strictly limited access and may be aggressively monitored.4 slides · 1 min read
- 19Clark-WilsonBiba only addresses one of three key integrity goals. The Clark-Wilson model improves on Biba by focusing on integrity at the transaction level and addressing three major goals of integrity in a commercial environment.3 slides · 1 min read
- 20Public Key Infrastructure (PKI)A PKI is a set of system, software, communication, and cryptography protocols required to use, manage, and control public key cryptography.6 slides · 1 min read
- 21Harrison, Ruzzo, Ullman (HRU)This model is very similar to the Graham-Denning model and composes a set of generic rights and a finite set of commands. It is also concerned with situations in which a subject should be restricted from gaining particular privileges.4 slides · 1 min read
- 22Brewer and NashThis model focuses on preventing conflict of interest when a given subject has access to objects with sensitive information associated with two competing parties.3 slides · 1 min read
- 23Service ModelsCloud service providers offer service models, such as infrastructure, platform, and software as a service, delivering scalable computing resources, development environments, or complete applications on demand.5 slides · 2 min read
- 24Separation of Duties (SoD)To attenuate possibilities for corruption and theft, the organization can craft an environment where no individual person can complete an entire trusted action.2 slides · 1 min read
- 25Other Uses of Digital SignaturesDigital signature can be used for other things such as distributed ledger technology (blockchain), Message Integrity Codes (MICs) and Message Authentication Codes (MACs). Let's take a look at a few.7 slides · 4 min read
- 26Key Distribution, Encryption, and WrappingKey distribution, encryption, and wrapping are methods for securely sharing and protecting cryptographic keys during storage or transmission.4 slides · 2 min read
- 27Server Rooms and Data CentersServer rooms and data centers are secure, climate-controlled spaces that house servers and network equipment for storing, processing, and managing digital data.4 slides · 2 min read
- 28Digital Certificates, Signatures, and ManagementThe purpose of a digital signature is to provide the same level of accountability for electronic transactions where a handwritten signature is not possible or feasible.6 slides · 3 min read
- 29Storage Media Protection and ManagementIt's tempting to think that the ubiquitous nature of cloud-hosted storage has eliminated the need for physical copies of important datasets or software to be created, stored, protected, managed, used, and then suitably destroyed at the end of their records…4 slides · 1 min read
- 30Wiring Closets and Intermediate Distribution FacilitiesThe facility wiring infrastructure or "cable plant" is integral to overall information system security and reliability.5 slides · 2 min read
- 31Plaintext-based AttacksAs the name of this attack implies, the attacker has access to known samples of plaintext.7 slides · 2 min read
- 32Brute Force AttacksBrute force attacks are also referred to as exhaustive search attacks. This technique simply involves trying every possible combination,specifically the key, until the correct one is identified.5 slides · 2 min read
- 33Client-based Systems Vulnerabilities and MitigationsEnd users in most cases physically control these devices. This allows for end user modification or removal from enterprise control of the system. They may be more susceptible to loss or theft for this reason.4 slides · 1 min read
- 34Distributed SystemsDistributed systems coordinate multiple independent computers to appear as a single system, enabling scalability, fault tolerance, and resource sharing across networks.4 slides · 1 min read
- 35Distributed Systems Vulnerabilities and Mitigations3 slides · 1 min read
- 36Social Engineering for Key DiscoverySocial engineering exploits human behavior to trick individuals into revealing sensitive authentication information, such as access codes or cryptographic keys.3 slides · 1 min read
- 37Site PlanningOrganizations plan alternate sites to ensure critical operations can continue during disruptions, supporting resilience through redundancy, backup systems, and secure data availability.5 slides · 2 min read
- 38Ransomware and Ransom AttacksBetween 2016 and 2018, ransomware attacks increased by more than 350% worldwide and are widely recognized as the second greatest threat to organizational information assets, following insider threats.8 slides · 2 min read
- 39Utilities and Heating, Ventilation, and Air Conditioning (HVAC)The utility services for most facilities generally include electrical, telecommunications, water, sewer, natural gas, steam, and hot and cold water supply for HVAC. Compromise of any of these systems could render the facility unusable, or significantly…3 slides · 2 min read
- 40Additional Algebraic AttacksAdditional algebraic attacks are listed below. Recall these attacks try to find correlations between certain elements to find weaknesses in multiple encryption cycles within the cryptosystem itself to try and yield the correct key.6 slides · 3 min read
- 41Additional AttacksBoth types of spoofing are forms of a common security violation known as a manin-the-middle (MITM) attack. This occurs when an attacker routes information between two users through their own machine without the knowledge of the two individuals…3 slides · 1 min read
- 42Examples of Asymmetric Encryption AlgorithmsRSA is an asymmetric key cryptosystem that offers both encryption and digital signatures that provides non-repudiation, integrity, and authentication of source Ron Rivest, Adi Shamir, and Leonard Adleman developed RSA in 1977, and as you might have…6 slides · 2 min read
- 43Industrial Control Systems (ICS)Supervisory control Distributed control Programmable and data acquisition systems (DCSs) logic controllers (SCADA) (PLCs)3 slides · 1 min read
- 44Industrial Control Systems (ICS) Vulnerabilities and MitigationsIndustrial Control Systems (ICS) Vulnerabilities and Mitigations4 slides · 2 min read
- 45Edge Computing and Fog Computing Vulnerabilities and MitigationsEdge Computing and Fog Computing Vulnerabilities and Mitigations3 slides · 1 min read
- 46Session Keys - Creation, ProtectionThere are a number of issues that pertain to scalability and cryptographic key integrity:3 slides · 2 min read
- 47Database Systems VulnerabilitiesVulnerabilities specific to the database system itself include the following:4 slides · 1 min read
- 48Crime Prevention through Environmental Design (CPTED) - Applying to Building DesignCrime Prevention through Environmental Design (CPTED) Applying to Building Design3 slides · 2 min read
- 49Cloud-based Systems Vulnerabilities and Mitigations3 slides · 1 min read
- 50PowerData centers and information systems consume significant power, driving operational costs and environmental impact, making energy efficiency a core design and management priority.6 slides · 1 min read
- 51High-performance Computing (HPC) SystemsWe will discuss high performance computing (HPC) systems and edge computing systems.5 slides · 1 min read
- 52MicroservicesMicroservices are an architectural approach where applications are made up of small, independent services that communicate with each other and are designed for scalability and easy deployment in cloud environments.3 slides · 2 min read
- 53Edge and Fog Computing ArchitecturesEdge and fog computing architectures process data closer to its source, reducing latency and bandwidth demands while enhancing responsiveness for connected systems.5 slides · 2 min read
- 54Case Study - Northgate Information SolutionsCase studyNorthgate Information Solutions (NIS) is a major supplier of software applications and outsourcing solutions to the public sector. Located in Hemel Hempstead, UK, it was located adjacent to the Buncefield oil storage depot.6 slides · 3 min read
- 55Possible Responses (Case Study - Northgate Information Solutions)Case study answersPossible Responses (Case Study: Northgate Information Solutions)1 slides · 1 min read
- 56Implementation and Algorithm AttacksThe main types of implementation attacks include the following:7 slides · 2 min read
- 57Restricted and Work Area StorageRestricted area security applies to any spaces or rooms within the facility where highly sensitive work occurs or information is stored. This includes secure facilities and classified workspaces.4 slides · 2 min read
- 58Trust but Verify"Trust but verify" means granting access cautiously while continuously monitoring and validating activity to prevent misuse or breaches in security systems.2 slides · 1 min read
- 59Goal and Drawbacks of KerberosThe primary goal of Kerberos is to ensure private communications between systems over a network. However, in managing the encryption keys, it acts to authenticate each of the principals in the communication based on the possession of the secret key, which…4 slides · 1 min read
- 60Internet of ThingsThe Internet of Things connects everyday devices to networks, enabling data exchange and automation while raising new security, privacy, and management challenges.3 slides · 2 min read
- 61Keep It SimpleSimplicity is a fundamental principle in designing and managing secure systems, influencing both user behavior and the reliability of security controls.2 slides · 1 min read
- 62Secure DefaultsSystems should adopt secure defaults, ensuring the most restrictive, leastprivilege settings are enabled to minimize vulnerabilities from the start.3 slides · 1 min read
- 63Algorithm and Protocol GovernanceEffective algorithm and protocol governance requires establishing policies and controls that ensure cryptographic methods are securely implemented, properly maintained, and comply with organizational or regulatory standards.2 slides · 1 min read
- 64Data Encryption Standard and Advanced Encryption StandardThe Data Encryption Standard (DES) and Advanced Encryption Standard (AES) are symmetric-key algorithms used to encrypt and decrypt data, with AES offering stronger security and efficiency than DES.5 slides · 4 min read
- 65Fail SecurelyFail-secure design is a security principle that ensures systems default to a secure state in the event of a failure, whether due to system crashes, design flaws, or attacks.3 slides · 2 min read
- 66Threat ModelingThreat modeling is a proactive process that identifies potential security risks, evaluates their impact, and guides the design of safeguards to reduce vulnerabilities before attacks occur.4 slides · 2 min read
- 67Key Storage and DestructionAll keys need to be protected against modification, and secret and private keys need to be protected against unauthorized disclosure.3 slides · 1 min read
- 68Embedded SystemsEmbedded systems are specialized computing devices designed to perform dedicated functions within larger systems, often with real-time constraints and limited hardware resources.5 slides · 4 min read
- 69Key ManagementKey management involves generating, storing, distributing, and rotating cryptographic keys securely to protect data and ensure authorized access in encryption systems.5 slides · 2 min read
- 70Case Study - StuxnetCase studyThe Stuxnet worm, identified in 2010, stands as an unprecedented cyber-weapon that showcased a level of sophistication previously unseen in the realm of cybersecurity. Its discovery marked a watershed moment, revealing a new era in cyber-espionage and…6 slides · 2 min read
- 71Possible Responses (Case Study - Stuxnet)Case study answers1. How did the Stuxnet worm demonstrate the application of secure design principles in its engineering processes?1 slides · 1 min read
