Across
- 4. Security controls that deter and detect access to premises and hardware
- 6. The level of hazard posed by vulnerabilities and threats
- 9. Security controls that identify and record attempted or successful intrusions
- 10. Security controls implemented as hardware, software, or firmware
- 16. Security controls implemented primarily by people
- 17. Ensuring data is stored and transferred as intended, without unauthorized modifications
- 18. Security controls that eliminate or reduce the likelihood of an attack succeeding
- 19. Determining and enforcing rights on resources
- 20. Security controls that eliminate or reduce the impact of a security policy violation
- 21. Tricking targets into interacting with malicious resources disguised as trusted ones
- 22. The potential for someone or something to exploit a vulnerability and breach security
- 23. Security controls that enforce rules of behavior, policies, and procedures
- 24. Security controls that provide oversight of the information system
Down
- 1. Identifying deviations between current security systems and framework requirements
- 2. Proving the identity of a subject attempting to access a resource
- 3. Security controls that psychologically discourage attackers
- 5. Protecting data resources from unauthorized access, attack, theft, or damage
- 7. Ensuring information is accessible to authorized users when needed
- 8. Creating an account or ID representing the user, device, or process
- 11. Security controls that substitute for principal controls to provide equivalent protection
- 12. The path or tool used by a threat actor to execute an attack
- 13. A weakness that can be accidentally triggered or intentionally exploited
- 14. Tracking and alerting on the usage of resources
- 15. Ensuring that a person cannot deny performing an action
- 20. Ensuring information can only be read by authorized individuals
