1/57
Comprehensive vocabulary flashcards covering terms, definitions, legal frameworks, concepts, and standard models from IAS Lesson 1.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Cybersecurity
The ongoing effort to protect networked systems and all of the data on them from unauthorized use or harm (theft, alteration, or destruction).
Identity Data
Personal information including full name, birth date, address, mother's maiden name, and government IDs used to open accounts or pass support checks.
Access Data
Authentication credentials such as usernames, passwords, OTPs, cookies, and API keys.
Financial Data
Monetary information including credit cards, e-wallet balances, bank credentials, and payroll records.
Leverage Data
Private records such as personal messages, photos, health records, and browsing history used for extortion or convincing scams.
Personal Security Level
Individual security practices involving unique passwords, password managers, MFA, software updates, and backups.
Organizational Security Level
Institutional protection focus for companies, schools, and hospitals through policies, access control, staff training, and incident response plans.
National Security Level
Government-level security protecting critical infrastructure, enforcing cybercrime laws, operating CERT teams, and maintaining election security.
Amateurs / Script Kiddies
Attackers with little technical skill of their own who rely on tools written by others.
White Hat Hackers
Authorized security testers who discover vulnerabilities through contracted and permitted testing.
Grey Hat Hackers
Hackers who locate vulnerabilities without prior invitation but typically disclose them to the affected entity.
Black Hat Hackers
Unauthorized attackers who exploit security vulnerabilities for personal or financial gain.
Organized Crime Attackers
Structured groups operating ransomware-as-a-service models with quarterly business targets.
Hacktivists
Attackers motivated by political or social causes who carry out attacks designed to gain publicity.
State-sponsored Attackers
Well-funded, patient, and quiet attackers engaging in espionage, sabotage, IP theft, and advanced persistent threats (APT).
Insider Threats
Individuals with legitimate access (employees, contractors, students) who cause harm maliciously or through carelessness.
External Threats
Security threats originating from outside an organization that must exploit unpatched software, weak passwords, or social engineering to gain access.
Virus
Malware that attaches to a legitimate file and requires human action to spread.
Worm
Malware that automatically replicates and spreads across networks without needing human action.
Trojan Horse
Malware that disguises itself as legitimate or useful software while conducting harmful actions in the background.
Ransomware
Malware that encrypts files and demands payment, often stealing data first in double extortion schemes.
Spyware / Keyloggers
Malware that surreptitiously monitors and records keystrokes, screens, web browsing, or camera and microphone feeds.
Rootkit / Backdoor
Software designed to hide its presence on a system and maintain persistent unauthorized access.
Adware / Scareware
Malware that floods devices with advertisements or generates fake security warnings to coerce payments.
Botnet
A collection of compromised, infected devices controlled remotely to execute coordinated attacks.
Social Engineering
The psychological manipulation of people into performing actions or divulging confidential information.
Phishing
A social engineering attack that uses fraudulent messages disguised as trusted entities, typically sent via email.
Spear Phishing
A targeted phishing attack tailored specifically to a single named individual.
Whaling
A targeted phishing attack aimed specifically at high-level executives.
Vishing
A social engineering attack conducted via telephone or voice communications.
Smishing
A social engineering attack delivered via SMS text messages.
Pretexting
A social engineering technique where an attacker invents a scenario or context to justify obtaining sensitive information.
Tailgating
A physical security breach where an unauthorized person closely follows an authorized person through a secured entry.
Denial of Service (DoS / DDoS)
An attack that overwhelms a system or network with traffic to render it unavailable to legitimate users.
Man-in-the-Middle (MITM)
An attack where an adversary positions themselves between a user and a service to read or alter communications.
Credential Stuffing
An automated attack testing stolen username and password combinations across multiple websites.
Zero-day
An exploit targeting a software vulnerability unknown to the software vendor, for which no security patch exists.
RA 10175
The Cybercrime Prevention Act in the Philippines, which penalizes illegal access, data interference, computer fraud, and identity theft.
RA 10173
The Data Privacy Act in the Philippines, regulating entities handling personal data and creating the National Privacy Commission.
McCumber Cube
A cybersecurity framework created by John McCumber (1991) featuring 3 dimensions yielding 3×3×3=27 evaluation cells.
CIA Triad
The core security framework comprising Confidentiality, Integrity, and Availability.
Confidentiality
The security principle ensuring that data is accessible only to authorized users.
Integrity
The security principle ensuring data is accurate, complete, and uncorrupted by unauthorized parties.
Availability
The security principle ensuring systems and data are accessible to authorized users when needed, measured by uptime targets such as 99% uptime (approx. 3.65days downtime/year) or 99.999% uptime (approx. 5min downtime/year).
Data At Rest
The state of data stored on a physical or virtual medium (disk, database, USB) that is not actively moving across a network.
Data In Transit
The state of data moving across a network, WiFi, or API.
Data In Process
The state of data loaded into memory, actively being modified, or displayed by an application.
Technology Safeguards
Security controls implemented via technical systems, including firewalls, antivirus, encryption, MFA, and patching.
Policy & Practice Safeguards
Security controls established through administrative guidelines, acceptable-use policies, and incident response plans.
People Safeguards
Security measures focused on human behavior through training, simulated phishing, and safe reporting practices.
Tactics
An attacker's goal at a specific stage of an intrusion, such as initial access or lateral movement.
Techniques
The general methods attackers use to accomplish specific tactics during an intrusion.
Procedures
The exact step-by-step operational execution or fingerprint used by a specific threat actor group.
Cyber Kill Chain
A 7-stage model (Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, Actions on Objectives) describing the sequence of an intrusion.
ISO 27001
The ISO standard specifying requirements for establishing, operating, and certifying an Information Security Management System (ISMS).
ISO 27002
The ISO standard providing a detailed catalogue of security controls and implementation guidance.
ISO 27005
The ISO standard offering guidelines for information security risk management.
ISMS
Information Security Management System; a management framework integrating policies, controls, and the Plan-Do-Check-Act cycle.