sec+ 1 & 2

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/60

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:42 PM on 8/25/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

61 Terms

1
New cards

cia

confidential, integrity, availibility

2
New cards

confidential

The fundamental security goal of keeping information and communications private and protecting them from unauthorized access.

3
New cards

integrity

means that the data is stored and transferred as intended, and any modification is unauthorized unless explicitly authorized through proper channels.

4
New cards

availability

  • means that information is readily accessible to those authorized to view or modify it.

Note:

5
New cards

nonrepudiation

The security goal of ensuring that the party that sent a transmission or created data remains associated with that data and cannot deny sending or creating that data.

hat a person cannot deny doing something, such as creating, modifying, or sending a resource.

6
New cards

nsit 5 functions

  • Identify—develop security policies and capabilities. Evaluate risks, threats, and vulnerabilities and recommend security controls to mitigate them.

  • Protect—procure/develop, install, operate, and decommission IT hardware and software assets with security as an embedded requirement of every stage of this operation's lifecycle.

  • Detect—perform ongoing, proactive monitoring to ensure that controls are effective and capable of protecting against new types of threats.

  • Respond—identify, analyze, contain, and eradicate threats to systems and data security.

  • Recover—implement cybersecurity resilience to restore systems and data if other controls are unable to prevent attacks.



<ul><li><p><strong>Identify</strong>—develop security policies and capabilities. Evaluate risks, threats, and vulnerabilities and recommend security controls to mitigate them.</p></li><li><p><strong>Protect</strong>—procure/develop, install, operate, and decommission IT hardware and software assets with security as an embedded requirement of every stage of this operation's lifecycle.</p></li><li><p><strong>Detect</strong>—perform ongoing, proactive monitoring to ensure that controls are effective and capable of protecting against new types of threats.</p></li><li><p><strong>Respond</strong>—identify, analyze, contain, and eradicate threats to systems and data security.</p></li><li><p><strong>Recover</strong>—implement cybersecurity resilience to restore systems and data if other controls are unable to prevent attacks.</p></li><li><p></p></li></ul><p></p>
7
New cards

security controls

A technology or procedure put in place to mitigate vulnerabilities and risk and to ensure the confidentiality, integrity, and availability (CIA) of information.

8
New cards

gap analysis

is a process that identifies how an organization's security systems deviate from those required or recommended by a framework.

9
New cards

IAM

A security process that provides identification, authentication, and authorization mechanisms for users, computers, and other entities to work with organizational assets like networks, operating systems, and applications. Also referred to as identity management (IdM), and access management.

  1. identification

  2. authentication

  3. authorization

  4. accounting


10
New cards

identification

The process by which a user account (and its credentials) is issued to the correct person. Sometimes referred to as enrollment.

11
New cards

authentication

A method of validating a particular entity's or individual's unique credentials.

proving that a subject is who or what it claims to be when it attempts to access the resource.

12
New cards

authorization

determining what rights subjects should have on each resource, and enforcing those rights.

13
New cards

accounting

Tracking authorized usage of a resource or use of rights by a subject and alerting when unauthorized use is detected or attempted.

14
New cards

security control

is designed to give a system or data asset the properties of confidentiality, integrity, availability, and non-repudiation. can be divided into four broad categories based on the way the control is implemented:

  1. managerial

  2. operational

  3. technical

  4. physical


<p><span>is designed to give a system or data asset the properties of confidentiality, integrity, availability, and non-repudiation. can be divided into four broad categories based on the way the control is implemented:</span></p><ol><li><p>managerial</p></li><li><p>operational</p></li><li><p>technical</p></li><li><p>physical</p></li></ol><p></p>
15
New cards

managerial control

the control gives oversight of the information system. Examples could include risk identification or a tool allowing the evaluation and selection of other security controls.

16
New cards

operational control

the control is implemented primarily by people. For example, security guards and training programs

17
New cards

technical control

A category of security control that is implemented as a system (hardware, software, or firmware). may also be described as logical controls.

firewalls, antivirus software, and OS access control models

18
New cards

physical control

controls such as security cameras, alarms, gateways, locks, lighting, and security guards that deter and detect access to premises and hardware are often placed in a separate category from technical controls.

19
New cards

preventative

A type of security control that acts before an incident to eliminate or reduce the likelihood that an attack can succeed.

20
New cards

detective

A type of security control that acts during an incident to identify or record that it is happening.

may not prevent or deter access, but it will identify and record an attempted or successful intrusion

21
New cards

corrective

A type of security control that acts after an incident to eliminate or minimize its impact.

A good example is a backup system that restores data that was damaged during an intrusion.

22
New cards

directive

the control enforces a rule of behavior, such as a policy, best practice standard, or standard operating procedure (SOP).

23
New cards

deterrent

—the control may not physically or logically prevent access, but it psychologically discourages an attacker from attempting an intrusion. This could include signs and warnings of legal penalties against trespass or intrusion.

24
New cards

compensating

A security measure that takes on risk mitigation when a primary control fails or cannot completely meet expectations.

25
New cards

security policy

a formalized statement that defines how security will be implemented within an organization. It describes the means the organization will take to protect the confidentiality, availability, and integrity of sensitive data and resources.

26
New cards

CIO

Company officer with the primary responsibility for management of information technology assets and procedures.

27
New cards

CTO

Company officer with the primary role of making effective use of new and emerging computing platforms and innovations.

28
New cards

CSO

Typically the job title of the person with overall responsibility for information assurance and systems security.

29
New cards

ISSO (information systems security officer)

Organizational role with technical responsibilities for implementation of security policies, frameworks, and controls.

30
New cards

soc (security operations center)

The location where security professionals monitor and protect critical information assets in an organization.

31
New cards

devops

A combination of software development and systems operations, and refers to the practice of integrating one discipline with the other.

32
New cards

devsecops

A combination of software development, security operations, and systems operations, and refers to the practice of integrating each discipline with the others.

33
New cards

CIRT (computer incident response team)

Team with responsibility for incident response.

must have expertise across a number of business domains (IT, HR, legal, and marketing, for instance).

34
New cards

risk

is a measure of the likelihood and impact of a threat actor being able to exploit a vulnerability in your organization's security systems.

35
New cards

vulnerability

A weakness that could be triggered accidentally or exploited intentionally to cause a security breach.

36
New cards

threat

A potential for an entity to exercise a vulnerability (that is, to breach security)

37
New cards

threat actor attributes

  • internal/external

  • sophistication/capability

  • resources/funding


38
New cards

service disruption

A type of attack that compromises the availability of an asset or business process.

39
New cards

data exfiltration

The process by which an attacker takes data that is stored inside of a private network and moves it to an external network.

40
New cards

disinformation

A type of attack that falsifies an information resource that is normally trusted by others.

41
New cards

hacker

describes an individual who has the skills to gain access to computer systems through unauthorized or unapproved means

42
New cards

hacktivist

A threat actor that is motivated by a social issue or political cause.

43
New cards

ATP (advanced persistent threat)

Threat actors with the ability to craft novel exploits and techniques to obtain, maintain, and diversify unauthorized access to network systems over a long period.

44
New cards

nation state actors

A type of threat actor that is supported by the resources of its host country's military and security services.

45
New cards

unintentional insider threat

A threat actor that causes a vulnerability or exposes an attack vector without malicious intent.

46
New cards

shadow it

Computer hardware, software, or services used on a private network without authorization from the system owner.

47
New cards

attack surface

is all the points at which a malicious threat actor could try to exploit a vulnerability. Any location or method where a threat actor can interact with a network port, app, computer, or user

48
New cards

threat vector

A specific path by which a threat actor gains unauthorized access to a system.

49
New cards

vulnerable software

contains a flaw in its code or design that can be exploited to circumvent access control or to crash the process.

50
New cards

unsecured network

Configuration that exposes a large attack surface, such as through unnecessary open service ports, weak or no authentication, use of default credentials, or lack of secure communications/encryption.

lacks CIA

51
New cards

lure

An attack type that will entice a victim into using or opening a removable device, document, image, or program that conceals malware.

ex: removable devices, exe file, doc file, image file

52
New cards

message based vector

any features that allow direct messaging to network users must be considered as part of the potential attack surface. email, sms, im, social media, 0 click

53
New cards

supply chain

An attack that targets the end-to-end process of manufacturing, distributing, and handling goods and services.

54
New cards

procurement management

  • Supplier—obtains products directly from a manufacturer to sell in bulk to other businesses. This type of trade is referred to as business to business (B2B).

  • Vendor—obtains products from suppliers to sell to retail businesses (B2B) or directly to customers (B2C). A vendor might add some level of customization and direct support.

  • Business Partner—implies a closer relationship where two companies share quite closely aligned goals and marketing opportunities.


55
New cards

human vector

People—employees, contractors, suppliers, and customers—represent part of the attack surface of any organization.

56
New cards

social engineering

Using persuasion, manipulation, or intimidation to make the victim violate a security policy. The goal might be to gain access to an account, gain access to physical premises, or gather information.

57
New cards

pretexting

Social engineering tactic where a team will communicate, whether directly or indirectly, a lie or half-truth in order to get someone to believe a falsehood.

58
New cards

phishing

A email-based social engineering attack in which the attacker sends email from a supposedly reputable source, such as a bank, to try to elicit private information from the victim.

vishing-voice

smishing-sms

59
New cards

pharming

An impersonation attack in which a request for a website, typically an e-commerce site, is redirected to a similar-looking, but fake, website.

60
New cards

business email compormise

An impersonation attack in which the attacker gains control of an employee's account and uses it to convince other employees to perform fraudulent actions.

61
New cards

watering hole

An attack in which an attacker targets specific groups or organizations, discovers which websites they frequent, and injects malicious code into those sites.