1/34
Vocabulary flashcards covering fundamental concepts, tenets, domains, policy frameworks, and data classification standards from Chapter 1 of Fundamentals of Information Systems Security.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Internet
A worldwide network with approximately 5.4+ billion users that links communication networks to one another.
World Wide Web
A system that defines how documents and resources are related across a network of computers, connecting websites, webpages, and digital content.
Cyberspace
All the accessible users, networks, webpages, and applications working in the worldwide electronic realm.
Internet of Things (IoT)
A network connecting personal devices, home devices, and vehicles to the Internet, supporting any-to-any connectivity.
Risk
The level of exposure to some event that has an effect on an asset.
Threat
Any action, either natural or human induced, that could damage an asset.
Vulnerability
A weakness that allows a threat to be realized or to negatively impact an asset.
Information System
Hardware, operating system, and application software that work together to collect, process, and store data for individuals and organizations.
Information Systems Security
The collection of activities that protect the information system and the data stored in it.
Tenets of Information Security
The three core principles of security consisting of confidentiality, integrity, and availability (C-I-A).

Confidentiality
The tenet of information security ensuring that only authorized users can view information.
Integrity
The tenet of information security ensuring that only authorized users can change information and that data remains valid and accurate.
Availability
The tenet of information security ensuring that information is accessible by authorized users whenever they request it.
Cryptography
The practice of hiding data and keeping it inaccessible to unauthorized users.
Encryption
The process of transforming data from cleartext into ciphertext.
Ciphertext
The scrambled data that results from encrypting cleartext.
Availability Calculation
The mathematical ratio determining system availability: A=Total Uptime+Total DowntimeTotal Uptime.

Seven Domains of an IT Infrastructure
The domain-based organization of enterprise IT systems comprising User, Workstation, LAN, LAN-to-WAN, WAN, Remote Access, and System/Application domains.
User Domain
The people and processes that access an organization's information system.
Workstation Domain
All the workstations where the production of an organization takes place, serving as the point of entry into the IT infrastructure.
LAN Domain
Encompasses the local area network (LAN), a collection of computers and devices connected to one another or to a common connection medium.
LAN-to-WAN Domain
The boundary where the IT infrastructure links to a wide area network (WAN) and the public Internet.
WAN Domain
The domain that connects remote locations, encompassing public networks such as the Internet.
Remote Access Domain
The domain that connects remote and mobile users to the organization's internal IT infrastructure.
System/Application Domain
The domain holding all mission-critical systems, applications, databases, and intellectual property assets.
Weakest Link in IT Security
Humans (users), due to lack of awareness, policy violations, or vulnerability to social engineering and mistakes.
Policy
A short written statement that defines a course of action applying to an entire organization.
Standard
A detailed written definition of how software and hardware are to be used within an organization.
Procedures
Written instructions detailing step-by-step how to carry out policies and standards.
Guidelines
Suggested courses of action for using a policy, standard, or procedure.

Hierarchical IT Security Policy Framework
A structured policy model where overarching policies are supported beneath by standardized technical rules, step-by-step procedures, and suggested guidelines.
PCI DSS
Payment Card Industry Data Security Standard; a global standard requiring the protection of consumer privacy data with proper security controls.
Top Secret
U.S. federal government data classification applied to information that would cause grave damage to national security if disclosed.
Secret
U.S. federal government data classification applied to information that would cause serious damage to national security if disclosed.
Confidential (Government Classification)
U.S. federal government data classification applied to information that would cause damage to national security if disclosed.