Fundamentals of Information Systems Security - Chapter 1

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/34

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering fundamental concepts, tenets, domains, policy frameworks, and data classification standards from Chapter 1 of Fundamentals of Information Systems Security.

Last updated 11:42 PM on 10/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

35 Terms

1
New cards

Internet

A worldwide network with approximately 5.4+ billion users that links communication networks to one another.

2
New cards

World Wide Web

A system that defines how documents and resources are related across a network of computers, connecting websites, webpages, and digital content.

3
New cards

Cyberspace

All the accessible users, networks, webpages, and applications working in the worldwide electronic realm.

4
New cards

Internet of Things (IoT)

A network connecting personal devices, home devices, and vehicles to the Internet, supporting any-to-any connectivity.

5
New cards

Risk

The level of exposure to some event that has an effect on an asset.

6
New cards

Threat

Any action, either natural or human induced, that could damage an asset.

7
New cards

Vulnerability

A weakness that allows a threat to be realized or to negatively impact an asset.

8
New cards

Information System

Hardware, operating system, and application software that work together to collect, process, and store data for individuals and organizations.

9
New cards

Information Systems Security

The collection of activities that protect the information system and the data stored in it.

10
New cards

Tenets of Information Security

The three core principles of security consisting of confidentiality, integrity, and availability (C-I-A).

<p>The three core principles of security consisting of confidentiality, integrity, and availability (C-I-A).</p>
11
New cards

Confidentiality

The tenet of information security ensuring that only authorized users can view information.

12
New cards

Integrity

The tenet of information security ensuring that only authorized users can change information and that data remains valid and accurate.

13
New cards

Availability

The tenet of information security ensuring that information is accessible by authorized users whenever they request it.

14
New cards

Cryptography

The practice of hiding data and keeping it inaccessible to unauthorized users.

15
New cards

Encryption

The process of transforming data from cleartext into ciphertext.

16
New cards

Ciphertext

The scrambled data that results from encrypting cleartext.

17
New cards

Availability Calculation

The mathematical ratio determining system availability: A=Total UptimeTotal Uptime+Total DowntimeA = \frac{\text{Total Uptime}}{\text{Total Uptime} + \text{Total Downtime}}.

18
New cards
<p>Seven Domains of an IT Infrastructure</p>

Seven Domains of an IT Infrastructure

The domain-based organization of enterprise IT systems comprising User, Workstation, LAN, LAN-to-WAN, WAN, Remote Access, and System/Application domains.

19
New cards

User Domain

The people and processes that access an organization's information system.

20
New cards

Workstation Domain

All the workstations where the production of an organization takes place, serving as the point of entry into the IT infrastructure.

21
New cards

LAN Domain

Encompasses the local area network (LAN), a collection of computers and devices connected to one another or to a common connection medium.

22
New cards

LAN-to-WAN Domain

The boundary where the IT infrastructure links to a wide area network (WAN) and the public Internet.

23
New cards

WAN Domain

The domain that connects remote locations, encompassing public networks such as the Internet.

24
New cards

Remote Access Domain

The domain that connects remote and mobile users to the organization's internal IT infrastructure.

25
New cards

System/Application Domain

The domain holding all mission-critical systems, applications, databases, and intellectual property assets.

26
New cards

Weakest Link in IT Security

Humans (users), due to lack of awareness, policy violations, or vulnerability to social engineering and mistakes.

27
New cards

Policy

A short written statement that defines a course of action applying to an entire organization.

28
New cards

Standard

A detailed written definition of how software and hardware are to be used within an organization.

29
New cards

Procedures

Written instructions detailing step-by-step how to carry out policies and standards.

30
New cards

Guidelines

Suggested courses of action for using a policy, standard, or procedure.

31
New cards
<p>Hierarchical IT Security Policy Framework</p>

Hierarchical IT Security Policy Framework

A structured policy model where overarching policies are supported beneath by standardized technical rules, step-by-step procedures, and suggested guidelines.

32
New cards

PCI DSS

Payment Card Industry Data Security Standard; a global standard requiring the protection of consumer privacy data with proper security controls.

33
New cards

Top Secret

U.S. federal government data classification applied to information that would cause grave damage to national security if disclosed.

34
New cards

Secret

U.S. federal government data classification applied to information that would cause serious damage to national security if disclosed.

35
New cards

Confidential (Government Classification)

U.S. federal government data classification applied to information that would cause damage to national security if disclosed.