Ch.1 Intro to Information Security

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/41

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:14 PM on 6/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

42 Terms

1
New cards

confidentiality, integrity and availability (CIA)

three basic security protections that must be extended over the information

2
New cards

confidentiality

ensures only approved individuals may access or view info

3
New cards

integrity

ensures that data is correct and unaltered

4
New cards

availability

ensures that information is accessible to authorized users

5
New cards

authentication authorization and accounting (AAA)

provides a framework to control access to computer resources

6
New cards

authentication

act of verifying credentials are authentic and not fabricated

7
New cards

authorization

grants permission for a user to take a particular action

8
New cards

accounting

creates a record that is preserved of who accessed the network and when they disconnected from it

9
New cards

control

safeguard employed within an enterprise to protect the CIA of information. Also called a countermeasure

10
New cards

managerial

controls that use administrative methods

11
New cards

operational

controls that are implemented and executed by people

12
New cards

technical

controls that are incorporated as part of hardware software or firmware

13
New cards

physical

controls that implement security in a defined structure and location

14
New cards

deterrent control

controls that attempt to discourage security violations before they occur

15
New cards

preventive control

controls used to prevent the threat from coming in contact with the vulnerability

16
New cards

detective control

controls designed to identify any threat that has reached the system

17
New cards

compensating control

controls that provide an alternative to normal controls that for some reason cannot be used

18
New cards

corrective control

controls intended to mitigate or lessen the damage caused by the incident

19
New cards

directive control

controls designed to ensure that a particular outcome is achieved

20
New cards

threat actor

an individual or entity responsible for attacks

21
New cards

unskilled attackers

individuals who want to perform attacks yet lack the technical knowledge to carry them out

22
New cards

data exfiltration

threat actor’s motivation of unauthorized copyiong of data

23
New cards

shadow IT

process of bypassing corporate approval for technology purchases (ethical motivation)

24
New cards

insider threat

employees contractors and business partners who pose a threat from the position of a trusted entity

25
New cards

hactivists

threat actors who are strongly motivated by philosophical or political beliefs

26
New cards

nation-state actors

threat actors employed by their own government to carry out attacks

27
New cards

advanced persistent threat (APT)

use innovative attack tools that silently extract data over an extended period of time

28
New cards

attack surface

digital platform that threat actors target for their exploits

29
New cards

supply chain

network that moves a product from its creation to the end-user

30
New cards

supply chain infections

maleware that can be injected into a product during its manufacturing, storage and distribution

31
New cards

open-source software

software where the source code is available for anyone to use freely without restrictions

32
New cards

malicious update

attack in which a software update is infected with malware and distributed

33
New cards

zero-day

vulnerability for which there are no days of advanced warning

34
New cards

misconfigurations

erroneous technology settings

35
New cards

data loss

the destruction of data so that it cannot be recovered

36
New cards

data exfiltration

stealing data to distribute it to other parties

37
New cards

data breach

stealing data to disclose it in an unauthorized fashion

38
New cards

identity theft

taking personally identifiable information to impersonate someone

39
New cards

framework

series of documented processes used to define policies and procedures for implementation and management of security controls in an enterprise environment

40
New cards

benchmarks/secure configuration guides

serve as a guideline for configuring a device or software so that it is resilient to attacks

41
New cards

requests for comments (RFCs)

document “white papers” that are authored by technology bodies employing specialists engineers and scientists who are experts in those areas

42
New cards

threat vector

also known as an attack surface