1/99
A comprehensive collection of 100 vocabulary flashcards reviewing key concepts, threats, life cycles, risk management formulas, policies, and access controls for IAS101.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Protecting Functionality
One of the four essential functions of information security that ensures the organization can continue its core operations.
Safe Application Operation
One of the four essential functions of information security that enables IT systems to run applications securely.
Data Protection
An essential function of information security that safeguards the information the organization collects and utilizes.
Asset Safeguarding
An essential function of information security that protects the organization's technological investments.
Threat
A category of entities (objects, persons, etc.) that pose a danger to an asset.
Vulnerability
An identified weakness in a system where controls are absent or ineffective.
Human Error Threat
A category of security threat consisting of accidents or employee mistakes.
Intellectual Property Compromise
A category of security threat involving piracy and copyright infringement.
Deliberate Software Attacks
A category of security threat that includes malicious software like viruses, worms, and Denial of Service (DoS) attacks.
Technological Obsolescence
A security threat resulting from using outdated or antiquated technologies.
Malicious Code
Software intended to destroy or steal data, including viruses, worms, and Trojan horses.
Brute Force Attack
Trying every possible password combination using computing resources to gain unauthorized access.
Dictionary Attack
A variation of a brute force attack that uses a list of commonly used passwords.
Denial of Service (DoS)
An attack that floods a target system with requests to overwhelm it and render it unavailable.
Distributed Denial of Service (DDoS)
A Denial of Service attack that utilizes many zombie computers to overwhelm a target.
IP Spoofing
Forging a source IP address to make a message appear to originate from a trusted host.
Man-in-the-Middle Attack
Impersonating an entity to eavesdrop on or divert data between two communicating parties.
Social Engineering
Using social skills to trick people into revealing sensitive credentials or information.
Cross-Site Scripting (XSS)
A client-side injection attack where malicious scripts are executed in a victim's browser via a legitimate web page.
SQL Injection (SQLi)
An attack that interferes with database queries to view, modify, or delete database data.
Parameterized Queries
Prepared statements used instead of string concatenation to prevent SQL injection attacks.
Systems Development Life Cycle (SDLC)
A phased development model consisting of 1. Investigation, 2. Analysis, 3. Logical Design, 4. Physical Design, 5. Implementation, and 6. Maintenance and Change.
Security Systems Development Life Cycle (SecSDLC)
A specialized version of the Systems Development Life Cycle focused specifically on managing information security.
Top-Down Approach (SecSDLC)
A security implementation process that starts with senior management (CEO, CIO, CISO) and filters down through the organization.
Bottom-Up Approach (SecSDLC)
A security effort originating at the grassroots level by technicians that often lacks strategic coordination.
Computer Fraud and Abuse Act (1986)
The cornerstone of federal computer-related law in the United States.
HIPAA (1996)
Health Insurance Portability and Accountability Act of 1996, which protects the confidentiality and security of health care data.
Sarbanes-Oxley Act (2002)
U.S. federal law enacted in 2002 focusing on the accuracy of financial reporting for publicly traded companies.
Ten Commandments of Computer Ethics
Ethical guidelines including rules such as 'Thou shalt not use a computer to harm other people' and 'Thou shalt not snoop around in other people's computer files'.
Linux Operating System
A Unix-like operating system core originally written by Linus Torvalds.
Linux Philosophy
The design principle to make each program do one thing well and expect the output of one program to be the input of another.
Linux File System Commands
Essential file system commands including ls (list), cd (change directory), pwd (print working directory), and mkdir (make directory).
Linux Network Commands
Essential network diagnostic and connectivity commands including ssh (secure shell), ping, and nslookup.
Linux Help Commands
Documentation and manual tools in Linux, specifically man (manual pages) and info.
Risk
The probability that something unwanted will happen along with its consequences.
Risk Management
The process of identifying risks represented by vulnerabilities in an organization's information assets/infrastructure and taking steps to reduce the risk to an acceptable level.
Three Major Undertakings of Risk Management
The sequential components of risk management consisting of 1. Risk Identification, 2. Risk Assessment, and 3. Risk Control.
Risk Identification
The process of identifying and assessing threats to an organization, its operations, and its workforce.
Information Asset Categories
The six categories evaluated during asset identification: People, Procedures, Data and information, Software, Hardware, and Networking elements.
Asset Identification and Inventory
The enumeration and classification of an organization's assets to determine their relative priority.
Confidential Classification
The information classification level designated for the most sensitive information that must be tightly controlled.
Internal Classification
The information classification level intended for employees, authorized contractors, and approved third parties.
External Classification
The information classification level designated for information approved for public release.
Threat Assessment
The process of examining each threat to determine its potential to endanger the organization.
Risk Assessment
The process of evaluating the relative risk for each vulnerability by assigning a risk rating/score to information assets.
Risk Control Strategies (D-T-M-A-T)
The five risk control strategies: Defend, Transfer, Mitigate, Accept, and Terminate.
Defend Strategy
A risk control strategy that attempts to prevent exploitation of a vulnerability via application of policy, education/training, and application of technology.
Transfer Strategy
A risk control strategy that attempts to shift risk to other assets, processes, or organizations (e.g., outsourcing, insurance, service contracts).
Mitigate Strategy
A risk control strategy that attempts to reduce the impact caused by exploitation through Incident Response, Disaster Recovery, or Business Continuity plans.
Accept Strategy
A risk control strategy where an organization chooses to accept the outcome/risk of exploitation based on probability, cost-benefit analysis, and feasibility.
Terminate Strategy
A risk control strategy where an organization avoids business activities that introduce uncontrollable risks.
Single Loss Expectancy (SLE)
The value of the most likely loss from an attack, calculated using the formula SLE=Asset Value×Exposure Factor.
Annualized Rate of Occurrence (ARO)
How often a specific type of attack is expected to occur on an annual basis.
Annualized Loss Expectancy (ALE)
The expected loss considering attack frequency, calculated using the formula ALE=SLE×ARO.
Exposure Factor (EF)
The percentage loss that a specific threat would have on a specific asset.
Quantitative Risk Measures
Metrics-based measures including number of successful attacks, staff-hours spent, dollars spent, number of security personnel, and value of lost information.
Qualitative Risk Measures
Process-based measures that are strategic and less focused on numbers, examining activities used to achieve organizational goals.
Risk Appetite
The amount and nature of risk an organization is willing to accept.
Residual Risk
The risk that remains even after security controls have been applied.
Strategic Planning
Process that sets the long-term direction of the organization and focuses resources toward clearly defined goals.
Chief Information Security Officer (CISO)
Executive who creates the strategic plan for achieving information security objectives alongside the information security management team.
Information Security Governance
Responsibilities and practices of executive management to provide strategic direction, ensure objectives are achieved, manage risks appropriately, and use resources responsibly.
Security Policy
A plan or course of action giving instructions from senior management that must not conflict with laws, must stand up in court, and must be properly administered and documented.
Security Standards
Detailed statements of what must be done to comply with an established security policy.
Enterprise Information Security Policy (EISP)
General organizational security policy that supports mission/vision and sets strategic direction and scope for the entire organization.
Issue-Specific Security Policy (ISSP)
Policy dealing with a specific technology or security issue such as email, internet use, hacking, or personal devices on company networks.
Systems-Specific Security Policy (SysSP)
Policy used as standards or procedures for configuring or maintaining specific systems.
Information Security Blueprint
The foundation for designing, selecting, and implementing security program elements including policies, risk management, education/training, controls, and maintenance.
Managerial Controls
High-level security controls focusing on administrative management, policy, and organizational governance.
Operational Controls
Security controls addressing day-to-day operations, processes, and human activities.
Technical Controls
Tactical security controls executed through technology, software, and hardware configurations.
Defense in Depth
A layered security approach using multiple security controls and safeguards such as policy, training and education, and technology.
Security Perimeter
The boundary between the organization's security environment and the outside world.
Firewall
A security system that controls information moving between an untrusted network (Internet/outside) and a trusted internal network.
Demilitarized Zone (DMZ)
A buffer or no-man's-land between internal and external networks, often used for Web servers.
Proxy Server
A network server that performs actions on behalf of another system.
Host-based IDPS
An Intrusion Detection and Prevention System installed directly on the machine it protects, monitoring system files and operating status.
Network-based IDPS
An Intrusion Detection and Prevention System that monitors network traffic and detects unusual activity based on previous baselines.
SETA Program
Security Education, Training, and Awareness program designed to reduce accidental security breaches caused by employees.
Three Elements of SETA
The three components of SETA: 1. Security Education, 2. Security Training, and 3. Security Awareness.
Contingency Plan
Plan prepared to anticipate, react to, recover from events threatening information assets, and restore normal operations.
Incident Response Plan (IRP)
A plan focused on identification, classification, response, and recovery from a specific security incident.
Disaster Recovery Plan (DRP)
A plan focused on preparation for and recovery from a major disaster.
Business Continuity Plan (BCP)
A plan ensuring critical business functions continue during catastrophic incidents or disasters.
Access Control
A method used by systems to determine whether and how to admit a user into a trusted area or information system.
Mandatory Access Control (MAC)
An access control method using data classification where users and data owners have limited control over access permissions.
Nondiscretionary Controls
Access controls strictly enforced and managed by a central authority, which can be role-based or task-based.
Discretionary Access Control (DAC)
Access control implemented at the discretion or option of the individual data user.
Identification
The first mechanism of access control where a user tells the system who they are.
Authentication
The second mechanism of access control where the system verifies who the user is.
Three Factors of Authentication
The three factors used to prove identity: 1. Something you know, 2. Something you have, and 3. Something you are.
Authorization
The third mechanism of access control that determines what the authenticated user is allowed to access.
Accountability
The fourth mechanism of access control that makes individuals responsible for their activities within an information system.
Packet-Filtering Firewall
A firewall architecture that examines header information of packets and decides whether to drop/deny or forward/allow.
Screened Host Firewall
A firewall architecture combining a packet-filtering router with a dedicated firewall or proxy.
Dual-Homed Host Firewall
A firewall architecture where a bastion host has two Network Interface Cards (NICs), one connected to the external network and one to the internal network.
Screened Subnet Firewall
A firewall architecture using a DMZ to provide an intermediate security network between public and internal networks.
Remote Connection Authentication Systems
Systems such as RADIUS, TACACS, and Diameter that authenticate credentials of users accessing an organization's network remotely.
Kerberos
An authentication system that uses symmetric key encryption to validate users to network resources.
IPSec Transport Mode vs. Tunnel Mode
In Transport Mode, only data is encrypted while the header remains visible; in Tunnel Mode, the entire original client packet is encrypted and added as the data portion of a new packet.