Chapter 4 - Cybersecurity Accessible

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/102

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:17 AM on 8/26/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

103 Terms

1
New cards

Chief Information Security Officer (CISO)

• Plays a role in developing an organization’s policies
designed to protect information assets and technologies
• Advise developing, implementing, and maintaining
processes to minimize IT risks
• Handle security incidents, oversee security tools, and lead
the development and enforcement of security protocols
and practices
• Require (or strongly prefer) a master’s degree: Master of
Business Administration (MBA) or a master’s degree in
cybersecurity

2
New cards

Common Job Responsibilities of a CISO

• Ensure alignment with the strategic direction of the
business
• Examine and report information security risks to meet
compliance and regulatory requirements
• Manage security incidents to protect corporate IT
assets
• Oversee relationships with security related vendors to
ensure they meet security requirement

3
New cards


Generative AI in Cybersecurity

• Can be used to learn from patterns found in cybersecurity
threats and vulnerabilities
• Can be trained on massive data sets of cybersecurity data
• Can be used to identify patterns and trends that aid in
predicting and preventing future cybersecurity threats

4
New cards

cybersecurity threat

an event or condition that has the
potential for causing asset loss and the undesirable
consequences or impact from such loss.

5
New cards

Causes of Asset Loss

situations and events related
to adversity typically referred
to as disruptions, hazards,
or threats

6
New cards

Types of Asset Loss

all forms of intentional,
unintentional, accidental,
incidental, misuse, abuse,
error, weakness, defect,
fault, and/or failure events
and associated conditions

7
New cards

Cybersecurity vulnerabilities

weaknesses or flaws in system
security procedures, design,
implementation, and control that
could be compromised accidentally
or intentionally.

8
New cards

Cybersecurity Exploits

the means through
which a system vulnerability can
be used by a hacker to execute a
malicious activity on a system

9
New cards

Viruses

Software that infects computers and is created using
computer code

10
New cards

Spyware

Software that collects information about a person’s
Internet surfing habits and behaviors.

11
New cards

Impersonation

A social engineering tool in which a hacker plays the role
of someone the target knows or would likely trust,
thereby fooling them into sharing important information.

12
New cards

Distributed Denial
of Service (DDOS)
attack

A cyberattack to make a computer or online service
unavailable to its users. It’s usually accomplished by
flooding the resource with nonsensical or superfluous
requests from multiple sources across the web

13
New cards

Cybersecurity threat mitigation

the policies and
procedures to help prevent against security incidents.Threat Prevention

14
New cards

Threat Prevention

Policies and procedures put in place by an organization
to protect systems and data

15
New cards

Threat
Identification

Security tools and oversight designed to identify
specific and active security threats

16
New cards

Threat Cure

Policies, tools, and strategies used to lessen the impact
of active security threats

17
New cards

Cybersecurity breaches

early-stage intrusions that can
lead to system damage, data loss, and network downtime.

18
New cards

Social Engineering

the
manipulation of people so that
they give up their confidential
information including:
• bank information
• passwords
• access to computers or networks
• Social Security numbers

19
New cards

Social engineering attacks

exploit
individuals’ trust and lack of
knowledge about what types of
information should be divulged

20
New cards

Three Common Cybersecurity
Goals

1. protection of data, information, and
systems
2. preservation of data, information, and
system integrity
3. promotion of the authentication of
data, systems, and information for
authorized users and to prevent
access to unauthorized users

21
New cards

Integrity can be maintained
through a variety of measures,
including:

• user-access controls
• file permission
• version controls

22
New cards

Authentication

a process that
helps an organization to establish
the origin of information or to
determine an individual’s or
entity’s identity.

23
New cards

Authentication methods are
designed to

• prevent unauthorized access to an
organization’s resources
• ensure that those who need access
to data and information receive the
access they need

24
New cards

External Threat Types

The risks are external to the
organization and include
malware, DDoS attacks,
ransomware, viruses, and
phishing attacks designed to
steal information and disrupt
system activities.

25
New cards

External Threat Types

These are threats from inside the
organization and include
accidents and intentional attacks.
• accidents include
accidentally erasing data or
allowing a breach via a social
engineering attack
• intentional attacks include
willful attacks on systems
and data

26
New cards

Spyware

software that collects
information about your Internet
surfing habits and behaviors

27
New cards

The information collected by
spyware includes:

• keystrokes
• passwords
• account numbers
• other confidential information

28
New cards

Spyware is commonly installed

via free downloads or by visiting
certain illegitimate websites

29
New cards

Adware

software that
collects the user’s web
browsing history

30
New cards

Functions of Adware:

• surface advertisements on a
digital device
• forward your search history and
requests to advertising and
social media sites
• collect a variety of marketing
and online behavioral data
about you

31
New cards

Bots

used to perform repetitive jobs with no
malicious intent, such as indexing a search engine or
gathering informa

32
New cards

Web Crawlers

One of the typical “good” bot
uses is to gather information.
Bots used for this purpose
are called web crawlers.

33
New cards

Malware Bots

Uses self-propagating malware
that infects its host and connects
back to a central server.

34
New cards

Ransomware

Malware that makes a computer’s data inaccessible until a
ransom is paid.

35
New cards

Rootkit

a type of malware that
hides in the operating system (OS)
and is triggered each time you boot
your computer.

36
New cards

Rootkits allow

an individual, either
legitimately or maliciously, to gain
control of a digital device or system
and maintain control over the device
or system undetected

37
New cards

keystroke logger / Keyloggers

a
form of spyware/surveillance
technology that records all actions
typed on a keyboard

38
New cards

Computer Viruses Application

It is created using computer code.
Computer viruses typically must be
“run” to attack and do damage

39
New cards

Adverse Impact Computer Viruses

Viruses can destroy programs or
alter the operations of a computer
or network.


40
New cards

Key Condition Computer Viruses

Computer viruses, much like a
biological flu virus, are designed to
spread in hosts and have the ability
to replicate themselves. They
cannot reproduce and spread
without proper programming, such
as that contained in a file or
document.

41
New cards

Trojan Horse

a program that appears legitimate but
executes an unwanted activity when activated.keyloggers can
be used on smartphones, tablets, and laptop computers

42
New cards

A Trojan horse can be used to

• delete data
• block data
• copy data
• modify data
• disrupt computer performance

43
New cards

A man in the middle (MITM)

occurs when a wrongdoer
places themselves in a dialog between a user and a computer
application.

44
New cards

Goal of an Attack MitM

these attacks are designed to steal a variety of digital personal
information including login and account information and credit
card numbers

45
New cards

Targets

MitM attacks are often targeted to the users of financial service
applications where a login is required including banks and credit
card companies, SaaS businesses, and online shopping sites

46
New cards

Man-in-the-Phone Attacks
(also termed as Man-in-the-
Mobile Attacks, or MitMo
attacks)

a new type of digital
attack that has recently emerged
due to the advancement and
proliferation of smartphones as
primary computing devices.
This malware allows a
perpetrator unauthorized access
to a device which gives them the
ability to monitor activity on the
device.

47
New cards

Kerberoasting attacks

type of cyberattack that targets the
Kerberos authentication protocol used within Windows Active
Directory environments.

48
New cards

brute force attack

a type of cyberattack where a hacker
guesses information such as a usernames and passwords to
access a private system.

49
New cards

How do these Kerberoasting attacks occur?

1. Attackers identify service
accounts within the Windows
Active Directory.
2. Attacker can request Ticket
Granting Service (TGS) tickets
from the Kerberos Key
Distribution Center.
3. Attacker extracts the TGS
tickets from memory on their
own compromised account or
machine.
4. Attacker can use credentials to
gain unauthorized access to
sensitive systems or data.

50
New cards

How to prevent a kerberoasting
attack?

• Use strong and complex
passwords
• Regularly change service
account passwords
• Implement least privilege
access
29

51
New cards

insider

any individual that has
knowledge of or authorized access to an organization’s IT
resources.

52
New cards

Threats can manifest through the following insider behaviors

• Espionage
• Terrorism
• Unauthorized access
• Workplace violence
• Intentional or unintentional loss or degradation of departmental
resources or capabilities

53
New cards

Intentional Insider Threats

Occur when an individual takes adverse actions for
personal benefit or grievance

54
New cards

Unintentional Insider Threats

Are the result of negligence or accidental
circumstances.

55
New cards

Other Insider Threats

• Include collusive and third-party threats. Collusive
threats are a type of insider threat whereby insiders
collude with outside parties to compromise the
organization.
• Third-party threats occur when people outside of the
organization that have been given access to
resources either intentionally or unintentionally
compromise security measures

56
New cards

SQL Injection

deployed via the web and designed to exploit
security weaknesses that allow the attacker to compromise databases
and data-driven applications.

57
New cards

Input Validation

User input is validated according to the
expected format.

58
New cards

Prepared Statements and Parameterized Queries

This
tactic helps to ensure that an attacker cannot change the intent
of a query, even if SQL commands are inserted by an attacker.

59
New cards

Frequent Testing

Tools and practices, such as penetration
testing, to regularly search for and fix vulnerabilities within the
application

60
New cards

Educating Developers

Ensuring that developers are aware
of the risks associated with SQL injection and the best practices
for preventing it

61
New cards

confidentiality


covers privacy and seeks to

avoid the unlawful exposure of personal and organizational
information.

62
New cards

The tools to ensure confidentiality
include

• access control
• user authentication
• user authorization
• physical security

63
New cards

availability


deals with ensuring data and

system infrastructure are available when needed.

64
New cards

Data in Transit

• in transit through networks (cellular, Wi-Fi, or other networks), or
• located in RAM (random access memory)

65
New cards

Protecting Data in Transit

the definition of data in transit is frequently used in the language
concerning many laws and regulations and addresses another key
area where data should be secured

66
New cards

Data At Rest

all data in computer storage. This
excludes data that is traveling on a network or that is
temporarily housed in computer memory (RAM) waiting for
execution.

67
New cards

Examples of data at rest include

• the files an organization stores on hard drives of individual computers
• files stored on internal storage hardware
• files on the servers by an offsite backup service provider
• files stored by cloud service/storage providers

68
New cards

Data In Process

Refers to data that is actively being processed and is not in
storage.
Common types of data in process:
• account balances
• usernames
• account information

69
New cards

The Federal Computer Fraud and Abuse Act (CFAA) prohibits a variety of activit

• unauthorized access (or exceeding authorized access) to a computer
• unauthorized access to a computer being used in interstate or foreign
commerce
• damaging a computer either recklessly or intentionally
• transmitting threats of extortion, and cyber extortion

70
New cards

National Conference on State Legislatures
(NCSL) Some of the key areas of legislative activity include:

• restructuring government for increased cybersecurity
• addressing the security of Internet-connected devices
• addressing cybersecurity threats in elections
• providing security for utilities and critical infrastructures

71
New cards

General Data Protection Regulation (GDPR)

This law regulates how companies protect the personal data
of citizens of the European Union (EU).

72
New cards

General Data Protection Regulation (GDPR) requirements include

• requiring the consent of subjects for data processing
• anonymizing collected data to protect privacy
• providing notifications of data breaches
• safe handling of data across country borders
• requiring that certain companies appoint a data protection officer to
oversee GDPR compliance

73
New cards

California’s SB-327 for IoT (Internet of Things) Security terms are:

• defined, to equip the device with a reasonable security feature or
features that are appropriate to the nature and function of the device
• appropriate to the information it may collect, contain, or transmit
• designed to protect the device and any information contained therein
from unauthorized access, destruction, use, modification, or
disclosure, as specified

74
New cards

Due to limited resources, organizations must:

• calculate their cybersecurity threats
• determine the value it will cost to protect against these threats
In order to determine the cost of security, a calculation of
Probable Maximum Loss (PML) is executed.

75
New cards

The purpose of risk analysis is to identify:

• An organization’s assets
• The potential loss to an organization due to threats
• How to best respond to a loss of data, information, and infrastructure

76
New cards

Risk analysis consists of five steps:

1. The organization assigns values to their information
assets including data, information, and infrastructure
2. They estimate the potential losses per security risks. This includes:
1. Costs associated with a malware attack
2. Costs due to fines and penalties from a security breach
3. Lost revenue due to system downtime.
3. Once the potential losses have been calculated, an estimate of the
likelihood of each type of risk or breach is calculated.
4. Costs are analyzed to create a range of potential costs to the
organization.
5. After careful analysis, the organization makes decisions about
appropriate countermeasures and the policies and procedures that
should be implemented

77
New cards

National Institute of Standards Technology (N IST)
Cybersecurity Framework

designed to assist
organizations in the development of cybersecurity policies and
procedures to protect against cyber threats and intrusions.

78
New cards

According to NIST, the framework is voluntary guidance for
organizations based on

• existing standards
• guidelines
• practices

79
New cards

Identify (ID) function

creates a
call to action for companies to develop a framework for how to
manage cybersecurity risks associated with the systems,
data, hardware, and capabilities that comprise their IT
infrastructure

80
New cards

Five Categories in the ID Function

1. Asset management
2. Business environment
3. Governance
4. Risk assessment
5. Risk management strategy

81
New cards

Protect (PR) function of the NIST
Cybersecurity Framework

• limiting and controlling secure access to systems and digital assets,
both physical and digital
• creating policies and procedures to prevent unauthorized access

82
New cards

Detect (D E) function

the development and implementation of
activities to identify the occurrence of a cybersecurity event,
with a focus on supporting the timely discovery of such events

83
New cards

Three Categories in the DE Function

1. Analysis of anomalies or events
2. Continuous monitoring of systems
3. Processes to detect events

84
New cards


Respond (RS) function

to establish and put in place the
necessary procedures that enable stakeholders to take action
regarding a detected cybersecurity event.

85
New cards

The five categories included in the R S function

• response planning
• communications about the issue
• analysis of the issue
• mitigation of the issue
• improvements to security as a result of the issue

86
New cards


Recover (RC)

function

an organization’s ability to develop and implement
the appropriate activities to maintain plans for resilience and to
restore any capabilities or services that were impaired due to a
cybersecurity event.

87
New cards

The RC function is broken down into three categories that
includ

• recovery planning to ensure restoration of systems
• improvements to existing security measures and processes that result
from an issue
• communications with internal and external stakeholders about the
circumstances of the issue and the remediation that took place

88
New cards

Common methods of identity verification include


Two-Factor Identification (2FA)
• Knowledge-Based Authentication (KBA)
• Multi-Factor Authentication (MFA)
• Biometric Verification
• Token-Based Authentication

89
New cards

Firewalls

Systems that control incoming and outgoing network
traffic based on predetermined security rules

90
New cards

Intrusion Detection Systems (IDS) and Intrusion Prevention
Systems (IPS)

Designed to monitor networks and systems for
malicious activities.
• IDS’s generate alerts for suspicious activities.
• IPS’s are designed to block detected threats actively.

91
New cards

Multifactor Authentication

A method of securing networks
requiring two or more verification factors to access a resource.
Combines something the user knows (a password) with something the
user has (a security token).

92
New cards

Steps in a Cybersecurity Plan

Step 1: Assess the Landscape
Step 2: Define Goals and Develop Policies and Procedures
Step 3: Identify and Enact IT Defenses
Step 4: Create Incidence Response and Recovery Plans
Step 5: Address Legal and Compliance Requirements
Step 6: Train Personnel
Step 7: Monitoring and Assessment

93
New cards

Steps for acquiring and implementing cybersecurity software

• Needs assessment
• Budget and cost analysis
• Research and selection
• Evaluate vendors
• Deployment and maintenance

94
New cards

Supply chain attacks

occur when an entity infiltrates an IT
system through an outside partner (such as a vendor) or
provider (such as a network provider) with access to
organizational systems and data

95
New cards

Third-party
Vulnerabilities of Supply Chain Attacks

Attackers exploit vulnerabilities in third-party software or
hardware components that are integrated into the target
organization's IT environment.

96
New cards

Stealth of Supply Chain Attacks

These attacks are often difficult to detect because they
exploit the trust between a company and its suppliers or
service providers.

97
New cards

Extensive
Impact of Supply Chain Attacks


Organizational supply chains are often interconnected
across the globe. A single compromised component of
the supply chain can affect multiple organizations across
multiple industries.

98
New cards

Hybrid environments

IT infrastructures that combine cloud-based
services with on-premises computing resources.

99
New cards

Generative AI (GenAI)

Offers productivity gains, skills gap
reduction, and better monitoring for threats

100
New cards

Outcome-Driven Metrics (ODM’s)

Measure the outcome of
investment in security measures