1/20
Vocabulary flashcards covering core cybersecurity terminology, public policy definitions, risk management concepts, and national cybersecurity strategies.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Internet
A network of computer networks (i.e. "a network of networks").
Computer Network
A group of computers connected to each other.
Cyber Attack
An intentional attempt by individuals or groups to "breach" information systems of other individuals, companies, or organizations.
Cyberware
Cyber attacks often conducted with the purpose of strategic or military gain.
Cyber Threat
Actions or events that have the potential to cause harm or disruption to information systems when exploited by a threat actor.
Vulnerability
A flaw, weakness, or error that lets a threat actor bypass security controls or otherwise take advantage of a system for illicit gain.
Human Error (in Cybersecurity)
The cause of 90% of successful cyber attacks and data breaches, with phishing being the most commonly used initial attack method.
CIA Triad
A method for ensuring the Confidentiality, Integrity, and Availability of information systems.
Confidentiality (CIA Triad)
The principle that only approved individuals may access information.
Integrity (CIA Triad)
The principle that information is correct and unaltered.
Availability (CIA Triad)
The principle that information is accessible to authorized users.
Defense-in-Depth Strategy
A framework for integrating administrative, physical, and technical security controls to create a layered and redundant approach to security.
Risk (in Cybersecurity)
The probability, or likelihood, that a threat will occur, measured against the potential impact, or consequences, posed by a vulnerability.
Risk Management Options
The four main choices for dealing with risk: avoid the risk, transfer the risk to someone else, accept the risk and move forward, or implement strategies and controls to mitigate the risk.
Policy
A set of principles or rules guiding decisive actions to achieve rational outcomes.
Public Policy
Goal-oriented actions and decisions created by all levels of government (municipal, state, and federal) to address societal issues and improve the welfare of citizens.
Four Types of Public Policy
Regulatory policy, Distributive policy, Redistributive policy, and Constituent policy (or Substantive policy).
Cybersecurity Policy
The strategic, legislative, and regulatory measures designed to protect data, networks, and infrastructure against cyber threats and/or risks.
2023 Department of Defense Cyber Strategy Lines of Effort
The 4 lines of effort: 1. Defend the Nation, 2. Prepare to Fight and Win in the Nation’s Wars, 3. Protect the Cyber Domain with Allies and Partners, 4. Build Enduring Advantages in Cyberspace.
Colonial Pipeline Incident
A ransomware attack attributed to the DarkSide ransomware group from Russia that impacted US fuel supply along the east coast and prompted significant domestic cybersecurity policy shifts.
Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022
A key domestic cybersecurity policy resulting from the Colonial Pipeline Incident.