1/29
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Physical, Administrative, Technical.
P.A.T
Information Security
A well-informed sense of assurance that information risks and controls are in balance; the protection of information and the systems and hardware that use, store, and transmit it.
Confidentiality, Integrity, Availability.
CIA Triangle
Larry Roberts
Developed ARPANET from its inception.
ARPANET
Became the foundation of modern networking but introduced new security concerns.
MULTICS
Multiplexed Information and Computing Service; the first operating system designed with security as its primary goal.
UNIX
Operating system primarily developed for text processing.
Security
The quality or state of being secure and free from danger.
Layers of Security
Physical, Personal, Operations, Communications, Network, Information Security.
Computer as Subject of an Attack
Used as an active tool to conduct attacks.
Computer as Object of an Attack
The target being attacked.
Bottom-Up Approach
Grassroots effort led by system administrators; provides technical expertise but lacks participant support.
Top-Down Approach
Initiated by upper management using the Systems Development Life Cycle (SDLC).
Systems Development Life Cycle (SDLC)
Methodology for designing and implementing information systems.
Methodology
Normal approach to problem solving based on structured sequence of procedures
Investigation, Analysis, Logical Design, Physical Design, Implementation, Maintenance and Change.
6 Phases of SDLC
Investigation Phase
Defines the problem, objectives, constraints, and scope.
Analysis Phase
Assesses the organization, current systems, and capabilities while documenting findings.
Logical Design Phase
Identifies business needs and data structures.
Physical Design Phase
Selects technologies and performs feasibility analysis.
Implementation Phase
Creates software, trains users, and prepares documentation.
Maintenance and Change Phase
Longest and most expensive phase; supports and modifies the system.
Chief Information Officer (CIO)
Senior technology officer responsible for strategic technology planning.
Chief Information Security Officer (CISO)
Responsible for assessing, managing, and implementing information security; reports directly to the CIO.
Data Owner
Responsible for the security and use of information.
Data Custodian
Responsible for data storage, maintenance, and protection.
Data Users
End users who work with information.
Information Security as Art
No hard and fast rules; no universally accepted complete solutions.
Information Security as Science
Deals with technology operating at high levels of performance.
Information Security as a Social Science
Examines the behavior of individuals interacting with systems.