Intro to Information Security

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/13

flashcard set

Earn XP

Description and Tags

Module 1: Objectives - 1. Define information security and explain the principles, 2. identify threat actors and their motivations, 3, Describe how attacks occur and the impact of attacks, 4. List various information security resources.

Last updated 1:13 AM on 8/26/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

14 Terms

1
New cards

Understanding Security

Security is the state of being free from danger: Measures taken to ensure Security. As Security is increased, convenience is (often) decreased.

2
New cards

Principles of Security

Confidentiality: Ensures that only approved individuals may access information

Integrity: Ensures that information is correct and unaltered.

Availability: Ensures that information is accessible to authorized users.

3
New cards

Principles of Security Part 2: Access to Information

Authentication: Act of ensuring a user’s credentials as authentic

Authorization: Grants permission for a user to take a particular action

Accounting: Creates a record of who, what, and when a person accesses network resources.

4
New cards

Principles of Security Part 3: Security Control

  • Deterrent Controls

  • Preventive Controls

  • Detective Controls

  • Compensating Controls

  • Corrective Controls

  • Directive Controls


5
New cards

Cybersecurity vs. Information Security

Cybersecurity: Range of Practices, Processes, and Technologies to protect devices, networks, and programs that process and store data in an electronic form

Information Security: Protects processed data that is essential in an enterprise environment

6
New cards

Threat Actors and Motivations:

Threat Actor: An individual or entity responsible for attacks, “Attacker”.

  • Unskilled Attackers

  • Shadow IT

  • Organized Crime

  • Insiders

  • Hacktivists

  • Nation- State Actors

Financial Crime:

  • Individual Users

  • Enterprises

  • Governments


7
New cards

Unskilled Attackers

Attackers who lack technical knowledge. Use Easy-Use attack tools that can be purchased. Motivation is usually data exfiltration or service disruption

8
New cards

Shadow IT

The Process of Bypassing Corporate Approval for technology purchases. Motivation is often ethical, but weakens security.

9
New cards

Organized Crime

Organized Crime is a close-knit group of highly- centralized enterprises set up for the purpose of engaging in illegal activities. Moved into cyberattacks, less risky and more rewarding than traditional crime. Motivated by financial gain generally

10
New cards

Insider Threats

Another threat comes from a company’s own employees, contractors, and business partners called insiders. Motivated by revenge or blackmail. Attacks from insider threats that are hard to recognize.

11
New cards

Hacktivists

Groups or individuals that are strongly motivated by ideology, principles or beliefs. Ranging from making statements, to retaliate ( for actions against them), and to disrupt or cause chaos.

12
New cards

Nation- State Actors

Attackers who are employed by the Government. Involved in year long intrusion campaigns that target sensitive economic, proprietary, or national security information.

Advanced Persistent Threat (APT): Use innovative attack tools that silently extract data over an extended period of time.

13
New cards

Other Actors

Competitors: Launch attacks against opponent’s system to steal classified information

Brokers: Sell their knowledge of a weakness to other attackers or governments

CyberTerrorists: Attacks a Nation’s network and computer infrastucture to cause disruption and panic among citizens.

14
New cards

Threat Vectors and Attack Surfaces Part 1: