ISDS 4096 Exam 2 Terms Burns

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/114

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:50 PM on 5/5/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

115 Terms

1
New cards

CIA Triad

Confidentiality, Integrity, Availability

2
New cards

Confidentiality

Only authorized users can view information.

3
New cards

Integrity

Information is complete and unaltered: a.k.a., only authorized users can change information.

4
New cards

Availability

Information is accessible by authorized users whenever they request information.

5
New cards

Policy

A short written statement that defines a course of action that applies to entire organization.

6
New cards

Standard

A detailed written definition of how software and hardware are to be used

7
New cards

Procedures

Written instructions for how to use policies and standards

8
New cards

Guidelines

Suggested course of action for using policy, standard, or procedure.

OR

Offer recommendations on how standards and baselines are implemented.

9
New cards

Standards

Define compulsory requirements

10
New cards

Baselines

Define the minimum level of security. Operationally focused form of a standard.

11
New cards

STRIDE

Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service (DoS), and Elevation of Privilege

12
New cards

Spoofing

An attack with the goal of gaining access to a target system through the use of falsified identity. When an attacker spoofs their identity as a valid or authorized entity, they are often able to bypass filters and blockades against unauthorized access.

13
New cards

Tampering

Any action resulting in unauthorized changes or manipulation of data, whether in transit or in storage.

14
New cards

Repudiation

The ability of a user or attacker to deny having performed an action or activity by maintaining plausible deniability.

15
New cards

Information Disclosure

The revelation or distribution of private, confidential, or controlled information to external or unauthorized entities.

16
New cards

Denial of Service (DoS)

An attack that attempts to prevent a system from performing its normal functions. This can be done through flaw exploitation, connection overloading, or traffic flooding.

17
New cards

Elevation of Privilege

An attack where a limited user account is transformed into an account with greater privileges, powers, and access.

18
New cards

Employee Oversight

Monitoring and supervision employees' activities

19
New cards

Collusion

Several people work together to perform a crime.

20
New cards

User Behavior Analytics (UBA)

User behavior analytics refers to the process of monitoring user behavior in an attempt to discover potential threats and attacks. UBA is designed to perform advanced threat detection in an organization by monitoring employee behavior and identifying those behaviors that could lead to potential threats to the organization.

21
New cards

Social Engineering Principles

Authority, Intimidation, Consensus, Scarcity, Familiarity, Trust, and Urgency

22
New cards

Authority

The trick is to convince the target that the attacker is someone with valid internal or external authority. Some attacker attackers claim their authority verbally, and others assume authority by wearing a costume or uniform.

23
New cards

Intimidation

Uses authority, confidence, or even the threat of harm to motivate someone to follow orders or instructions. It is often focusing on exploiting uncertainty in situations where a clear directive of operation or response isn't defined.

24
New cards

Consensus

Or "social proof" is the act of taking advantage of a person's natural tendency to mimic what others are doing or are perceived as having done in the past. The attacker attempts to convince the victim that a particular action or response is necessary to be consistent with social norms or previous occurrences.

25
New cards

Scarcity

A technique used to convince someone that an object has a higher value based on the object's scarcity.

26
New cards

Familiarity

Attempts to exploit a person's native trust in that which is familiar. The attacker often tries to appear to have a common contact or relationship with the target, such as mutual friends or experiences, or uses a facade to take on the identity of another company or person.

27
New cards

Trust

An attacker working to develop a relationship with a victim. This may take seconds or months, but eventually the attacker attempts to use the value of the relationship (the victim's trust in the attacker) to convince the victim to reveal information or perform an action that violates company security.

28
New cards

Urgency

Often joint with scarcity, because the need to act quickly increases as scarcity indicates a greater risk of missing out. Often used as a method to get a quick response from a target before they have time to carefully consider or refuse compliance.

29
New cards

End-of-life (EOL)

A manufacturer no longer produces a produce a product. Should be scheduled for replacement or to be reitred.

30
New cards

End-of-service-life (EOSL) or End-of-support (EOS)

Systems that are no longer receiving updates and support from the vendor. Must be replace/retired

31
New cards

Cybersecurity Framework

Identify, Protect, Detect, Respond, and Recover

32
New cards

identity

Develop an organizational understanding to manage cybersecurity risk to: systems, assets, data, and capabilities.

33
New cards

Protect

Develop and implement the appropriate safeguards to ensure the delivery of services.

34
New cards

Detect

Develop and implement the appropriate activities to identify the occurrence of cybersecurity events.

35
New cards

Respond

Develop and implement the appropriate to take action regarding a detected cybersecurity event.

36
New cards

Recover

Develop and implement the appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity event.

37
New cards

Incident Management Steps

Detection, Response, Mitigation, Reporting, Recovery, Remediation, and Lessons Learned

38
New cards

Intrusion Detection and Prevention Systems

Tools and techniques to detect and prevent unauthorized access

39
New cards

Intrusion Detection System (IDS)

More of an alerting system that lets an organization know if anomalous or malicious activity is detected.

40
New cards

Intrusion Prevention System (IPS)

Takes detection a step forward and shuts down the network before access can be gained or prevent further movement in a network

41
New cards

(ISC)2 Code of Ethics

1. Protect society, the commonwealth, and the infrastructure.

2. Act honorably, honestly, justly, responsibly, and legally.

3. Provide diligent and competent service to principals.

4. Advance and protect the profession.

42
New cards

Forensic Procedure

Network analysis, Software analysis, and Hardware/embedded device analysis

43
New cards

Network Analysis

- Intrusion detection and prevention system logs

- Network flow data captured by a flow monitoring system

- Captures deliberately collected during an incident

- Logs from firewalls and other network security devices

44
New cards

Software Analysis

Validation of file hash values against known file types

45
New cards

Hardware/Embedded Device Analysis

A type of Analysis in which an analyst may review the contents of hardware and embedded devices.

This may include a review of: PCs, Personal computers, Smartphones, Tablet computers, and Embedded computers in cars, security systems, and other devices

46
New cards

Host-based IDS (HIDS)

- Monitors activity on a single computer, including process calls and information recorded in system, application, security, and host-based firewall logs.

- Can detect infections where an intruder has infiltrated a system and is controlling it remotely.

47
New cards

Downsides to Host-based IDS

- More costly to manage because they require administrative attention on each system

- Cannot detect network attacks on other systems

- Easier for an intruder to discover and disable

48
New cards

Network-based IDS (NIDS)

- Monitors and evaluates network activity to detect attacks or event anomalies.

- A single NIDS can monitor a large network by using remote sensors to collect data at key network locations that send data to a central management console such as a security information and event management (SIEM) system.

- These sensors can monitor traffic at routers, firewalls, network switches that support port mirroring, and other types of network taps.

49
New cards

Downsides to Network-based IDS

Usually can detect an attack, but it can't always provide info about an attack's success. So it won't know if an attack affected specific systems, user accounts, files, or applications. However, after administrators receive the alert, they can check relevant systems and use NIDS logs as part of an audit trail to learn what happened.

50
New cards

NIST SP 800-53

Its primary goal and objective is to ensure that appropriate security requirements and security controls are applied to all U.S. Federal Government information and information management systems.

51
New cards

Risk Assessment Process

Step 1. Prepare for Assessment

Step 2. Conduct Assessment

Step 3. Communicate Results

Step 4. Maintain Assessment

52
New cards

Step 1. Prepare for Assessment

- Identify the purpose of the assessment

- Identify the scope of the assessment

- Identify the assumptions and constraints associated with the assessment

- Identify the sources of info to be used as inputs to the assessment

- Identify the risk model and analytic approaches (i.e., assessment and analysis approaches) to be employed during the assessment.

53
New cards

Step 2. Conduct Assessment

- Identify threat sources

- Determine the likelihood

- Determine the impact

- Determine risk value

54
New cards

Step 3. Communicate Results

- Prepare a report

- Tailor the report

- Use visual aids

- Provide context

- Highlight the benefits

- Follow up

55
New cards

Step 4. Maintain Assessment

- Conduct regular assessments

- Monitor threat intelligence

- Conduct employee training and report potential risks

- Review and prioritize

56
New cards

Monte Carlo Simulation

- Uses a computer to generate a large number of scenarios based on probabilities for inputs.

57
New cards

Personally Identifiable Information (PII)

Any information about an individual maintained by an agency, including:

(1) any information that can be used to distinguish or trace an individual's identity, such as name, social security number, date and place of birth, mother's maiden name, or biometric records; and

(2) any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information.

58
New cards

Protected Health Information (PHI)

- HIPPA

- Health information means any information, whether oral or recorded in any form or medium, that:

(A) is created or received by a health care provider, health plan, public health authority, employer, life insurer, school or university, or health care clearinghouse; and

(B) related to the past, present, or future physical or mental health or condition of any individual, or the past, present, or future payment for the provision of healthcare to an individual.

59
New cards

Proprietary Data

Any data that helps an organization maintain a competitive edge.

60
New cards

Non-government Data Classification Standards

Private Data, Confidential (more secure), Internal Use Only, and Public Domain Data (less secure)

61
New cards

Data Loss Prevention (DLP)

A system that can identify critical data, monitor how it is being accessed, and protect it from unauthorized users.

62
New cards

Network-based DLP

- scans all outgoing data looking for specific data

- if sensitive data is sent, the DLP with detect it, prevent it from leaving, and send an alert

63
New cards

Endpoint-based DLP

- can scan files stored on a system as well as files sent to external devices (such as printers)

- can prevent users from copying data to USB drives or sending sensitive info to printers

64
New cards

Solid State Drive (SSD) Destruction

- Use integrated circuitry or flash-based memory.

- NSA requires disintegrators to shred the SSDs to a size of 2 mm or smaller (0.079 in).

65
New cards

Hard Disk Drive (HDD)

- Use magnetization

- Degausser creates a heavy magnetic field to realign the magnetized media.

66
New cards

Deletion

Erasing, Clearing, Purging, and Degassing

67
New cards

Erasing

Simply performing a delete operation against a file, a selection of files, or the entire media. (gone forever)

68
New cards

Clearing

Or overwriting, is a process of preparing media for reuse and ensuring that the cleared data cannot be recovered using traditional recovery tools.

69
New cards

Purging

A more intense form of clearing that prepares media for reuse in a less secure environment (downgrade).

70
New cards

Degaussing

The process of removing or rearranging the magnetic field of a disk in order to render the data unrecoverable. (typically a hard disk)

71
New cards

Pseudonymization

the process of removing personal identifies from data and replacing those identifiers with pseudonyms/aliases or artificial identifiers as placeholder values. Often similar in structure to original data.

72
New cards

Tokenization

The process of replacing sensitive data with unique identification symbols that retain all the essential information about the data without compromising its security.

73
New cards

Anonymization

the process of removing all relevant data so that it is impossible to identify the original subject or person. (reidentification)

74
New cards

Managed Services in the Cloud

Software as a Service (SaaS); Platform as a Service (PaaS); and Infrastructure as a Service (IaaS)

75
New cards

Software as a Service (SaaS)

Models provide fully functional applications typically accessible via a web browser.

76
New cards

Platform as a Service (PaaS)

Models provide consumers with a computing platform, including hardware, operating systems, and a runtime environment.

77
New cards

Infrastructure as a Service (IaaS)

Models provide basic computing resources to customers. (IBM Cloud, AWS, Microsoft Azure, and etc)

78
New cards

Common Vulnerabilities and Exposures (CVE)

An online list of known vulnerabilities (and patches) to software, especially web servers. It is maintained by the MITRE Corporation.

79
New cards

Business Impact Analysis (BIA)

A process that helps an organization identify critical systems and components that are essential to the organization's success.

80
New cards

Single Loss Expectancy (SLE)

Asset Value (AV) * Exposure Factor (EF)

[AV x EF]

81
New cards

Annualized Rate of Occurrence (ARO)

Number of incidents per year

82
New cards

Annualized Loss Expectancy (ALE)

Single Loss Expectancy (SLE) * Annualized Rate of Occurrence (ARO)

[SLE x ARO]

83
New cards

Redundant Array of Independent Disks (RAID)

a technology used to combine multiple hard drives into a single unit called an array. This enhances performance and reliability.

84
New cards

Uninterruptible Power Supply (UPS)

An almost instant battery power source that provides electric current during a power outage. Provides 5 to 30 minutes to shutdown or start a generator.

85
New cards

Quality of Service (QoS)

a set of technologies that work on a network to guarantee its ability to dependably run high-priority applications and traffic under limited network capacity.

86
New cards

Bandwidth

speed of a link

87
New cards

Latency

Time it takes for a network request to travel from its sender to its receiver.

88
New cards

Packet Loss

refers to data that never reaches its destination or gets discarded because it arrives too late

89
New cards

Jitter

When a time delay in the sending of data packets over a network connection occurs

90
New cards

Cold Site

an off-site location kept on standby for disaster recovery but without any active hardware. Requires time to set up and become operational.

91
New cards

Hot Site

A fully functional off-site location that can take over immediately in the event of a system failure. Fully equipped but expensive

92
New cards

Warm Site

Somewhere between cold and hot sites. It has some hardware and can become operational more quickly than a cold site but still requires some time.

93
New cards

Cloud Site

A virtual site that allows for quick scaling and deployment but is dependent on internet connectivity.

94
New cards

Computer Crime

The statute prohibits seven categories of conduct involving unauthorized access to computers, including, with certain exceptions and conditions:

1. Obtaining national security information through unauthorized computer access and sharing or retaining it;

2. Obtaining certain types of information through unauthorized computer access;

3. Accessing government computers without authorization;

4. Engaging in computer‐based frauds through unauthorized computer access;

5. Knowingly causing damage to certain computers by transmission of a program, information, code, or command;

6. Trafficking in passwords or other means of unauthorized access to a computer; and

7. Making extortionate threats to harm a computer

or based on information obtained through

unauthorized access to a computer.

95
New cards

Federal Information Security Management Act (FISMA)

This places a significant burden on federal agencies and government contractors, who must develop and maintain substantial documentation of their FISMA compliance activities.

96
New cards

Copyrights

- Original works of authorship

- Author: 70 years after death

- Companies: 120 years after creation or 95 years once published

97
New cards

Digital Millennium Copyright Act

a 1998 US law intended to update copyright law for electronic commerce and electronic content providers. It criminalizes the circumvention of electronic and digital copyright protection systems.

98
New cards

Trademark

symbol, word, or words legally registered or established by use as representing a company or product or services. must not be confusingly similar or descriptive.

99
New cards

Patents

- intellectual property rights granted for inventions that are useful, novel, and non-obvious

- 20-year protection from the date of filing

100
New cards

Trade Secrets

intellectual property rights in the form of inventions and information, not generally known to others, that convey economic advantages to the holders. NDA