1/161
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Access Control Object
A passive entity that typically receives or contains some form of data.
Access Control Subject
An active entity and can be any user, program, or process that requests permission to cause data to flow from an access control object to the access control subject or between access control objects.
Asynchronous Password Token
A one-time password is generated without the use of a clock, either from a one-time pad or cryptographic algorithm.
Authorization
Determines whether a user is permitted to access a particular resource.
Connected Tokens
Must be physically connected to the computer to which the user is authenticating.
Contactless Tokens
Form a logical connection to the client computer but do not require a physical connection.
Disconnected Tokens
Have neither a physical nor logical connection to the client computer.
Entitlement
A set of rules, defined by the resource owner, for managing access to a resource (asset, service, or entity) and for what purpose.
Identity Management
The task of controlling information about users on computers.
Proof of Identity
Verify people's identities before the enterprise issues them accounts and credentials.
Kerberos
A popular network authentication protocol for indirect (third-party) authentication services.
Lightweight Directory Access Protocol (LDAP)
A client/server-based directory query protocol loosely based on X.500, commonly used to manage user information. LDAP is a front end and not used to manage or synchronize data per se as opposed to DNS.
Single Sign-On (SSO)
Designed to provide strong authentication using secret-key cryptography, allowing a single identity to be shared across multiple applications.
Static Password Token
The device contains a password that is physically hidden (not visible to the possessor) but that is transmitted for each authentication.
Synchronous Dynamic Password Token
A timer is used to rotate through various combinations produced by a cryptographic algorithm.
Trust Path
A series of trust relationships that authentication requests must follow between domains
Availability
Refers to the ability to access and use information systems when and as needed to support an organization's operations.
Breach
The intentional or unintentional release of secure information to an untrusted environment.
CMDB
A configuration management database (CMDB) is a repository that contains a collection of IT assets that are referred to as configuration items.
Compensating Controls
Introduced when the existing capabilities of a system do not support the requirements of a policy.
Confidentiality
Refers to the property of information in which it is only made available to those who have a legitimate need to know.
Configuration Management (CM)
A discipline that seeks to manage configuration changes so that they are appropriately approved and documented, so that the integrity of the security state is maintained, and so that disruptions to performance and availability are minimized.
Corrective Control
These controls remedy the circumstances that enabled unwarranted activity, and/ or return conditions to where they were prior to the unwanted activity.
COTS
A Federal Acquistion Regulation (FAR) term for commercial off-the-shelf (COTS) items, that can be purchased n the commercial marketplace and used under government contract.
Deduplication
A process that scans the entire collection of information looking for similar chunks of data that can be consolidated.
Defense-in-depth
Provision of several overlapping subsequent limiting barriers with no respect to one safety or security threshold, so that the threshold can only be surpassed if all barriers have failed.
Degaussing
A technique of erasing data on disk or tape (including video tapes) that, when performed properly, ensures that there is insufficient magnetic remanence to reconstruct data.
Deluge System
A fire suppression system with open sprinker heads, water is held back until a detector in the area is activated.
Deterrent Control
Controls that prescribe some sort of punishment, randing from embarrassment to job termination or jail time for noncompliance. Their intent is to dissuade people from performing unwanted acts.
Directive Control
Controls dictated by organizational and legal authorities.
Dry System
A fire suppression system that does not have water in the pipes until the electric valve is stimulated by excess heat.
Dual Control
A procedure that uses two or more entities (usually persons) operating in concert to protect a system resource, such that no single entity acting alone can access that resource.
Information Rights Management (IRM)
Assigns specific properties to an object such as how long the object may exist, what users or systems may access it, and if any notifications need to occur when the file is opened, modified, or printed.
Integrity
The property of information whereby it is recorded, used, and maintained in a way that ensures its completeness, accuracy, internal consistency, and usefulness for a stated purpose.
IT Asset Management (ITAM)
Entails collecting inventory and financial and contractual data to manage the IT asset throughout its life cycle.
Least Privilege
A security principle in which any user/process is given only the necessary, minimum level of access rights (privileges) explicitly, for the minimum amount of time, in order for it to complete its operation.
Non-repudiation
A service that is used to provide assurance of the integrity and origin of data in such a way that the integrity and origin can be verified by a third party as having originated from a specific entity in possession of the private key of the claimed signatory.
Pre-action System
A fire suppression system that contains water in the pipes but will not release the water until detectors in the area have been activated. This can eliminate concerns of water damage due to accidental or false activation.
Preventive Control
Controls that block unwanted actions.
Privacy
The rights and obligations of individuals and organizations with respect to the collection, use, retention, and disclosure of personal information.
Procedures
Step-by-step instructions for performing a specific task or set of tasks.
Release Management
A software engineering discipline that controls the release of applications, updates, and patches to the production environment.
Release Management Policy
Specifies the conditions that must be met for an application or component to be released to production, roles and responsibilities for packaging, approving, moving, and testing code releases, and approval and documentation requirements.
Release Manager
Responsible for planning, coordination, implementation, and communication of all application releases.
Separation of Duties
An operational security mechanism for preventing fraud and unauthorized use that requires two or more individuals to complete a task or perform a specific function.
Systems Integrity
The maintenance of a known good configuration and expected operational function.
Annualized Loss Expectancy (ALE)
The expected annual loss because of a risk to a specific asset.
Annualized Rate of Occurrence (ARO)
The expected number of exploitations by a specific threat of a vulnerability to an asset in a given year.
Antivirus Gateways
Monitoring control for viruses contained within communications of major application types, such as web traffic, e-mail, and FTP.
Asset
Anything of value that is owned by an organization. Assets include both tangible items such as information systems and physical property and intangible assets such as intellectual property.
Countermeasure
An added-on reactive security controls.
Exploit
A particular attack. It is named this way because these attacks exploit system vulnerabilities.
False Negative
The monitoring system missed reporting an exploit event by not firing an alarm.
False Positive
Monitoring triggered an event but nothing was actually wrong, and in doing so the monitoring has incorrectly identified benign communications as a danger.
Impact
The magnitude of harm that could be caused by a threat's exercise of a vulnerability.
Java/ActiveX Filters
These security gateway systems screen communications for these components and block or limit their transmission.
Likelihood
The probability that a potential vulnerability may be exercised within the construct of the associated threat environment.
Network Mapping
A process that "paints the picture" of which hosts are up and running externally or internally and what services are available on the system.
Promiscuous Interface
A network interface that collects and processes all of the packets sent to it regardless of the destination MAC address.
Risk
A function of the likelihood of a given threat source exercising a potential vulnerability, and the resulting impact of that adverse event on the organization.
Residual Risk
The risk that remains after risk reduction and mitigation efforts are complete.
Risk Assessments
Assess threats to information systems, system vulnerabilities and weaknesses, and the likelihood that threats will exploit these vulnerabilities and weaknesses to cause adverse effects.
Risk Register
Serves as a way for the organization to know their possible exposure at a given time.
Safeguard
A built-in proactive security control implemented to provide protection against threats.
Signature
A string of characters or activities found within processes or data communications that describes a known system attack.
Single Loss Expectancy (SLE)
The expected monetary loss to an organization from a threat to an asset.
Threat
The potential for a threat source to exercise (accidentally trigger or intentionally exploit) a specific vulnerability.
Threat Source
Either intent or method targeted at the intentional exploitation of a vulnerability or a situation or method that may accidentally trigger a vulnerability.
True Negative
The monitoring system has not recognized benign traffic as cause for concern.
True Positive
The monitoring system recognized an exploit event correctly.
Tuning
Customizing a monitoring system to your environment.
Vulnerability
A system weakness.
War Dialing
Attempts to locate unauthorized, also called rogue, modems connected to computers that are connected to networks.
War Driving
Involves traveling around with a wireless scanner looking for wireless access points.
Web Traffic Screening
These systems block web traffic to and from specific sites or sites of a specific type.
Business Continuity Planning
The proactive development of a plan that can be executed to restore business operations within predetermined times after a disaster or other significant disruption to the organization.
Adverse Events
Events with a negative consequence, such as system crashes, network packet floods, unauthorized use of system privileges, defacement of a web page, and execution of malicious code that destroys data.
Clustering
A method of configuring multiple computers so that they effectively operate as a single system.
Computer Security Incident
A violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.
Differential Backups
Records differences in data since the most recent full backup.
Event
Any observable occurrence in a system or network.
Full Backup
Copies the entire system to backup media.
Full Interruption Testing
When business operations are actually interrupted at the primary processing facility.
High Availability Clustering
A clustering method that uses multiple systems to reduce the risk associated with a single point of failure.
Incremental Backups
Records changes that are made to the system since the last incremental backup.
Intrusion Detection Systems (IDS)
Use available information to determine if an attack is underway, send alerts, and provide limited response capabilities.
Intrusion Prevention Systems (IPS)
Use available information to determine if an attack is underway, send alerts but also block the attack from reaching its intended target.
Locard's Principle of Exchange
States that when a crime is committed, the perpetrators leave something behind and take something with them, hence the exchange.
Maximum Tolerable Downtime (MTD)
The maximum amount of time that a business function can be unavailable before the organization is harmed to a degree that puts the survivability of the organization at risk.
Recovery Point Objective (RPO)
Specifies the point in time to which data could be restored in the event of a business continuity disruption.
Recovery Time Objective (RTO)
Indicates the period of time within which a business function or information system must be restored after a disruption.
Asymmetric
Two different but mathematically related keys are used where one key is used to encrypt and another is used to decrypt.
Asynchronous
Encrypt/Decrypt requests are processed in queues.
Certificate Authority (CA)
An entity trusted by one or more users as an authority in a network that issues, revokes, and manages digital certificates.
Cryptanalysis
The study of techniques for attempting to defeat cryptographic techniques and, more generally, information security services.
Cryptology
The science that deals with hidden, disguised, or encrypted communications. It embraces communications security and communications intelligence.
Cryptosystem
Represents the entire cryptographic operation. This includes the algorithm, the key, and key management functions.
Decryption
The reverse process from encryption. It is the process of converting a ciphertext message into plaintext through the use of the cryptographic algorithm and key that was used to do the original encryption.
Digital Certificate
An electronic document that contains the name of an organization or individual, the business address, the digital signature of the certificate authority issuing the certificate.
Digital Signatures
Provide authentication of a sender and integrity of a sender's message.