MODULE 1: Introduction to Information Security

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/77

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:18 AM on 7/28/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

78 Terms

1
New cards

Information Security

The protection of information and its critical elements, including the systems and hardware that use, store, and transmit it

2
New cards

Confidentiality

Preventing unauthorized disclosure of information

3
New cards

Integrity

Preventing unauthorized or accidental modification of information

4
New cards

Availability

Ensuring authorized users have timely, uninterrupted access to information

5
New cards

C.I.A. Triangle

The historic industry standard for computer security, built on Confidentiality, Integrity, and Availability

6
New cards

Accuracy

Information is free from mistakes or errors and has constant integrity

7
New cards

Authenticity

Information is genuine and original, not corrupted, falsified, or simulated

8
New cards

Utility

Information has a useful purpose or value

9
New cards

Possession

The physical ownership or control of the information container/medium

10
New cards

CNSS Security Model (McCumber Cube)

A 27-cell evaluation framework represented by a 3x3x3 cube mapping Security Objectives, Information States, and Security Measures

11
New cards

Rand Report R-609

A seminal DoD-sponsored paper that started the formal study of computer security, expanding it beyond physical protection

12
New cards

MULTICS

An early timesharing operating system that attempted to build security into software

13
New cards

ARPANET

The precursor to the Internet, developed by Larry Roberts through ARPA

14
New cards

Asset

Any organizational resource, physical or logical, that needs protection

15
New cards

Access

An authorized subject's ability to use, manipulate, or integrate with an asset

16
New cards

Attack

An intentional or unintentional act that can damage or compromise information assets

17
New cards

Control, Safeguard, or Countermeasure

Mechanisms designed to prevent, detect, or mitigate attacks and reduce risk

18
New cards

Exploit

A technique or tool used by threat agents to take advantage of a system's vulnerability

19
New cards

Exposure

A state of vulnerability where an asset is open to being compromised

20
New cards

Loss

Any damage, theft, or destruction of an asset

21
New cards

Protection Profile / Security Posture

The complete, integrated set of security controls and policies an organization has in place

22
New cards

Risk

The probability that a vulnerability will be exploited by a threat agent to cause loss

23
New cards

Threat

Any category of object, person, or force that represents a constant danger to an asset

24
New cards

Threat Agent

The specific instance of a threat, such as a specific hacker or a specific hurricane

25
New cards

Vulnerability

A weakness, flaw, or loophole in a system or security posture

26
New cards

Computer as the Subject

The computer is used as an active tool to conduct an attack, such as sending spam or launching DDoS

27
New cards

Computer as the Object

The computer is the target being attacked, such as having its database stolen or system shut down

28
New cards

Software (IS component)

Applications and operating systems

29
New cards

Hardware (IS component)

Physical computing machinery

30
New cards

Data (IS component)

Stored files, databases, and transactions; the primary target of attacks

31
New cards

People (IS component)

Users, administrators, and stakeholders; often the weakest link

32
New cards

Procedures (IS component)

Written instructions, policies, and regulations

33
New cards

Networks (IS component)

Communication lines and protocols

34
New cards

Bottom-Up Approach

Systems administrators drive security improvements from the grassroots technical level; often fails from lack of executive support

35
New cards

Top-Down Approach

Security initiated and structured by upper management with strong support, funding, and a formal SDLC

36
New cards

SDLC

Systems Development Life Cycle; a structured, multi-phase process for developing information systems

37
New cards

SecSDLC

Security Systems Development Life Cycle; a structured, multi-phase process for developing a security program

38
New cards

The Champion

A high-level executive sponsor who secures administrative backing, corporate visibility, and critical project funding

39
New cards

The Team Leader

A project manager who coordinates tasks, manages personnel, and understands the technical/policy demands of InfoSec

40
New cards

Security Policy Developers

Professionals skilled in mapping organizational culture and compliance mandates to practical security policies

41
New cards

Risk Assessment Specialists

Experts in quantifying asset value, performing financial risk assessments, and evaluating control costs

42
New cards

Security Professionals

Technical specialists who design, configure, and implement systems and network security controls

43
New cards

Systems Administrators

IT staff responsible for day-to-day hosting, upkeep, and performance of system environments

44
New cards

End Users

The actual operators of systems who provide feedback to ensure security controls do not disrupt workflows

45
New cards

Data Owner

Senior executives ultimately responsible for the overall security and classification of a specific dataset

46
New cards

Data Custodian

Technical staff, usually SysAdmins, responsible for the storage, backup, transport, and active protection of data

47
New cards

Data Users

Employees who interact with data during daily duties and must adhere to handling policies

48
New cards

Security as Art

Implementation requires subjective judgment, creative problem-solving, and tailored designs unique to each organization

49
New cards

Security as Science

Built on high-performance technology and logical, predictable, quantifiable outcomes of software and hardware flaws

50
New cards

Security as a Social Science

Focuses on human behaviors, since humans are the weakest link, requiring attention to sociology and psychology

51
New cards

Virus

Code that infects systems and replicates by attaching to other files

52
New cards

Worm

An independent program that replicates itself across networks

53
New cards

Trojan Horse

Desirable software hiding a malicious payload

54
New cards

Logic Bomb

Code triggered by a specific event or time

55
New cards

Back Door (Trap Door)

A mechanism that bypasses normal authentication to grant access

56
New cards

Polymorphic Threat

Malware that changes its shape/signature to evade detection

57
New cards

Expert Hacker

A hacker who develops software scripts, writes exploits, and masters multiple technical skills

58
New cards

Script Kiddie

An unskilled hacker who uses expertly written tools without fully understanding the underlying systems

59
New cards

Information Extortion

Stealing information and demanding payment for its return or nondisclosure, common in credit card theft

60
New cards

Technological Obsolescence

Outdated or antiquated infrastructure leading to untrustworthy, unreliable systems

61
New cards

Password Crack

Attempting to reverse-calculate or guess an encrypted password

62
New cards

Brute Force

Utilizing raw computing power to try every possible combination of a password

63
New cards

Dictionary Attack

Targeted password guessing that uses a pre-compiled list of common passwords

64
New cards

Denial-of-Service (DoS)

Sending a massive volume of connection or information requests to crash a target system or block legitimate traffic

65
New cards

Distributed DoS (DDoS)

A coordinated stream of DoS requests launched from many locations simultaneously

66
New cards

Spoofing

Forging packet headers, like IP addresses, to make a transmission appear to originate from a trusted host

67
New cards

Man-in-the-Middle

Sniffing network packets, modifying them, and re-inserting them into the path; also called TCP Hijacking

68
New cards

Spam

Unsolicited commercial e-mail that serves as an active attack vector for malware

69
New cards

Mail Bombing

A specific form of DoS where massive quantities of e-mail are directed to a target inbox

70
New cards

Simplicity (SA principle)

Keep the software design as simple and small as possible

71
New cards

Permission, Not Exclusion

Access decisions must be based on explicit permission rather than blocking, i.e. Default Deny

72
New cards

Continuous Verification

Every single access to every object must be checked for authority

73
New cards

Key-Based Security

Protection must depend on the strength of keys/passwords, not the secrecy of the design

74
New cards

Dual Control

Critical mechanisms should require two independent keys to unlock, preventing single points of failure

75
New cards

Least Privilege

Programs and users must utilize only the privileges necessary to complete their tasks

76
New cards

Buffer Overrun

Writing more data to an allocation zone than it is built to hold, corrupting memory

77
New cards

Command Injection

Passing malicious user input directly to system command interpreters

78
New cards

Cross-Site Scripting (XSS)

Injecting malicious scripts into trusted websites viewed by other users