Information Security Chapter 1

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/36

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:18 PM on 8/24/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

37 Terms

1
New cards

Confidentiality

Information should be read by authorized users only

2
New cards

Integrity

Data is stored and transferred as intended and any modification is authorized

3
New cards

Availability

Information is accessible to those authorized to view or modify it

4
New cards

Non-Repudiation

Persons cannot deny creating or modifying data

5
New cards

Cybersecurity Framework

Identify, Protect, Detect, Respond, Recover

6
New cards

Managerial (Security Control Category)

Give oversight of system

7
New cards

Operational (Security Control Category)

Relies on a person for implementation

8
New cards

Technical (Security Control Category)

Implemented in operating systems, software, and security appliances

9
New cards

Physical (Security Control Categoy)

Devices that mediate access to premises and hardware

10
New cards

Preventive (Security Control Functional Types)

  • Physically or logically restricts unauthorized access

  • Operates before an attack


11
New cards

Detective (Security Control Functional Types)

  • Identifies attempted or successful intrusions

  • Operated during an attack


12
New cards

Corrective (Security Control Functional Types)

  • Responds to and fixes an incident and may prevent its recurrences

  • Operates after an attack


13
New cards

Directive (Security Control Functional Types)

Enforces a rule of behavior

14
New cards

Deterrent

Psychologically discourages intrusions

15
New cards

Compensating

  • Substitutes for principal control

  • Associated with framework compliance measures


16
New cards

Chief Information Officer (Information Security Roles)

CIO (Overall Responsibility)

17
New cards

Chief Security Officer (Information Security Roles)

CSO (Overall Responsibility)

18
New cards

Managerial (Information Security Roles)

Oversees the implementation and management of an organization's IT security policies, personnel, and resources.

19
New cards

Information Systems Security Officer (Information Security Roles)

ISSO (Technical)

20
New cards

Non-technical (Information Security Roles)

Employees and personnel who help protect information by following security policies, procedures, and safe security practices, even if they do not manage or configure IT systems.

21
New cards

Due care/liability (Responsibilities)

The responsibility of an organization or individual to take reasonable steps to protect information systems and be legally accountable if negligence or failure to fulfill that responsibility results in security breaches or damages.

22
New cards

Risk assessment and testing

Information Security Competencies (1)

23
New cards

Specifying, sourcing, installing, and configuring secure devices and software

Information Security Competencies (2)

24
New cards

Access Control and User Privileges

Information Security Competencies (3)

25
New cards

Auditing Logs and Events

Information Security Competencies (4)

26
New cards

Incidence response and reporting

Information Security Competencies (5)

27
New cards

Business Continuity and Disaster Recovery

Information Security Competencies (6)

28
New cards

Security Operations Center

SOC

29
New cards

Development, security, and operations

DevSecOps

30
New cards

Cyber Incident Response Team

CIRT

31
New cards

Gap Analysis

A business tool used to compare a company's current performance or state with a desired future goal

32
New cards
33
New cards

Access Control

Identification, Authentication, Authorization, and Accounting

34
New cards

Identification

The system owner confirms the user’s identity and creates an account to represent the user

35
New cards

Authentication

Entering the credentials and comparing it to the hashed credential

36
New cards

Authorization

For each action, the account performs a permission list is checked to allow or deny the action

37
New cards

Accounting

The system tracks permission usage in a log. The user cannot prevent this auditing