Module 1: Introduction to Information Security

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/44

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:17 PM on 9/18/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

45 Terms

1
New cards

Confidentiality

Ensuring data is not disclosed to unauthorized people, entities, or processes

2
New cards

Integrity

Ensuring data has not been altered in an unauthorized manner

3
New cards

Availability

Ensuring systems and data are accessible to authorized users when needed

4
New cards

CIA Triad

Confidentiality, Integrity, Availability — the three core goals of information security

5
New cards

Authentication

Verifying a user's claimed identity (e.g. password, biometric)

6
New cards

Authorization

Granting an authenticated user permission to access specific resources

7
New cards

Accounting

Tracking and logging user activity for auditing purposes

8
New cards

AAA

Authentication, Authorization, Accounting — framework for controlling and monitoring access

9
New cards

Managerial Control

Administrative controls like policies and procedures set by management

10
New cards

Operational Control

Controls implemented by people in day-to-day operations (e.g. security awareness training)

11
New cards

Technical Control

Controls implemented through technology (e.g. firewalls, encryption)

12
New cards

Physical Control

Controls that physically restrict access (e.g. locks, fences, guards)

13
New cards

Deterrent Control

Discourages an attacker from attempting an attack (e.g. warning signs)

14
New cards

Preventive Control

Stops an attack before it happens (e.g. firewall rules)

15
New cards

Detective Control

Identifies that an attack occurred (e.g. IDS, logs)

16
New cards

Compensating Control

An alternative control used when the primary control isn't feasible

17
New cards

Corrective Control

Restores systems after an attack (e.g. backups, patches)

18
New cards

Directive Control

Directs or mandates a behavior through policy (e.g. acceptable use policy)

19
New cards

Threat Actor

Any person or entity responsible for a security incident

20
New cards

Attributes of Actors

Characteristics used to classify threat actors: sophistication, resources, internal/external

21
New cards

Unskilled Attacker

Low-skill attacker using existing tools/scripts (aka "script kiddie")

22
New cards

Hacktivist

Attacker motivated by political or philosophical beliefs, aims for disruption/chaos

23
New cards

Organized Crime

Threat actor group motivated primarily by financial gain

24
New cards

Nation-State Actor

Highly resourced attacker sponsored by a government, motivated by espionage or war

25
New cards

Insider Threat

Threat actor who is an employee/contractor, motivated by revenge, financial gain, or blackmail

26
New cards

Shadow IT

Unauthorized IT systems/software used within an organization without approval

27
New cards

Data Exfiltration

Unauthorized transfer/theft of data out of a system

28
New cards

Service Disruption

Attack goal of taking down or degrading a service

29
New cards

Attack Surface

All the points where an unauthorized user could try to enter or extract data

30
New cards

Vulnerable Software

Software containing exploitable weaknesses (client-based or agentless)

31
New cards

Unsupported Systems

Systems/apps no longer receiving security updates (legacy/EOL)

32
New cards

Removable Devices

USB drives and similar media that can introduce malware or exfiltrate data

33
New cards

Unsecure Networks

Networks lacking proper protections (e.g. open Wi-Fi)

34
New cards

Open Service Ports

Network ports left open and exploitable by attackers

35
New cards

Default Credentials

Factory-set usernames/passwords that attackers try first

36
New cards

Message-Based Vector

Attack delivered via SMS or instant messaging

37
New cards

Supply Chain

The network of suppliers, vendors, and providers an org depends on

38
New cards

Managed Service Provider (MSP)

Third-party company managing IT infrastructure/services for a client

39
New cards

OS-Based Vulnerability

A weakness in an operating system that can be exploited

40
New cards

Malicious Update

A software update that has been tampered with to deliver malware

41
New cards

Firmware Vulnerability

A weakness in low-level device software

42
New cards

Legacy Platform

Outdated system still in use despite lacking modern security support

43
New cards

End-of-Life (EOL)

Point at which a vendor stops supporting/patching a product

44
New cards

Misconfiguration

Improperly set up system/security settings that create vulnerabilities

45
New cards

Zero-Day

A vulnerability unknown to the vendor with no patch available yet