IT 107 - Information Assurance and Security 1

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/89

flashcard set

Earn XP

Description and Tags

This consists of Module 1 - Module 6 topics from a reference book of Michael E. Whitman, Herbert J. Mattord - Principles of Information Security. Module 1: Introduction to Information Security, Module 2: The need for Information Security, Module 3: The need for Information Security, Module 4: Risk Management, Module 5: Incident Response and Contingency Planning, and Module 6: Legal, Ethical, and Professional Issues in Information Security

Last updated 5:45 AM on 10/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

90 Terms

1
New cards

Baseline Security Responsibility (Organization & Employee)

The organization must protect information to the best of its ability. Employees must possess working knowledge on safeguarding assigned assets and know how to prevent unauthorized disclosure, damage, or destruction.

2
New cards

Computer Security

This term specified the protection of the physical location and assets associated with computer technology from outside threats, but it later came to represent all actions taken to protect computer systems from losses.

3
New cards

Early History of Computer Security (WWII–1960s)

Began in WWII with physical security for mainframes (e.g., Enigma-decoding systems). The 1960s introduced ARPANET, designed by Dr. Larry Roberts, laying the groundwork for network security.

4
New cards

RAND Report R-609 (1970)

A landmark publication that expanded the scope of security beyond physical hardware to encompass data protection, access controls, and security policy management.

5
New cards

Information Security (Infosec)

The protection of the confidentiality, integrity, and availability of information assets across storage, processing, and transmission via policy, education, training/awareness, and technology.

6
New cards

C.I.A. Triad

The traditional industry standard for computer security consisting of Confidentiality, Integrity, and Availability. Currently viewed as insufficient on its own for modern, constantly evolving environments.

7
New cards

CNSS Definition of Information Security

Protection of information and its critical elements, including the hardware and systems that store, use, and transmit that information.

8
New cards

Access

A subject or object’s ability to use, manipulate, modify, or affect another subject or object (Authorized = Legal; Hacker = Illegal).

9
New cards

Asset

Any logical (software, data, website) or physical (hardware, personnel) organizational resource being protected.

10
New cards

Control/Countermeasure/Safeguard

Security mechanisms, policies, or procedures implemented to successfully counter attacks, reduce risk, resolve vulnerabilities, and improve overall security posture.

11
New cards

Attack

An intentional or unintentional act that can damage or otherwise compromise information and the systems that support it.

An active, deliberate attempt that uses an exploit to target a vulnerability and cause damage.

12
New cards

Direct Attack

Originates directly from the threat actor (e.g., hacker breaking into a PC).

13
New cards

Indirect Attack

Originates from a compromised resource acting under threat control (e.g., a botnet attacking target systems).

14
New cards

Security

State of being secure and free from danger or harm; also, the actions taken to make someone or something secure.

15
New cards

Information Security

Protection of the confidentiality, integrity, and availability of information assets, whether in storage, processing, or transmission, via the application of policy, education, training and awareness, and technology.


16
New cards

Network Security

Subset of communications security; the protection of voice and data networking components, connections, and content.


17
New cards

National Security

Is a multilayered system that protects the sovereignty of a state, its people, its resources, and its territory.

18
New cards

Successful Organization Protects

  • Its people

  • Operations

  • Physical infrastructure

  • Functions

  • Communications

  • Information


19
New cards

Passive Attack

Someone who casually reads sensitive information not intended for his or her use is committing a ________.

20
New cards

Intentional Attack

A hacker attempting to break into an information system is an __________.

21
New cards

Unintentional Attack

A lightning strike that causes a building fire is an __________.

22
New cards

Computer as a Subject of Attack

The computer is used as an agent/tool to conduct the attack.

23
New cards

Computer as an Object of Attack

The computer is the target entity being attacked.

24
New cards

Exploit

A specific technique, tool, or documented procedure used to take advantage of a vulnerability in a system or software for personal gain or damage.

25
New cards

Exposure

The condition or state of being vulnerable where a weakness is known to an attacker.

26
New cards

Loss

A single instance of an information asset suffering damage, destruction, unauthorized modification, disclosure, or denial of use.

27
New cards

Protection Profile (Security Posture)

The total set of controls and safeguards—policy, education, training, and technology—that an organization deploys to protect its assets.

28
New cards

Risk

The probability of an unwanted occurrence, adverse event, or loss.

29
New cards

Risk Appetite

The quantity and nature of risk an organization is willing to accept.

30
New cards

Threat

Any event/circumstance with potential to adversely affect operations or assets.

constant potential risk or danger to an asset (e.g., malware, natural disaster).

31
New cards

Threat Agent

A specific instance within a threat source (e.g., a specific hacker, lightning strike, or tornado).

32
New cards

Threat Source

A general category representing the origin of danger (e.g., "Acts of Nature").

33
New cards

Threat Event

An occurrence of an event caused by a threat agent (often used interchangeably with "attack").

34
New cards

Vulnerability

A potential weakness in an asset or its defensive control system(s), such as a software bug, unpatched port, or unlocked door.

A flaw, weakness, or lack of controls in a system that leaves assets exposed.

35
New cards

Confidentiality

Attribute ensuring data is accessible only to authorized entities with a valid need-to-know. Protected by classification, secure storage, policies, and training.

36
New cards

Integrity

Attribute ensuring data remains whole, authentic, uncorrupted, and untampered with. Verified via file hashing, file size monitoring, and error correction codes.

37
New cards

Availability

Attribute ensuring authorized users can access data in a usable format without obstruction whenever needed.

38
New cards

Accuracy

Attribute representing data that is complete, correct, and free from deliberate or accidental errors/modifications.

39
New cards

Authenticity

Attribute guaranteeing information is genuine, original, and unaltered from its state of creation or transmission (opposite of spoofing).

40
New cards

Utility

Attribute representing the usefulness and value of information formatted so end users can derive meaning or insights.

41
New cards

Verification and Protection Controls

File Hashing: Calculates a unique hash value using a mathematical algorithm; a mismatch with the recorded hash indicates data tampering or corruption.


File Size & Monitoring: Checking file size changes to spot virus/worm activity.


Error Detection & Correction: Uses redundancy bits, check bits, and error-correcting codes during transmission to trigger automatic retransmission of corrupted data.


42
New cards

Possession

Refers to having legitimate ownership or control over information media.

Does not automatically cause a breach of confidentiality if the data remains encrypted and unreadable to the attacker.

43
New cards

Breach of Possession

Occurs when unauthorized individuals gain physical or digital control of data (e.g., stolen backup tapes or ransomware encryption).

44
New cards

McCumber Cube Structure

A 3x3x3 architectural framework yielding 27 cells requiring controls:

  1. Goals: Confidentiality, Integrity, Availability

  2. States: Storage, Processing, Transmission

  3. Safeguards: Policy, Education, Technology


Created by John McCumber in 1991.

45
New cards

6 Components of an Information System

Software, Hardware, Data, People (weakest link), Procedures, and Networks.

46
New cards

Software

Includes applications, operating systems, and command utilities. It carries the "lifeblood" of information within an organization but is often the most difficult component to secure due to programming errors, bugs, and design flaws.

47
New cards

Hardware

  • The physical technology that houses and executes the software, stores and transports data, and provides interfaces for input and output. Physical security policies focus on protecting hardware assets from theft or physical damage.


48
New cards

Data

The stored, processed, or transmitted information managed by the system. It is frequently the primary target of security attacks.

49
New cards

People

Includes users, system administrators, and staff. Often considered the weakest link in security, people can accidentally or intentionally introduce security risks through lack of awareness, social engineering, or improper procedures.

50
New cards

Procedures

The written instructions, policies, and operational rules that govern how the information system is used and managed.

51
New cards

Networks

  • The communication systems and connections (such as local networks or the internet) that link hardware devices together, allowing data and resources to be shared across the organization.


52
New cards

Bottom-Up Approach

  • Process: Driven by system administrators and technical staff working on day-to-day operations to patch and secure systems.

  • Limitation: Often lacks organizational support, clear direction, top-level authority, and dedicated funding, making it less effective overall.


53
New cards

Top-Down Approach

  • Process: Initiated by upper management, who establish security policies, allocate resources, assign accountability, and dictate outcomes.

  • Advantage: Highly structured and effective because it secures executive leadership, funding, and organization-wide enforcement.


54
New cards

Senior Management/Leadership

Champion security initiatives, approve strategic security policies, and allocate necessary budget and personnel.

55
New cards

Chief Information Officer (CIO)

  • Oversees the organization’s overall IT strategy, aligning technology goals with business objectives and ensuring security initiatives are integrated.


56
New cards

Chief Information Security Officer (CISO)

Directly responsible for managing the information security program, assessing risks, enforcing policies, and coordinating incident responses.

57
New cards

System and Network Administrators

 Implement and maintain technical safeguards (e.g., firewalls, intrusion detection systems, access controls, and patches).

58
New cards

Champion (Project Team Role)

  • A senior executive who promotes the project and ensures its support, both financially and administratively, at the highest levels of the organization


59
New cards

Data Owner

An executive with ultimate responsibility and control over a specific dataset, responsible for setting and modifying data classifications.

60
New cards

Data Custodian (Steward)

Technical personnel handling day-to-day administration, storage, backups, and security enforcement on data systems.

61
New cards

Data Trustee

A senior manager appointed by a busy Data Owner to oversee information management and coordinate with Data Custodians.

62
New cards

3 Communities of Interest

  1. Infosec Management: Focused on security and threat prevention.

  2. IT Management: Focused on system design, performance, speed, and usability.

  3. Organizational Management: Focused on overarching business operations and goals.


63
New cards

Security as an Art

Relies on practitioner intuition, experience, non-standardized problem-solving, and custom solutions.

64
New cards

Security as a Science

Relies on precise technical rules, mathematical algorithms (cryptography), metrics, formal models, and repeatable processes.

65
New cards

Why Organizations Need Information Security

Organizations depend on information to drive decisions, maintain communication, manage operations/transactions, deliver customer services, and protect reputation against constant threats to data and supporting systems.

66
New cards

Four Primary Functions of Information Security Program

  1. PROTECTING THE ORGANIZATION'S ABILITY TO FUNCTION: Information security is a business and management issue, not just a technical problem. It ensures that business operations continue smoothly despite risks and interruptions.

  1. PROTECTING COLLECTED AND USED DATA: Organizations rely heavily on data to deliver value and keep transaction records. Information security safeguards this data whether it is in transmission, in processing, or at rest.


  1. ENABLING THE SAFE OPERATION OF APPLICATIONS: Modern organizations rely on infrastructure platforms, operating systems, email, and messaging tools. Security creates a protected environment for these applications to run safely.

  1. SAFEGUARDING TECHNOLOGY ASSETS: As organizations grow, they require scalable hardware solutions (such as firewalls, VPNs, and intrusion detection systems) to defend against evolving cyber threats and a growing pool of potential attackers.


67
New cards

Relationship of Threat, Vulnerability, and Attack

A threat represents the potential danger, a vulnerability is the weakness that permits the danger, and an attack is the actual event where a threat agent exploits that weakness.

68
New cards

Exposed, Altered, Destroyed, Stolen, Unavailable

5 States Unprotected Information is Vulnerable To

69
New cards

6 Major Risks of Inadequate InfoSec Protection

Loss of transaction records/value, inability to function, increased vulnerability to attacks, data theft/sabotage/corruption, loss of trust, and compromise by internal/external threats.

70
New cards

Operations, People, Systems, Reputation, Information

5 Core Areas Protected by InfoSec

71
New cards

How InfoSec Protects Operations & People

  • Operations: Prevents operational disruptions, downtime, and revenue loss caused by cyber attacks or system failures.

  • People: Educates employees via security awareness/training to mitigate risks like insider errors, social engineering, and policy non-compliance.


72
New cards

How InfoSec Protects Systems, Reputation, & Information

  • Systems: Safeguards infrastructure (OS, databases, hardware, cloud, networks) so they run reliably.

  • Reputation: Prevents loss of customer trust and brand damage caused by data breaches or defacements.

  • Information: Preserves CIA triad of data at rest, in processing, and in transmission.


73
New cards

Impact of Attacks on C.I.A. Triad

  • Confidentiality: Breached when sensitive data is exposed, stolen, or accessed without permission (e.g., data sniffing).

  • Integrity: Breached when data/systems are altered, corrupted, or damaged without authorization (e.g., website defacement).

  • Availability: Breached when systems/networks are taken offline or rendered unusable (e.g., ransomware, DoS).


74
New cards

12 Categories of InfoSec Threats

Intellectual Property Compromises, Quality of Service Deviations, Espionage/Trespass, Forces of Nature, Human Error/Failure, Information Extortion, Sabotage/Vandalism, Software Attacks, Technical Hardware Failures, Technical Software Failures, Technological Obsolescence, and Theft.

75
New cards

Compromises to Intellect Property

Unauthorized copying, piracy, copyright infringement, or exposure of trade secrets and software (e.g., employees using company ideas for personal gain).

76
New cards

Deviations in Quality of Service

Irregularities or outages in critical supporting utility services, such as power supply, water, ISP connections, or WAN services.

77
New cards

Espionage or Trespass

Unauthorized access to electronic systems or physical locations to gather confidential data or industrial secrets (e.g., shoulder surfing, entering restricted server rooms).

78
New cards

Forces of Nature

Uncontrollable physical hazards ("acts of God") such as fires, floods, earthquakes, lightning, tornados, and severe weather.

79
New cards

Human Error or Failure

Unintentional mistakes, negligence, improper training, accidental misconfigurations, or falling for social engineering tactics by employees.

80
New cards

Information Extortion

Cyber-blackmail attempts demanding payment or ransom in exchange for restoring system access or preventing the public disclosure of stolen data (e.g., ransomware).

81
New cards

Sabotage or Vandalism

Deliberate destruction, alteration, or defacement of physical equipment, websites, or systems to harm an organization's operations or reputation (e.g., hacktivist website defacement).

82
New cards

Software Attacks

Execution of malicious code or attack methods designed to disrupt or exploit systems (e.g., viruses, worms, Trojans, ransomware, backdoors, DoS/DDoS).

83
New cards

Technical Hardware Failures or Errors

Physical equipment breakdowns, manufacturing defects, or component failures in servers, network devices, or storage media.

84
New cards

Technical Software Failures or Errors

Coding flaws, bugs, unpatched application vulnerabilities, or unexpected software behaviors.

85
New cards

Technological Obsolescence

Outdated or legacy technologies, software, or hardware that no longer receive vendor support or security updates, leaving them exposed to exploits.

86
New cards

Theft

The illegal physical or digital confiscation or removal of equipment, media, paper records, or organizational data without authorization.

87
New cards

Human and Intentional Threats

Threats that are deliberate actions or human-driven behaviors carried out by internal or external threat agents that jeopardize an organization's information assets.

  1. Compromises to Intellectual Property

  2. Espionage or Trespass

  3. Human Error or Failure

  4. Information Extortion

  5. Sabotage or Vandalism

  6. Theft


88
New cards

Technical Threat, Technical Failures, and Obsolescence

These threats involve failures, flaws, or attacks related to hardware, software, and electronic systems.

  1. Software Attacks

  1. Technical Hardware Failures or Errors

  1. Technical Software Failures or Errors

  2. Technological Obsolescence


89
New cards

Environmental Threats

These threats stem from physical surroundings, nature, weather, and infrastructure external to the IT systems themselves.

  1. Forces of Nature


90
New cards

Operational Threats

These threats arise from business operations, administrative processes, human actions, and everyday organizational activities.

  1. Deviations in Quality of Service