1/89
This consists of Module 1 - Module 6 topics from a reference book of Michael E. Whitman, Herbert J. Mattord - Principles of Information Security. Module 1: Introduction to Information Security, Module 2: The need for Information Security, Module 3: The need for Information Security, Module 4: Risk Management, Module 5: Incident Response and Contingency Planning, and Module 6: Legal, Ethical, and Professional Issues in Information Security
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Baseline Security Responsibility (Organization & Employee)
The organization must protect information to the best of its ability. Employees must possess working knowledge on safeguarding assigned assets and know how to prevent unauthorized disclosure, damage, or destruction.
Computer Security
This term specified the protection of the physical location and assets associated with computer technology from outside threats, but it later came to represent all actions taken to protect computer systems from losses.
Early History of Computer Security (WWII–1960s)
Began in WWII with physical security for mainframes (e.g., Enigma-decoding systems). The 1960s introduced ARPANET, designed by Dr. Larry Roberts, laying the groundwork for network security.
RAND Report R-609 (1970)
A landmark publication that expanded the scope of security beyond physical hardware to encompass data protection, access controls, and security policy management.
Information Security (Infosec)
The protection of the confidentiality, integrity, and availability of information assets across storage, processing, and transmission via policy, education, training/awareness, and technology.
C.I.A. Triad
The traditional industry standard for computer security consisting of Confidentiality, Integrity, and Availability. Currently viewed as insufficient on its own for modern, constantly evolving environments.
CNSS Definition of Information Security
Protection of information and its critical elements, including the hardware and systems that store, use, and transmit that information.
Access
A subject or object’s ability to use, manipulate, modify, or affect another subject or object (Authorized = Legal; Hacker = Illegal).
Asset
Any logical (software, data, website) or physical (hardware, personnel) organizational resource being protected.
Control/Countermeasure/Safeguard
Security mechanisms, policies, or procedures implemented to successfully counter attacks, reduce risk, resolve vulnerabilities, and improve overall security posture.
Attack
An intentional or unintentional act that can damage or otherwise compromise information and the systems that support it.
An active, deliberate attempt that uses an exploit to target a vulnerability and cause damage.
Direct Attack
Originates directly from the threat actor (e.g., hacker breaking into a PC).
Indirect Attack
Originates from a compromised resource acting under threat control (e.g., a botnet attacking target systems).
Security
State of being secure and free from danger or harm; also, the actions taken to make someone or something secure.
Information Security
Protection of the confidentiality, integrity, and availability of information assets, whether in storage, processing, or transmission, via the application of policy, education, training and awareness, and technology. |
Network Security
Subset of communications security; the protection of voice and data networking components, connections, and content. |
National Security
Is a multilayered system that protects the sovereignty of a state, its people, its resources, and its territory.
Successful Organization Protects
Its people
Operations
Physical infrastructure
Functions
Communications
Information
Passive Attack
Someone who casually reads sensitive information not intended for his or her use is committing a ________.
Intentional Attack
A hacker attempting to break into an information system is an __________.
Unintentional Attack
A lightning strike that causes a building fire is an __________.
Computer as a Subject of Attack
The computer is used as an agent/tool to conduct the attack.
Computer as an Object of Attack
The computer is the target entity being attacked.
Exploit
A specific technique, tool, or documented procedure used to take advantage of a vulnerability in a system or software for personal gain or damage.
Exposure
The condition or state of being vulnerable where a weakness is known to an attacker.
Loss
A single instance of an information asset suffering damage, destruction, unauthorized modification, disclosure, or denial of use.
Protection Profile (Security Posture)
The total set of controls and safeguards—policy, education, training, and technology—that an organization deploys to protect its assets.
Risk
The probability of an unwanted occurrence, adverse event, or loss.
Risk Appetite
The quantity and nature of risk an organization is willing to accept.
Threat
Any event/circumstance with potential to adversely affect operations or assets.
constant potential risk or danger to an asset (e.g., malware, natural disaster).
Threat Agent
A specific instance within a threat source (e.g., a specific hacker, lightning strike, or tornado).
Threat Source
A general category representing the origin of danger (e.g., "Acts of Nature").
Threat Event
An occurrence of an event caused by a threat agent (often used interchangeably with "attack").
Vulnerability
A potential weakness in an asset or its defensive control system(s), such as a software bug, unpatched port, or unlocked door.
A flaw, weakness, or lack of controls in a system that leaves assets exposed.
Confidentiality
Attribute ensuring data is accessible only to authorized entities with a valid need-to-know. Protected by classification, secure storage, policies, and training.
Integrity
Attribute ensuring data remains whole, authentic, uncorrupted, and untampered with. Verified via file hashing, file size monitoring, and error correction codes.
Availability
Attribute ensuring authorized users can access data in a usable format without obstruction whenever needed.
Accuracy
Attribute representing data that is complete, correct, and free from deliberate or accidental errors/modifications.
Authenticity
Attribute guaranteeing information is genuine, original, and unaltered from its state of creation or transmission (opposite of spoofing).
Utility
Attribute representing the usefulness and value of information formatted so end users can derive meaning or insights.
Verification and Protection Controls
File Hashing: Calculates a unique hash value using a mathematical algorithm; a mismatch with the recorded hash indicates data tampering or corruption.
File Size & Monitoring: Checking file size changes to spot virus/worm activity.
Error Detection & Correction: Uses redundancy bits, check bits, and error-correcting codes during transmission to trigger automatic retransmission of corrupted data.
Possession
Refers to having legitimate ownership or control over information media.
Does not automatically cause a breach of confidentiality if the data remains encrypted and unreadable to the attacker.
Breach of Possession
Occurs when unauthorized individuals gain physical or digital control of data (e.g., stolen backup tapes or ransomware encryption).
McCumber Cube Structure
A 3x3x3 architectural framework yielding 27 cells requiring controls:
Goals: Confidentiality, Integrity, Availability
States: Storage, Processing, Transmission
Safeguards: Policy, Education, Technology
Created by John McCumber in 1991.
6 Components of an Information System
Software, Hardware, Data, People (weakest link), Procedures, and Networks.
Software
Includes applications, operating systems, and command utilities. It carries the "lifeblood" of information within an organization but is often the most difficult component to secure due to programming errors, bugs, and design flaws.
Hardware
The physical technology that houses and executes the software, stores and transports data, and provides interfaces for input and output. Physical security policies focus on protecting hardware assets from theft or physical damage.
Data
The stored, processed, or transmitted information managed by the system. It is frequently the primary target of security attacks.
People
Includes users, system administrators, and staff. Often considered the weakest link in security, people can accidentally or intentionally introduce security risks through lack of awareness, social engineering, or improper procedures.
Procedures
The written instructions, policies, and operational rules that govern how the information system is used and managed.
Networks
The communication systems and connections (such as local networks or the internet) that link hardware devices together, allowing data and resources to be shared across the organization.
Bottom-Up Approach
Process: Driven by system administrators and technical staff working on day-to-day operations to patch and secure systems.
Limitation: Often lacks organizational support, clear direction, top-level authority, and dedicated funding, making it less effective overall.
Top-Down Approach
Process: Initiated by upper management, who establish security policies, allocate resources, assign accountability, and dictate outcomes.
Advantage: Highly structured and effective because it secures executive leadership, funding, and organization-wide enforcement.
Senior Management/Leadership
Champion security initiatives, approve strategic security policies, and allocate necessary budget and personnel.
Chief Information Officer (CIO)
Oversees the organization’s overall IT strategy, aligning technology goals with business objectives and ensuring security initiatives are integrated.
Chief Information Security Officer (CISO)
Directly responsible for managing the information security program, assessing risks, enforcing policies, and coordinating incident responses.
System and Network Administrators
Implement and maintain technical safeguards (e.g., firewalls, intrusion detection systems, access controls, and patches).
Champion (Project Team Role)
A senior executive who promotes the project and ensures its support, both financially and administratively, at the highest levels of the organization
Data Owner
An executive with ultimate responsibility and control over a specific dataset, responsible for setting and modifying data classifications.
Data Custodian (Steward)
Technical personnel handling day-to-day administration, storage, backups, and security enforcement on data systems.
Data Trustee
A senior manager appointed by a busy Data Owner to oversee information management and coordinate with Data Custodians.
3 Communities of Interest
Infosec Management: Focused on security and threat prevention.
IT Management: Focused on system design, performance, speed, and usability.
Organizational Management: Focused on overarching business operations and goals.
Security as an Art
Relies on practitioner intuition, experience, non-standardized problem-solving, and custom solutions.
Security as a Science
Relies on precise technical rules, mathematical algorithms (cryptography), metrics, formal models, and repeatable processes.
Why Organizations Need Information Security
Organizations depend on information to drive decisions, maintain communication, manage operations/transactions, deliver customer services, and protect reputation against constant threats to data and supporting systems.
Four Primary Functions of Information Security Program
PROTECTING THE ORGANIZATION'S ABILITY TO FUNCTION: Information security is a business and management issue, not just a technical problem. It ensures that business operations continue smoothly despite risks and interruptions.
PROTECTING COLLECTED AND USED DATA: Organizations rely heavily on data to deliver value and keep transaction records. Information security safeguards this data whether it is in transmission, in processing, or at rest.
ENABLING THE SAFE OPERATION OF APPLICATIONS: Modern organizations rely on infrastructure platforms, operating systems, email, and messaging tools. Security creates a protected environment for these applications to run safely.
SAFEGUARDING TECHNOLOGY ASSETS: As organizations grow, they require scalable hardware solutions (such as firewalls, VPNs, and intrusion detection systems) to defend against evolving cyber threats and a growing pool of potential attackers.
Relationship of Threat, Vulnerability, and Attack
A threat represents the potential danger, a vulnerability is the weakness that permits the danger, and an attack is the actual event where a threat agent exploits that weakness.
Exposed, Altered, Destroyed, Stolen, Unavailable
5 States Unprotected Information is Vulnerable To
6 Major Risks of Inadequate InfoSec Protection
Loss of transaction records/value, inability to function, increased vulnerability to attacks, data theft/sabotage/corruption, loss of trust, and compromise by internal/external threats.
Operations, People, Systems, Reputation, Information
5 Core Areas Protected by InfoSec
How InfoSec Protects Operations & People
Operations: Prevents operational disruptions, downtime, and revenue loss caused by cyber attacks or system failures.
People: Educates employees via security awareness/training to mitigate risks like insider errors, social engineering, and policy non-compliance.
How InfoSec Protects Systems, Reputation, & Information
Systems: Safeguards infrastructure (OS, databases, hardware, cloud, networks) so they run reliably.
Reputation: Prevents loss of customer trust and brand damage caused by data breaches or defacements.
Information: Preserves CIA triad of data at rest, in processing, and in transmission.
Impact of Attacks on C.I.A. Triad
Confidentiality: Breached when sensitive data is exposed, stolen, or accessed without permission (e.g., data sniffing).
Integrity: Breached when data/systems are altered, corrupted, or damaged without authorization (e.g., website defacement).
Availability: Breached when systems/networks are taken offline or rendered unusable (e.g., ransomware, DoS).
12 Categories of InfoSec Threats
Intellectual Property Compromises, Quality of Service Deviations, Espionage/Trespass, Forces of Nature, Human Error/Failure, Information Extortion, Sabotage/Vandalism, Software Attacks, Technical Hardware Failures, Technical Software Failures, Technological Obsolescence, and Theft.
Compromises to Intellect Property
Unauthorized copying, piracy, copyright infringement, or exposure of trade secrets and software (e.g., employees using company ideas for personal gain).
Deviations in Quality of Service
Irregularities or outages in critical supporting utility services, such as power supply, water, ISP connections, or WAN services.
Espionage or Trespass
Unauthorized access to electronic systems or physical locations to gather confidential data or industrial secrets (e.g., shoulder surfing, entering restricted server rooms).
Forces of Nature
Uncontrollable physical hazards ("acts of God") such as fires, floods, earthquakes, lightning, tornados, and severe weather.
Human Error or Failure
Unintentional mistakes, negligence, improper training, accidental misconfigurations, or falling for social engineering tactics by employees.
Information Extortion
Cyber-blackmail attempts demanding payment or ransom in exchange for restoring system access or preventing the public disclosure of stolen data (e.g., ransomware).
Sabotage or Vandalism
Deliberate destruction, alteration, or defacement of physical equipment, websites, or systems to harm an organization's operations or reputation (e.g., hacktivist website defacement).
Software Attacks
Execution of malicious code or attack methods designed to disrupt or exploit systems (e.g., viruses, worms, Trojans, ransomware, backdoors, DoS/DDoS).
Technical Hardware Failures or Errors
Physical equipment breakdowns, manufacturing defects, or component failures in servers, network devices, or storage media.
Technical Software Failures or Errors
Coding flaws, bugs, unpatched application vulnerabilities, or unexpected software behaviors.
Technological Obsolescence
Outdated or legacy technologies, software, or hardware that no longer receive vendor support or security updates, leaving them exposed to exploits.
Theft
The illegal physical or digital confiscation or removal of equipment, media, paper records, or organizational data without authorization.
Human and Intentional Threats
Threats that are deliberate actions or human-driven behaviors carried out by internal or external threat agents that jeopardize an organization's information assets.
Compromises to Intellectual Property
Espionage or Trespass
Human Error or Failure
Information Extortion
Sabotage or Vandalism
Theft
Technical Threat, Technical Failures, and Obsolescence
These threats involve failures, flaws, or attacks related to hardware, software, and electronic systems.
Software Attacks
Technical Hardware Failures or Errors
Technical Software Failures or Errors
Technological Obsolescence
Environmental Threats
These threats stem from physical surroundings, nature, weather, and infrastructure external to the IT systems themselves.
Forces of Nature
Operational Threats
These threats arise from business operations, administrative processes, human actions, and everyday organizational activities.
Deviations in Quality of Service