ITAN Ch. 2 Vocab

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/30

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:04 PM on 8/31/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

31 Terms

1
New cards

Bring your own device (BYOD)

A business policy that permits, and in some cases encourages, employees to use their own mobile devices (smartphones, tablets, or laptops) to access company computing resources and applications.

2
New cards

exploit

An attack on an information system that takes advantage of a particular system vulnerability.

3
New cards

zero-day attack

An attack that takes place before the security community becomes aware of and fixes a security vulnerability.

4
New cards

attack vector

The technique used to gain unauthorized access to a device or a network.

5
New cards

Ransomware

Malware that stops you from using your computer or accessing your data until you meet certain demands.

6
New cards

distributed denial-of-service (DDoS) attack

A cyberattack in which a malicious hacker takes over computers via the Internet and causes them to flood a target site with demands for data and other small tasks.

7
New cards

data breach

The unintended release of sensitive data or the access of sensitive data by unauthorized individuals.

8
New cards

Cyberespionage

The deployment of malware that secretly steals data in the computer systems of organizations.

9
New cards

Cyberterrorism

The intimidation of government or civilian population by using information technology to disable critical national infrastructure (e.g., energy, transportation, financial, law enforcement, emergency response) to achieve political, religious, or ideological goals.

10
New cards

Department of Homeland Security (DHS)

A large federal agency with more than 240,000 employees and a budget of almost $65 billion whose goal is to provide for a “safer, more secure America, which is resilient against terrorism and other potential threats.”

11
New cards

U.S. Computer Emergency Readiness Team (US-CERT)

A partnership between the Department of Homeland Security and the public and private sectors; established to provide timely handling of security incidents as well as conducting improved analysis of such incidents.

12
New cards

CIA security triad

Confidentiality, integrity, and availability form the basis of the CIA security triad.

13
New cards

Risk assessment

The process of assessing security-related risks to an organization’s computers and networks from both internal and external threats.

14
New cards

reasonable assurance

The recognition that managers must use their judgment to ensure that the cost of control does not exceed the system’s benefits or the risks involved.

15
New cards

disaster recovery plan

A documented process for recovering an organization’s business information system assets—including hardware, software, data, networks, and facilities—in the event of a disaster such as a flood, fire, or electrical outage.

16
New cards

business continuity plan

A document that includes an organization’s disaster recovery plan, occupant emergency evacuation plan, continuity of operations plan, and an incident management plan.

17
New cards

mission-critical processes

A process that plays a pivotal role in an organization’s continued operations and goal attainment.

18
New cards

Failover

A backup technique that involves automatically switching applications and programs to a redundant or replicated server, network, or database to prevent interruption of service.

19
New cards

security policy

Defines an organization’s security requirements, as well as the controls and sanctions needed to meet those requirements.

20
New cards

security audit

A process that enables the organization to identify its potential threats, establish a benchmark of where it is, determine where it needs to be, and develop a plan to meet those needs.

21
New cards

Biometric authentication

The process of verifying your identity using your physiological measurements (fingerprint, shape of your face, shape of your hand, vein pattern, your iris, or retina) or behavioral measurements (voice recognition, gait, gesture, or other unique behaviors).

22
New cards

firewall

A system of software, hardware, or a combination of both that stands guard between an organization’s internal network and the Internet, and limits network access based on the organization’s access policy.

23
New cards

next-generation firewall (NGFW)

A hardware- or software-based network security system that can detect and block sophisticated attacks by filtering network traffic dependent on the packet contents.

24
New cards

Encryption

The process of scrambling messages or data in such a way that only authorized parties can read it.

25
New cards

encryption key

A value that is applied (using an algorithm) to a set of unencrypted text (plaintext) to produce encrypted text that appears as a series of seemingly random characters (ciphertext) that is unreadable by those without the encryption key needed to decipher it.

26
New cards

Transport Layer Security (TLS)

A communications protocol or system of rules that ensures privacy between communicating applications and their users on the Internet.

27
New cards

Antivirus software

Should be installed on each user’s personal computer to scan a computer’s memory and disk drives regularly for viruses.

28
New cards

virus signature

Code that indicates the presence of a specific virus.

29
New cards

intrusion detection system (IDS)

Software and/or hardware that monitors system and network resources and activities and notifies network security personnel when it detects network traffic that attempts to circumvent the security measures of a networked computer environment.

30
New cards

managed security service provider (MSSP)

A company that monitors, manages, and maintains computer and network security for other organizations.

31
New cards

Computer forensics

A discipline that combines elements of law and computer science to identify, collect, examine, and preserve data from computer systems, networks, and storage devices in a manner that preserves the integrity of the data gathered so that it is admissible as evidence in a court of law.