Computer and Cybersecurity, Cybercrime Law, and Security Controls

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/83

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering Computer Security concepts, Philippine Cybercrime and Data Privacy laws, and Information Security Controls.

Last updated 11:43 PM on 5/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

84 Terms

1
New cards

Computer security

The protection of computer systems and information from harm, theft, and unauthorized use.

2
New cards

Cyber security

The practice of defending computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks; also known as information technology security or electronic information security.

3
New cards

NETWORK SECURITY

The practice of securing a computer network from intruders, whether targeted attackers or opportunistic malware.

4
New cards

APPLICATION SECURITY

A category of cyber security that focuses on keeping software and devices free of threats by prioritizing security in the design stage.

5
New cards

INFORMATION SECURITY

The protection of the integrity and privacy of data, both in storage and in transit.

6
New cards

OPERATIONAL SECURITY

The category of cyber security that includes the processes and decisions for handling and protecting data assets, such as user permissions and storage procedures.

7
New cards

Disaster recovery

Policies that dictate how an organization restores its operations and information to return to the same operating capacity as before an incident.

8
New cards

Business continuity

The plan an organization falls back on while trying to operate without certain resources following a cyber-security incident.

9
New cards

End-user education

The practice of teaching people to follow good security practices, such as deleting suspicious email attachments, to prevent accidental system compromise.

10
New cards

CONFIDENTIALITY

A principle of the Information Security Triad ensuring that sensitive information is kept private and only accessible to authorized individuals needing it for their jobs.

11
New cards

INTEGRITY

A principle of the Information Security Triad that involves maintaining the accuracy, consistency, and trustworthiness of data from unauthorized modification.

12
New cards

AVAILABILITY

A principle of the Information Security Triad ensuring that information is readily accessible to authorized users in a timely and reliable manner when needed.

13
New cards

Firewall

A network security device that monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on defined rules.

14
New cards

Hackers

Persons who break into a computer system for reasons such as stealing data, disrupting service, or finding ethical vulnerabilities.

15
New cards

Threats

Anything that can compromise the confidentiality, integrity, or availability of an information system.

16
New cards

Vulnerability

Any weakness in the Information Technology (IT) infrastructure that hackers can exploit to gain unauthorized access to data.

17
New cards

Cyberattack

An attempt by digital adversaries to access a network or system to alter, steal, destroy, or expose information.

18
New cards

MALWARE

Any program or code created with the intent to harm a computer, network, or server; previously referred to as a "computer virus."

19
New cards

DENIAL-OF-SERVICE (DoS) ATTACKS

A malicious attack launched from a single system that floods a network with simultaneous false requests to disrupt business operations.

20
New cards

DISTRIBUTED DENIAL-OF-SERVICE (DDoS)

A type of attack that launches its flood of false requests from multiple systems simultaneously.

21
New cards

SPOOFING

A technique where a cybercriminal disguises themselves as a known or trusted source, such as through a fake website.

22
New cards

PHISHING

A cyberattack using email, SMS, or social engineering to entice victims into sharing sensitive information or downloading malicious files.

23
New cards

SMiShing

A specific type of phishing that sends fraudulent SMS messages to trick individuals.

24
New cards

MAN-IN-THE-MIDDLE ATTACK

An identity-based attack where an adversary eavesdrops on the conversation between two targets.

25
New cards

MALVERTISING

A code injection attack that injects malicious code into a clickable element inside an online advertisement.

26
New cards

SOCIAL ENGINEERING ATTACKS

Techniques where attackers use psychological tactics to manipulate people into taking a desired action.

27
New cards

HONEYTRAP

A social engineering tactic where an attacker pretends to be a love interest on a dating website to defraud victims.

28
New cards

INSIDER THREATS

Internal actors, such as current or former employees, who pose a danger because they have direct access to sensitive resources.

29
New cards

DNS TUNNELING

An attack that leverages Domain Name System queries and responses to bypass security measures and transmit data within a network.

30
New cards

ADVANCED PERSISTENT THREATS (APTs)

Attacks where intruders remain undetected in a system for extended periods to spy on activity and steal data.

31
New cards

RANSOMWARE

Malware where an adversary encrypts a victim’s data and demands payment in exchange for a decryption key.

32
New cards

FILELESS MALWARE

A type of malware that does not install code on a target's system, making it very difficult to detect.

33
New cards

SPYWARE

Malicious software that collects information about a user’s web activity without their knowledge or consent.

34
New cards

ADWARE

A type of non-malicious spyware that watches online activity to determine which advertisements to show a user.

35
New cards

TROJAN

Malware that appears to be legitimate software or harmless files, such as free downloads.

36
New cards

WORMS

Self-contained programs that replicate themselves to spread across computers, potentially deleting files or exhausting system resources.

37
New cards

ROOTKITS

A collection of software designed to give malicious actors control of a computer network or application.

38
New cards

EXPLOITS

Data or software that uses a defect in an operating system to install malware or steal data.

39
New cards

SCAREWARE

Software that tricks users into believing their computer is infected to persuade them to install fake antivirus software.

40
New cards

KEYLOGGER

A tool that records everything a person types on an infected device and sends the data to an attacker.

41
New cards

BOTNET

A network of computers infected with malware and controlled by a bot herder to launch attacks.

42
New cards

MALSPAM

Malicious spam that delivers malware via email attachments.

43
New cards

WIPER ATTACK

A cyberattack designed to permanently delete or corrupt data on targeted systems.

44
New cards

I LOVE YOU Worm

A worm created in 20002000 by Onel De Guzman that spread through email and caused millions of dollars in damages globally.

45
New cards

Republic Act 8792

The Philippine Electronic Commerce Act of 20002000, which recognizes electronic transactions, documents, and signatures as legally valid.

46
New cards

Electronic Data Messages

Communication modes such as emails or SMS that hold the same legal validity as physical messages under R.A. 87928792.

47
New cards

HACKING/CRACKING

Under R.A. 87928792, unauthorized access to a system with intent to corrupt, alter, steal, or destroy data without the owner's consent.

48
New cards

Republic Act 10175

The Cybercrime Prevention Act of 20122012, which defines and penalizes crimes committed with or through information and communication technologies.

49
New cards

ILLEGAL ACCESS

The act of accessing the whole or any part of a computer system without right or consent, including making use of its resources.

50
New cards

ILLEGAL INTERCEPTION

Listening to or monitoring communication through electronic eavesdropping or tapping devices while it occurs.

51
New cards

DATA INTERFERENCE

The intentional or reckless alteration, damaging, or deletion of computer data without right, including virus transmission.

52
New cards

SYSTEM INTERFERENCE

Intentional or reckless hindering of a computer network's functioning through unauthorized data transmission or deletion.

53
New cards

CRYPTOJACKING

Software or malware that takes over a computer's resources to mine cryptocurrency without the user's permission.

54
New cards

CYBERSQUATTING

The acquisition of a domain name in bad faith to profit, mislead, or deprive others from registering it.

55
New cards

Computer-related FORGERY

The input or alteration of computer data without right resulting in inauthentic data intended to be acted upon for legal purposes.

56
New cards

Computer-related FRAUD

The unauthorized alteration of computer data causing damage resulting in monetary loss.

57
New cards

Computer-related IDENTITY THEFT

The intentional acquisition or misuse of identifying information belonging to another person without right.

58
New cards

CYBERSEX

The willful engagement or control of lascivious exhibition of sexual activity with the aid of a computer system for favor or consideration.

59
New cards

ONLINE LIBEL

Defamation involving false statements in writing with intent to damage reputation, consisting of four elements: Allegation, Publication, Identification, and Malice.

60
New cards

UNJUST VEXATION

Under Article 287287 of the Revised Penal Code, actions that cause annoyance or distress to another person without lawful justification.

61
New cards

Decisional privacy

A category of the right to privacy involving independence in making decisions of great importance.

62
New cards

Informational privacy

The right to not have private information disclosed and to live freely without surveillance.

63
New cards

Doctrine of Incorporation

The principle where the Philippines adopts generally accepted principles of international law, such as the right to privacy, as part of the law of the land.

64
New cards

Pacta sunt servanda

A principle in international law stating that "Agreements must be followed," obligating a country to comply with treaties they have signed.

65
New cards

ANTI-PHOTO AND VIDEO VOYEURISM ACT OF 2009

Republic Act 99959995, which prohibits capturing, copying, or distributing images of a person's private area without consent where they have a reasonable expectation of privacy.

66
New cards

Republic Act 10173

The Data Privacy Act of 20122012, which protects individual privacy while regulating the legal processing of personal data.

67
New cards

PERSONAL INFORMATION CONTROLLER (PIC)

The individual or corporation that decides what to do with collected personal data.

68
New cards

PERSONAL INFORMATION PROCESSOR (PIP)

One who processes personal data on behalf of a Personal Information Controller.

69
New cards

PERSONAL INFORMATION

Information about an individual that can be used to identify them, such as name, address, or phone number.

70
New cards

SENSITIVE PERSONAL INFORMATION

Information or opinions about an individual that may be used to harm or discriminate, such as medical records, criminal records, or ethnic origin.

71
New cards

PRINCIPLE OF TRANSPARENCY

The data privacy principle requiring that a subject knows what data is collected, why it is collected, and how it is collected in clear language.

72
New cards

LEGITIMATE PURPOSE PRINCIPLE

The requirement that data is collected only for specific and explicit purposes of the Personal Information Controller.

73
New cards

PRINCIPLE OF PROPORTIONALITY

The rule that the amount of data collected should be adequate, relevant, and not excessive in proportion to the processing purpose.

74
New cards

Right to RECTIFICATION

The right of a data subject to dispute inaccuracies in their data and have them corrected immediately.

75
New cards

Right to DATA PORTABILITY

The right to obtain a copy of data in a structured electronic format for further use by the data subject.

76
New cards

SAFE SPACES ACT OF 2018

Republic Act 1131311313, which defines and penalizes gender-based online sexual harassment.

77
New cards

Security controls

Safeguards used to avoid, detect, counteract, or minimize security risks to property, information, and assets.

78
New cards

Physical Controls

Tangible security features such as security guards, gates, access cards, and CCTVs.

79
New cards

Technical Controls

Computer technology used to protect IT infrastructure, such as firewalls, antivirus software, and encryption.

80
New cards

Administrative Controls

Policies, procedures, or guidelines practiced by employees, such as hiring policies and Internet usage rules.

81
New cards

Preventive Controls

Security measures designed to stop a breach from occurring, such as fences, alarms, or firewalls.

82
New cards

Detective Controls

Measures implemented to alert an organization while a security breach is in progress or after it has occurred.

83
New cards

Compensating Controls

Emergency security measures, like an emergency shutdown or a power generator, taken to minimize damages during an active breach.

84
New cards

Corrective Controls

Measures used to repair damage or restore capabilities following a breach, such as re-issuing access cards or patching a system.