1/83
Vocabulary flashcards covering Computer Security concepts, Philippine Cybercrime and Data Privacy laws, and Information Security Controls.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Computer security
The protection of computer systems and information from harm, theft, and unauthorized use.
Cyber security
The practice of defending computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks; also known as information technology security or electronic information security.
NETWORK SECURITY
The practice of securing a computer network from intruders, whether targeted attackers or opportunistic malware.
APPLICATION SECURITY
A category of cyber security that focuses on keeping software and devices free of threats by prioritizing security in the design stage.
INFORMATION SECURITY
The protection of the integrity and privacy of data, both in storage and in transit.
OPERATIONAL SECURITY
The category of cyber security that includes the processes and decisions for handling and protecting data assets, such as user permissions and storage procedures.
Disaster recovery
Policies that dictate how an organization restores its operations and information to return to the same operating capacity as before an incident.
Business continuity
The plan an organization falls back on while trying to operate without certain resources following a cyber-security incident.
End-user education
The practice of teaching people to follow good security practices, such as deleting suspicious email attachments, to prevent accidental system compromise.
CONFIDENTIALITY
A principle of the Information Security Triad ensuring that sensitive information is kept private and only accessible to authorized individuals needing it for their jobs.
INTEGRITY
A principle of the Information Security Triad that involves maintaining the accuracy, consistency, and trustworthiness of data from unauthorized modification.
AVAILABILITY
A principle of the Information Security Triad ensuring that information is readily accessible to authorized users in a timely and reliable manner when needed.
Firewall
A network security device that monitors incoming and outgoing network traffic and decides whether to allow or block specific traffic based on defined rules.
Hackers
Persons who break into a computer system for reasons such as stealing data, disrupting service, or finding ethical vulnerabilities.
Threats
Anything that can compromise the confidentiality, integrity, or availability of an information system.
Vulnerability
Any weakness in the Information Technology (IT) infrastructure that hackers can exploit to gain unauthorized access to data.
Cyberattack
An attempt by digital adversaries to access a network or system to alter, steal, destroy, or expose information.
MALWARE
Any program or code created with the intent to harm a computer, network, or server; previously referred to as a "computer virus."
DENIAL-OF-SERVICE (DoS) ATTACKS
A malicious attack launched from a single system that floods a network with simultaneous false requests to disrupt business operations.
DISTRIBUTED DENIAL-OF-SERVICE (DDoS)
A type of attack that launches its flood of false requests from multiple systems simultaneously.
SPOOFING
A technique where a cybercriminal disguises themselves as a known or trusted source, such as through a fake website.
PHISHING
A cyberattack using email, SMS, or social engineering to entice victims into sharing sensitive information or downloading malicious files.
SMiShing
A specific type of phishing that sends fraudulent SMS messages to trick individuals.
MAN-IN-THE-MIDDLE ATTACK
An identity-based attack where an adversary eavesdrops on the conversation between two targets.
MALVERTISING
A code injection attack that injects malicious code into a clickable element inside an online advertisement.
SOCIAL ENGINEERING ATTACKS
Techniques where attackers use psychological tactics to manipulate people into taking a desired action.
HONEYTRAP
A social engineering tactic where an attacker pretends to be a love interest on a dating website to defraud victims.
INSIDER THREATS
Internal actors, such as current or former employees, who pose a danger because they have direct access to sensitive resources.
DNS TUNNELING
An attack that leverages Domain Name System queries and responses to bypass security measures and transmit data within a network.
ADVANCED PERSISTENT THREATS (APTs)
Attacks where intruders remain undetected in a system for extended periods to spy on activity and steal data.
RANSOMWARE
Malware where an adversary encrypts a victim’s data and demands payment in exchange for a decryption key.
FILELESS MALWARE
A type of malware that does not install code on a target's system, making it very difficult to detect.
SPYWARE
Malicious software that collects information about a user’s web activity without their knowledge or consent.
ADWARE
A type of non-malicious spyware that watches online activity to determine which advertisements to show a user.
TROJAN
Malware that appears to be legitimate software or harmless files, such as free downloads.
WORMS
Self-contained programs that replicate themselves to spread across computers, potentially deleting files or exhausting system resources.
ROOTKITS
A collection of software designed to give malicious actors control of a computer network or application.
EXPLOITS
Data or software that uses a defect in an operating system to install malware or steal data.
SCAREWARE
Software that tricks users into believing their computer is infected to persuade them to install fake antivirus software.
KEYLOGGER
A tool that records everything a person types on an infected device and sends the data to an attacker.
BOTNET
A network of computers infected with malware and controlled by a bot herder to launch attacks.
MALSPAM
Malicious spam that delivers malware via email attachments.
WIPER ATTACK
A cyberattack designed to permanently delete or corrupt data on targeted systems.
I LOVE YOU Worm
A worm created in 2000 by Onel De Guzman that spread through email and caused millions of dollars in damages globally.
Republic Act 8792
The Philippine Electronic Commerce Act of 2000, which recognizes electronic transactions, documents, and signatures as legally valid.
Electronic Data Messages
Communication modes such as emails or SMS that hold the same legal validity as physical messages under R.A. 8792.
HACKING/CRACKING
Under R.A. 8792, unauthorized access to a system with intent to corrupt, alter, steal, or destroy data without the owner's consent.
Republic Act 10175
The Cybercrime Prevention Act of 2012, which defines and penalizes crimes committed with or through information and communication technologies.
ILLEGAL ACCESS
The act of accessing the whole or any part of a computer system without right or consent, including making use of its resources.
ILLEGAL INTERCEPTION
Listening to or monitoring communication through electronic eavesdropping or tapping devices while it occurs.
DATA INTERFERENCE
The intentional or reckless alteration, damaging, or deletion of computer data without right, including virus transmission.
SYSTEM INTERFERENCE
Intentional or reckless hindering of a computer network's functioning through unauthorized data transmission or deletion.
CRYPTOJACKING
Software or malware that takes over a computer's resources to mine cryptocurrency without the user's permission.
CYBERSQUATTING
The acquisition of a domain name in bad faith to profit, mislead, or deprive others from registering it.
Computer-related FORGERY
The input or alteration of computer data without right resulting in inauthentic data intended to be acted upon for legal purposes.
Computer-related FRAUD
The unauthorized alteration of computer data causing damage resulting in monetary loss.
Computer-related IDENTITY THEFT
The intentional acquisition or misuse of identifying information belonging to another person without right.
CYBERSEX
The willful engagement or control of lascivious exhibition of sexual activity with the aid of a computer system for favor or consideration.
ONLINE LIBEL
Defamation involving false statements in writing with intent to damage reputation, consisting of four elements: Allegation, Publication, Identification, and Malice.
UNJUST VEXATION
Under Article 287 of the Revised Penal Code, actions that cause annoyance or distress to another person without lawful justification.
Decisional privacy
A category of the right to privacy involving independence in making decisions of great importance.
Informational privacy
The right to not have private information disclosed and to live freely without surveillance.
Doctrine of Incorporation
The principle where the Philippines adopts generally accepted principles of international law, such as the right to privacy, as part of the law of the land.
Pacta sunt servanda
A principle in international law stating that "Agreements must be followed," obligating a country to comply with treaties they have signed.
ANTI-PHOTO AND VIDEO VOYEURISM ACT OF 2009
Republic Act 9995, which prohibits capturing, copying, or distributing images of a person's private area without consent where they have a reasonable expectation of privacy.
Republic Act 10173
The Data Privacy Act of 2012, which protects individual privacy while regulating the legal processing of personal data.
PERSONAL INFORMATION CONTROLLER (PIC)
The individual or corporation that decides what to do with collected personal data.
PERSONAL INFORMATION PROCESSOR (PIP)
One who processes personal data on behalf of a Personal Information Controller.
PERSONAL INFORMATION
Information about an individual that can be used to identify them, such as name, address, or phone number.
SENSITIVE PERSONAL INFORMATION
Information or opinions about an individual that may be used to harm or discriminate, such as medical records, criminal records, or ethnic origin.
PRINCIPLE OF TRANSPARENCY
The data privacy principle requiring that a subject knows what data is collected, why it is collected, and how it is collected in clear language.
LEGITIMATE PURPOSE PRINCIPLE
The requirement that data is collected only for specific and explicit purposes of the Personal Information Controller.
PRINCIPLE OF PROPORTIONALITY
The rule that the amount of data collected should be adequate, relevant, and not excessive in proportion to the processing purpose.
Right to RECTIFICATION
The right of a data subject to dispute inaccuracies in their data and have them corrected immediately.
Right to DATA PORTABILITY
The right to obtain a copy of data in a structured electronic format for further use by the data subject.
SAFE SPACES ACT OF 2018
Republic Act 11313, which defines and penalizes gender-based online sexual harassment.
Security controls
Safeguards used to avoid, detect, counteract, or minimize security risks to property, information, and assets.
Physical Controls
Tangible security features such as security guards, gates, access cards, and CCTVs.
Technical Controls
Computer technology used to protect IT infrastructure, such as firewalls, antivirus software, and encryption.
Administrative Controls
Policies, procedures, or guidelines practiced by employees, such as hiring policies and Internet usage rules.
Preventive Controls
Security measures designed to stop a breach from occurring, such as fences, alarms, or firewalls.
Detective Controls
Measures implemented to alert an organization while a security breach is in progress or after it has occurred.
Compensating Controls
Emergency security measures, like an emergency shutdown or a power generator, taken to minimize damages during an active breach.
Corrective Controls
Measures used to repair damage or restore capabilities following a breach, such as re-issuing access cards or patching a system.