Chapter 1 IA Concepts

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 11:41 PM on 9/8/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards

What are the three core principles of information system security known as the CIA triad?

Confidentiality, Integrity, and Availability.

2
New cards

What does the term 'risk' refer to in information security?

The likelihood that something bad will happen to an asset.

3
New cards

What is a threat in the context of information system security?

Any action that could damage an asset.

4
New cards

What is a vulnerability?

A weakness that allows a threat to be a risk.

5
New cards

Define 'information system'.

A combination of hardware, operating systems, and application software that work together to collect data.

6
New cards

What are the seven domains of an IT infrastructure?

User domain, workstation domain, LAN domain, LAN-to-WAN domain, WAN domain, Remote access domain, System/Application domain.

7
New cards

Why is the user considered the weakest link in the security of an IT infrastructure?

Because users can inadvertently create vulnerabilities through actions like sharing passwords or failing to follow security protocols.

8
New cards

What are the components of an IT security policy framework?

Policies, standards, procedures, and guidelines that aim to reduce risks and threats.

9
New cards

What is the End-User License Agreement (EULA)?

A license agreement between a user and a software vendor that outlines usage rights and liabilities.

10
New cards

What does the term 'availability' refer to in information security?

The amount of time users can access a system, application, and data.

11
New cards

What is meant by data classification standards?

The categorization of data based on its importance and sensitivity to determine the appropriate level of protection.

12
New cards

What is the role of cryptography in information security?

To ensure confidentiality by protecting sensitive information through encryption.

13
New cards

What are the current laws related to information security?

FISMA, SOX, GLBA, HIPAA, CIPA, and FERPA.

14
New cards

What does maintaining integrity in an information system mean?

Ensuring that the information is valid, uncorrupted, and accurate.

15
New cards

What is meant by 'hardening' in the workstation domain?

The process of securing a system by reducing its surface of vulnerability.

16
New cards

What is the purpose of vulnerability policies in an IT security framework?

To establish guidelines for identifying, managing, and mitigating vulnerabilities.

17
New cards

Define the term 'data breach'.

An incident where unauthorized access to sensitive data occurs.

18
New cards

What could lead to unauthorized access in information systems?

Obtaining authorized logon ID and password without permission.

19
New cards

What does uptime measure in relation to availability?

The total time a system is operational and accessible to users.

20
New cards

What types of data are typically found within an IT infrastructure?

Privacy data, corporate intellectual property, and governmental intellectual property.