1/19
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What are the three core principles of information system security known as the CIA triad?
Confidentiality, Integrity, and Availability.
What does the term 'risk' refer to in information security?
The likelihood that something bad will happen to an asset.
What is a threat in the context of information system security?
Any action that could damage an asset.
What is a vulnerability?
A weakness that allows a threat to be a risk.
Define 'information system'.
A combination of hardware, operating systems, and application software that work together to collect data.
What are the seven domains of an IT infrastructure?
User domain, workstation domain, LAN domain, LAN-to-WAN domain, WAN domain, Remote access domain, System/Application domain.
Why is the user considered the weakest link in the security of an IT infrastructure?
Because users can inadvertently create vulnerabilities through actions like sharing passwords or failing to follow security protocols.
What are the components of an IT security policy framework?
Policies, standards, procedures, and guidelines that aim to reduce risks and threats.
What is the End-User License Agreement (EULA)?
A license agreement between a user and a software vendor that outlines usage rights and liabilities.
What does the term 'availability' refer to in information security?
The amount of time users can access a system, application, and data.
What is meant by data classification standards?
The categorization of data based on its importance and sensitivity to determine the appropriate level of protection.
What is the role of cryptography in information security?
To ensure confidentiality by protecting sensitive information through encryption.
What are the current laws related to information security?
FISMA, SOX, GLBA, HIPAA, CIPA, and FERPA.
What does maintaining integrity in an information system mean?
Ensuring that the information is valid, uncorrupted, and accurate.
What is meant by 'hardening' in the workstation domain?
The process of securing a system by reducing its surface of vulnerability.
What is the purpose of vulnerability policies in an IT security framework?
To establish guidelines for identifying, managing, and mitigating vulnerabilities.
Define the term 'data breach'.
An incident where unauthorized access to sensitive data occurs.
What could lead to unauthorized access in information systems?
Obtaining authorized logon ID and password without permission.
What does uptime measure in relation to availability?
The total time a system is operational and accessible to users.
What types of data are typically found within an IT infrastructure?
Privacy data, corporate intellectual property, and governmental intellectual property.