Cyber security

0.0(0)
Studied by 1 person
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/37

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:35 AM on 8/24/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

38 Terms

1
New cards

Goals

Big, long term targets to be achieved. Hard to measure if or when they have been achieved.

2
New cards

Objectives

Specific, measurable steps towards achieving a larger goal. Can be proved using data.

3
New cards

APIs

APIs create vulnerabilities by exposing endpoints that can be exploited. Insufficient authentication and authorisation, lack of input validation and improper error handling. Leads to data breaches and unauthorised access.

4
New cards

Malware

Suspicious code that enters computer without user knowledge to cause harm. Deliberate threat

5
New cards

Unpatched software

Leaves known security flaws unaddressed which can be exploited. Can lead to unauthorised access, data breaches, compromising the security and integrity of the entire system.

6
New cards

Poor identity and access management practices

Allows unauthorised access to sensitive data. Including: inadequate password policies, lack of multi-factor authentication and insufficient monitoring of access logs.

7
New cards

Man in the middle attacks

an eaves dropping attack where unauthorised third party intercepts WIFI transmissions. To mitigate: use strong encryption, server certificate verification, use of secure networks, multi-factor authentication, ensure up-to-date software and systems.

8
New cards

Insider threats

an attack from someone who the business trusts, former employees, partners etc: causing data breach, fraud, theft of intellectual property and sabotage.

9
New cards

Cyber security incidents

Social engineering, DDoS, Bots

10
New cards

Software acquired by a third party

the user is reliant on the developer to notify about patch fixes and improvements

11
New cards

Ineffective code review practices

lead to deployment of insecure software, resulting in data breaches, system outages and compromised user data.

12
New cards

Combined development environments

allows potentially untested code to enter production environments. Separates people who should not be touching production data.

13
New cards

Types of vulnerabilities and risks

Use of APIs, Malware, Unpatched software, Poor access management, Man-in-the-middle attacks, insider threats, cyber security incidents, using third party software, ineffective code review practices, combined development environments.

14
New cards

Version control and code repositories

Can record each stage of the development so that is is possible to ‘roll back’ to any previous point in development.

15
New cards

Robust identity management

clearly documenting and training employees in cyber security. Only authorised individuals have access to resources and system.

16
New cards

Encryption

recognises that data will be exposed so data should be encrypted so attackers cannot read the data.

17
New cards

Code review

examining code to identify and eliminate vulnerabilities before deployment.

18
New cards

Regular updates and patches

Can fix potential vulnerabilities in the software

19
New cards

Seperate Environments

prevent untested or insecure code from the live environment. Enforces stricter access controls.

20
New cards

Software development practices

Version control and code repositories, identity and access management, encryption, code review, regular updates and patches and separated environments.

21
New cards

Accidental threats

accidental deletion or overwriting of data cause by user inattention or carelessness. Confusing screen design with lookalike interface.

22
New cards

Event based threats

natural disasters, power or network outages, hardware failures and data corruption

23
New cards

Deliberate threats

insider threats, unauthorised access, theft of data, malware and DDoS

24
New cards

Copyright Act 1968

Any person wishing to use another person’s work must obtain permission or pay for a license. Covers websites and software. If broken will lead to fines and imprisonment. (Federal)

25
New cards

Privacy Act 1988

Govern how organisations collect, use and share personal information. Applies to government organisations, organisations that are contracted with the government, organisations with a turnover of > $3 million, if they store medical info and if they sell or distribute personal info. (Federal)

26
New cards

Privacy and Data Protection Act 2014

Protects information held by Victorian government Agencies, including contractors working for government. (State)

27
New cards

Essential Eight

It is an industry standard framework design to assist businesses to become cyber secure and resistant. Application whitelisting, patch applications, configure Microsoft office macro settings, user application hardening, restrict admin privileges, patch operating system, multi-factor authentication and daily backups

28
New cards

Cyber security principles

Segregated areas for development, protection of software source, secure by design, use of memory safe languages, vulnerability disclosure, providing patches.

29
New cards

Ethics

Issues that arise that challenge moral standards, principles or expectations and tha can impact individuals and/or expectations.

30
New cards

Ineffective security practices

exposes users to risks such as data breaches and identity theft

31
New cards

Use of artificial intelligence

AI could contain biases present from training data that may lead to the system to produce inaccurate results based on stereotypes.

32
New cards

Intellectual Property

can limit access to ideas and technologies which can slow down creativity and progress. Can stop developers from working together creating monopolies

33
New cards

Copy right issues

Can restrict access to educational materials raising concerns about fair use. Creators rights vs public access to information

34
New cards

Strategies to improve security

Onboarding and induction programs to teach now employees and developer training

35
New cards

Advantages of developing externally

Up to date security tools, continuous security, responsibility and compliance with regulations.

36
New cards

Disadvantages of developing software externally

increased development costs, limited control over development, dependence on external for issues, data security and privacy risks.

37
New cards

Risk management plans

plans to identify, assess and mitigate risks to software development and operations, ensuring continuity and security.

38
New cards

Development of risk management plans

Identifying and evaluating risks, developing and implementing mitigation strategies, Preparing detailed incident response plans and Regularly monitoring and reviewing the risk management plan