Information Security Fundamentals Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/35

flashcard set

Earn XP

Description and Tags

This set of vocabulary flashcards covers Information Security fundamentals, including the CIA triad, attack classifications, security threats, and major international laws and regulations.

Last updated 1:02 PM on 8/12/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

36 Terms

1
New cards

Information Security

The state of the well-being of information and infrastructure in which the possibility of theft, tampering, or disruption of information and services is kept low or tolerable.

2
New cards

Security Policy

A specification of how objects in a security domain are allowed to interact.

3
New cards

Confidentiality

The assurance that the information is accessible only to authorized people through controls like data classification and encryption.

4
New cards

Integrity

The trustworthiness of data or resources in the prevention of improper and unauthorized changes to ensure information is sufficiently accurate for its purpose.

5
New cards

Checksum

A number produced by a mathematical function to verify that a given block of data is not changed.

6
New cards

Availability

The assurance that the systems responsible for delivering, storing, and processing information are accessible when required by authorized users.

7
New cards

Authenticity

The characteristic of communication, documents, or any data that ensures the quality of being genuine or uncorrupted.

8
New cards

Non-repudiation

A guarantee that the sender of a message cannot later deny having sent it and the recipient cannot deny having received it, often ensured using digital signatures.

9
New cards

Functionality (Security Triangle)

The set of features provided by the system within the Security, Functionality, and Usability Triangle.

10
New cards

Usability (Security Triangle)

The GUI components used to design the system for ease of use within the Security, Functionality, and Usability Triangle.

11
New cards

Security (Security Triangle)

The restrictions imposed on accessing the components of the system within the Security, Functionality, and Usability Triangle.

12
New cards

Attacks Formula

Attacks=Motive(Goal)+Method+VulnerabilityAttacks = Motive (Goal) + Method + Vulnerability

13
New cards

Passive Attacks

The intercepting and monitoring of network traffic and data flow without tampering with the data, making them difficult to detect.

14
New cards

Reconnaissance

The initial phase where attackers gather information about a target system, network, or organization.

15
New cards

Footprinting

A reconnaissance technique used to gather information about a target computer system or network before attempting an attack.

16
New cards

Active Attacks

The tampering of data in transit or disrupting communication between systems to bypass or break into secured systems.

17
New cards

Close-in Attacks

Attacks performed when the attacker is in close physical proximity to the target system to gather or modify information.

18
New cards

Insider Attacks

Attacks performed by trusted persons who have physical access to critical assets and use privileged access to violate rules.

19
New cards

Pod slurping

An insider attack involving data theft using a portable storage device like a USB stick or a digital music player.

20
New cards

Distribution Attacks

Occur when attackers tamper with hardware or software at its source or in transit before installation.

21
New cards

Advanced Persistent Threats (APT)

An attack focusing on stealing information from a victim machine over a long period without the user being aware of it.

22
New cards

Virus

A self-replicating program that produces a copy of itself by attaching to another computer program, boot sector, or document.

23
New cards

Worm

A malicious program that replicates, executes, and spreads across network connections.

24
New cards

Ransomware

Malware that restricts access to a computer system's files and demands an online payment to remove the restrictions.

25
New cards

Botnet

A huge network of compromised systems used by attackers to perform tasks such as Denial-of-Service (DoS) attacks.

26
New cards

Phishing

The practice of sending an illegitimate email falsely claiming to be from a legitimate site to acquire personal or account information.

27
New cards

Payment Card Industry Data Security Standard (PCI DSS)

A proprietary information security standard for organizations that handle cardholder information for major debit, credit, and ATM cards.

28
New cards

ISO/IEC 27001:2013

Specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

29
New cards

HIPAA Privacy Rule

Provides federal protections for individually identifiable health information and gives patients rights to that information.

30
New cards

HIPAA Security Rule

Specifies administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of electronically protected health information.

31
New cards

National Provider Identifier (NPI)

A unique 10-digit, intelligence-free numeric identifier assigned to covered health care providers under HIPAA.

32
New cards

Sarbanes-Oxley (SOX) Act

Enacted in 2002 to protect public and investors by increasing the accuracy and reliability of corporate disclosures.

33
New cards

Digital Millennium Copyright Act (DMCA)

An American copyright law that implements WIPO treaties and prohibits circumvention of technological protection measures used by copyright owners.

34
New cards

Federal Information Security Management Act (FISMA)

Provides a comprehensive framework for ensuring the effectiveness of information security controls over resources supporting federal operations.

35
New cards

General Data Protection Regulation (GDPR)

A stringent European Union law that imposes obligations on organizations globally if they target or collect data related to people in the EU.

36
New cards

Data Protection Act 2018 (DPA)

The framework for data protection law in the UK that updates and replaces the Data Protection Act 1998.