1/35
This set of vocabulary flashcards covers Information Security fundamentals, including the CIA triad, attack classifications, security threats, and major international laws and regulations.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Information Security
The state of the well-being of information and infrastructure in which the possibility of theft, tampering, or disruption of information and services is kept low or tolerable.
Security Policy
A specification of how objects in a security domain are allowed to interact.
Confidentiality
The assurance that the information is accessible only to authorized people through controls like data classification and encryption.
Integrity
The trustworthiness of data or resources in the prevention of improper and unauthorized changes to ensure information is sufficiently accurate for its purpose.
Checksum
A number produced by a mathematical function to verify that a given block of data is not changed.
Availability
The assurance that the systems responsible for delivering, storing, and processing information are accessible when required by authorized users.
Authenticity
The characteristic of communication, documents, or any data that ensures the quality of being genuine or uncorrupted.
Non-repudiation
A guarantee that the sender of a message cannot later deny having sent it and the recipient cannot deny having received it, often ensured using digital signatures.
Functionality (Security Triangle)
The set of features provided by the system within the Security, Functionality, and Usability Triangle.
Usability (Security Triangle)
The GUI components used to design the system for ease of use within the Security, Functionality, and Usability Triangle.
Security (Security Triangle)
The restrictions imposed on accessing the components of the system within the Security, Functionality, and Usability Triangle.
Attacks Formula
Attacks=Motive(Goal)+Method+Vulnerability
Passive Attacks
The intercepting and monitoring of network traffic and data flow without tampering with the data, making them difficult to detect.
Reconnaissance
The initial phase where attackers gather information about a target system, network, or organization.
Footprinting
A reconnaissance technique used to gather information about a target computer system or network before attempting an attack.
Active Attacks
The tampering of data in transit or disrupting communication between systems to bypass or break into secured systems.
Close-in Attacks
Attacks performed when the attacker is in close physical proximity to the target system to gather or modify information.
Insider Attacks
Attacks performed by trusted persons who have physical access to critical assets and use privileged access to violate rules.
Pod slurping
An insider attack involving data theft using a portable storage device like a USB stick or a digital music player.
Distribution Attacks
Occur when attackers tamper with hardware or software at its source or in transit before installation.
Advanced Persistent Threats (APT)
An attack focusing on stealing information from a victim machine over a long period without the user being aware of it.
Virus
A self-replicating program that produces a copy of itself by attaching to another computer program, boot sector, or document.
Worm
A malicious program that replicates, executes, and spreads across network connections.
Ransomware
Malware that restricts access to a computer system's files and demands an online payment to remove the restrictions.
Botnet
A huge network of compromised systems used by attackers to perform tasks such as Denial-of-Service (DoS) attacks.
Phishing
The practice of sending an illegitimate email falsely claiming to be from a legitimate site to acquire personal or account information.
Payment Card Industry Data Security Standard (PCI DSS)
A proprietary information security standard for organizations that handle cardholder information for major debit, credit, and ATM cards.
ISO/IEC 27001:2013
Specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
HIPAA Privacy Rule
Provides federal protections for individually identifiable health information and gives patients rights to that information.
HIPAA Security Rule
Specifies administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of electronically protected health information.
National Provider Identifier (NPI)
A unique 10-digit, intelligence-free numeric identifier assigned to covered health care providers under HIPAA.
Sarbanes-Oxley (SOX) Act
Enacted in 2002 to protect public and investors by increasing the accuracy and reliability of corporate disclosures.
Digital Millennium Copyright Act (DMCA)
An American copyright law that implements WIPO treaties and prohibits circumvention of technological protection measures used by copyright owners.
Federal Information Security Management Act (FISMA)
Provides a comprehensive framework for ensuring the effectiveness of information security controls over resources supporting federal operations.
General Data Protection Regulation (GDPR)
A stringent European Union law that imposes obligations on organizations globally if they target or collect data related to people in the EU.
Data Protection Act 2018 (DPA)
The framework for data protection law in the UK that updates and replaces the Data Protection Act 1998.