CyberSecurity Fundamentals and Program Management Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/99

flashcard set

Earn XP

Description and Tags

A comprehensive vocabulary set of 100 flashcards reviewing cybersecurity fundamentals, control types, data management, supply chain risks, governance, frameworks, risk quantitative metrics, and emerging AI security concepts based on lecture notes.

Last updated 3:06 PM on 9/22/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

100 Terms

1
New cards

Primary Strategic Objectives (CyberSecurity)

The four key business objectives achieved by cybersecurity: protecting information assets, individual privacy, legal position, and public image.

2
New cards

Confidentiality

Ensures that only authorized individuals are allowed access to sensitive information with legitimate purposes.

3
New cards

Integrity

Ensures that only authorized modifications are made to information or systems.

4
New cards

Availability

Ensures that information and systems are ready to meet the needs of legitimate users at the time those users request them.

5
New cards

C-I-A Triad

The core security goals consisting of Confidentiality, Integrity, and Availability.

6
New cards

D-A-D

The three breaches of cybersecurity: Disclosure (confidentiality), Alteration (integrity), and Destruction (availability).

7
New cards

Disclosure

The exposure of sensitive information to unauthorized individuals (data loss), representing a violation of confidentiality.

8
New cards

Alteration

The unauthorized modification of information, representing a violation of integrity.

9
New cards

Destruction

The disruption of an authorized user's legitimate access to information, representing a violation of availability.

10
New cards

Managerial Controls

Security controls that give oversight of the system.

11
New cards

Operational Controls

Security controls that depend on a person for implementation.

12
New cards

Technical Controls

Security controls implemented in information technology, such as operating systems, software, and security appliances.

13
New cards

Preventive Control

A security control that stops crime in the first place by physically or logically restricting unauthorized access before an attack occurs.

14
New cards

Detective Control

A security control operating during an attack that identifies and records any attempted or successful intrusion.

15
New cards

Corrective and Recovery Control

A security control operating after an attack that responds to and fixes an incident and may also prevent its reoccurrence.

16
New cards

Deterrent Control

A security control operating before an attack that attempts to discourage individuals from committing a security breach.

17
New cards

Physical Control

A security control usually considered an operational control by NIST and CompTIA that operates during physical events.

18
New cards

Compensating Control

Alternative controls used when a primary prescribed control is not feasible.

19
New cards

OECD Principles of Privacy

Core privacy principles: Collection Limitation, Data Quality, Purpose Specification, Use Limitation, Security Safeguards, Openness, Individual Participation, and Accountability.

20
New cards

Personally Identifiable Information (PII)

Personal information that can be used to personally identify an individual, usually comprising two or more pieces of personal data.

21
New cards

Electronic Health Records (EHR)

Digital patient health records categorized under healthcare PII.

22
New cards

Protected Health Information (PHI)

Healthcare-specific PII subject to specialized health privacy regulations.

23
New cards

Data at Rest

Data stored in persistent storage media, protected using encryption and access control lists.

24
New cards

Data in Transit

Data transmitted over a network, protected using transport encryption such as TLS or IPSec.

25
New cards

Data in Use

Data present in volatile memory, such as system RAM or CPU registers and cache.

26
New cards

Data Exfiltration

Deliberately moving sensitive data from inside an organization to outside an organization's perimeter without permission.

27
New cards

Steganography

A method of hiding data within other data to conceal information during transfer.

28
New cards

Data Loss Prevention (DLP)

Safeguards comprising hardware and software elements designed to prevent sensitive data from falling into unauthorized hands.

29
New cards

De-identification

The process of removing personal information from shared datasets.

30
New cards

Anonymization

The process of modifying data to remove or obscure PII, making it impossible to identify individuals from a dataset.

31
New cards

Tokenization

A database deidentification method that replaces field values with random tokens linked to a separate vault source.

32
New cards

Data Masking

Whole or partial redaction of strings using format-preserving masks, which is irreversible.

33
New cards

Content Aware DLP Technologies

Inspection technologies used to classify information content across Network, Host/Endpoint, Cloud-based, and Discovery states.

34
New cards

Media Handling Controls

Physical and logical safeguards including marking, handling, storing, declassifying, and disposing of media containing sensitive data.

35
New cards

Pulping

A paper disposal method that recycles paper into pulp.

36
New cards

Platter Destruction

The most secure hard drive disposal method involving physical shredding or pulverizing of drive platters.

37
New cards

Degaussing

A demagnetizing technique that renders magnetic media unusable, but does not work on SSD or flash storage.

38
New cards

Secure Erasing

A sanitization technique that wipes an entire drive (effective for SSDs) while keeping the drive reusable.

39
New cards

Wiping / Erasure

A disposal technique of rewriting storage positions with binary 1's and 0's to sanitize reusable media.

40
New cards

NIST SP800-88

NIST publication titled Guidelines for Media Sanitization.

41
New cards

Governance

Board of Directors function that evaluates stakeholder needs, directs prioritization, and monitors performance against objectives.

42
New cards

Management

Executive Management function (e.g., CEO, COO) that plans, builds, runs, and monitors operational activities.

43
New cards

COBIT 5

A framework separating enterprise Governance (Evaluate, Direct, Monitor) from Management (Plan, Build, Run, Monitor).

44
New cards

Governance, Risk, and Compliance (GRC)

An integrated enterprise approach combining executive oversight mechanisms, risk tolerance setting, and regulatory compliance monitoring.

45
New cards

Risk Management

Process by which an organization sets risk appetite, identifies potential risks and impacts, and prioritizes mitigation based on business objectives.

46
New cards

Compliance

Process that records and monitors controls needed to ensure that policies, standards, procedures, and legal requirements are adhered to.

47
New cards

Executive Management Role

Role holding ultimate responsibility for information security, forming steering oversight committees, and assigning ownership.

48
New cards

Information Security Officer

Role responsible for protecting enterprise information assets and facilitating the overall information security program.

49
New cards

Data Owner

Role bearing primary responsibility for determining data classification levels, assigning safeguards, and maintaining data accuracy/integrity.

50
New cards

Custodians (Technology Providers)

Role responsible for assisting with information security implementation and providing secure IT infrastructure for applications.

51
New cards

IT Auditors

Independent evaluators assessing the appropriateness and adequacy of security controls based on compliance and risk.

52
New cards

RACI Matrix

Responsibility Assignment Matrix specifying roles as Responsible, Accountable, Consulted, or Informed for project tasks.

53
New cards

CyberSecurity Policy

Document defining management's guidance and mandatory requirements for implementing information security.

54
New cards

Master Service Agreement (MSA)

Contract establishing the foundation for long-term business relationships by defining future engagement terms and obligations.

55
New cards

Service Level Agreement (SLA)

Legally binding contract defining service behavior, operational expectations, and measurable quality standards.

56
New cards

Operating Level Agreement (OLA)

An internal organizational document detailing relationships between internal departments supporting business activities.

57
New cards

Statement of Work (SOW)

An agreement between a client and service provider defining exact project scope, deliverables, and exclusions.

58
New cards

Memorandum of Understanding (MOU)

A non-binding document outlining participant responsibilities in an agreement between two organizations.

59
New cards

Interconnection Security Agreement (ISA)

Document describing technical interconnection requirements, data sensitivity, and data flow when sharing information between organizations (NIST SP800-47).

60
New cards

Interoperability Agreement (IA)

Agreement between organizations (commonly subsidiary companies) to work together to facilitate mutual data exchange.

61
New cards

Business Partnership Agreement (BPA)

Written agreement detailing business partner relationships, profit/loss shares, obligations, and partner exit conditions.

62
New cards

Reciprocal Agreement (RA)

Agreement where two organizations with similar tech infrastructures act as disaster recovery alternate sites for each other.

63
New cards

Non-Disclosure Agreement (NDA)

Contract promising to protect confidential secret information disclosed during business or employment relationships.

64
New cards

Configuration Management

Discipline ensuring that all hardware, software, and IT assets owned by an organization are known, controlled, and tracked.

65
New cards

Configuration Management Database (CMDB)

Centralized database detailing records of all IT assets, software versions, configurations, and interrelationships.

66
New cards

IT Asset Inventory

Inventory of physical/virtual assets (hardware, software, licenses) used primarily for asset tracking, compliance, and financial management.

67
New cards

Change Control

Process ensuring that all IT modifications are approved, documented, tested, and accepted.

68
New cards

Software Supply Chain Attack

Attempt to exploit weaknesses in software development stages (source code, build process, update server) to plant malware.

69
New cards

Software Bill of Materials (SBOM)

Comprehensive inventory list of all application software components and dependencies used in software supply chain tracking.

70
New cards

CISA

Cybersecurity & Infrastructure Security Agency, part of Homeland Security providing security guidance and alerts.

71
New cards

Risk

A function of the likelihood of a threat exploiting a vulnerability and the resulting impact severity on the organization.

72
New cards

Asset

Any resource of value to an organization.

73
New cards

Threat

A potential danger (accidental trigger or intentional exploit) to an asset if a threat-agent takes advantage of a vulnerability.

74
New cards

Threat-Agent

Anything or anyone (actor, vector, natural disaster) that has the potential to cause a threat.

75
New cards

Vulnerability

A flaw or weakness in an asset or security system.

76
New cards

Exposure

An opportunity for a threat to cause loss due to an unresolved vulnerability.

77
New cards

Exploit / Event

An instance of loss experienced or execution of an attack targeting a vulnerability.

78
New cards

Safeguard

Technical or non-technical risk mitigation mechanism or countermeasure.

79
New cards

Passive Man-Made Threat

Threat involving gathering or intercepting information without interacting directly with target systems, leaving no trace.

80
New cards

Active Man-Made Threat

Threat involving direct interaction with target systems, typically leaving a trail or trace of activity.

81
New cards

Script Kiddies

Unskilled threat actors who use existing computer scripts or code without deep expertise or significant funding.

82
New cards

Hacktivist

Threat actor launching attacks to support an activist movement or further a social/political cause.

83
New cards

Malicious Insider

An employee or authorized user with legitimate access who abuses privileges out of greed, revenge, or coercion.

84
New cards

Nation-State Actors

Highly organized and funded threat actors sponsored by a government entity for political or strategic objectives.

85
New cards

Black Hat

An unauthorized hacker performing malicious criminal activities.

86
New cards

White Hat

An authorized security professional (ethical hacker) working within the law to protect organizations.

87
New cards

Gray Hat

A semi-authorized hacker who may violate ethical standards or laws without malicious intent.

88
New cards

Total Risk (Inherent Risk)

Risk existing before security safeguards are applied, calculated as Total Risk=Threats×Vulnerability×Asset Value\text{Total Risk} = \text{Threats} \times \text{Vulnerability} \times \text{Asset Value}.

89
New cards

Residual Risk

The risk remaining after security safeguards and mitigations have been applied.

90
New cards

Accepted Risk

Choice made by an organization to tolerate risk without implementing additional security safeguards.

91
New cards

Single Loss Expectancy (SLE)

Monetary loss expected from a single realized threat, calculated as SLE=Asset Value (AV)×Exposure Factor (EF)\text{SLE} = \text{Asset Value (AV)} \times \text{Exposure Factor (EF)}.

92
New cards

Exposure Factor (EF)

The percentage of loss a realized threat could cause to a specific asset.

93
New cards

Annualized Rate of Occurrence (ARO)

The estimated frequency or number of times a specific threat takes place during a single year.

94
New cards

Annualized Loss Expectancy (ALE)

Estimated annual loss from a risk, calculated as ALE=SLE×ARO\text{ALE} = \text{SLE} \times \text{ARO}.

95
New cards

Qualitative Risk Analysis

Subjective risk assessment assigning non-monetary ratings (e.g., Low, Medium, High) based on subject matter expert input.

96
New cards

Risk Register

Central repository/worksheet detailing identified risks, risk owners, likelihood, impact, scores, and mitigation steps.

97
New cards

NIST Risk Management Framework (RMF)

A 6-step lifecycle process defined in NIST SP 800-37: Categorize, Select, Implement, Assess, Authorize, and Monitor.

98
New cards

Business Impact Analysis (BIA)

Initial BC/DR process identifying critical business assets, evaluating downtime operational impact, and establishing recovery priorities.

99
New cards

Maximum Tolerable Downtime (MTD)

Estimated maximum duration a system can remain inoperable before impact on an organization becomes severe.

100
New cards

Recovery Time Objective (RTO)

Maximum acceptable period of time that a business process or IT system can be unavailable during a disaster.