Send a link to your students to track their progress
373 Terms
1
New cards
Information security
Protects information and systems from unauthorized access, disclosure, alteration, destruction, and disruption.
2
New cards
Asset
Anything valuable to an organization that needs protection, such as data, systems, people, or equipment.
3
New cards
Threat
Anything capable of causing harm to an asset.
4
New cards
Vulnerability
A weakness that a threat could exploit.
5
New cards
Risk
The potential for harm when a threat exploits a vulnerability, based on how likely it is and how serious the impact would be.
6
New cards
Control
A safeguard used to reduce the likelihood or impact of a security risk.
7
New cards
Confidentiality
Information is accessible only to authorized people or systems.
8
New cards
Integrity
Information remains accurate, complete, and protected from unauthorized changes.
9
New cards
Availability
Systems and data are accessible to authorized users when needed.
10
New cards
Identification
A user or system claims an identity.
11
New cards
Authentication
The system verifies that the claimed identity is valid.
12
New cards
Authorization
The system determines what an authenticated user or system is allowed to access or do.
13
New cards
Accounting
The system records activity so actions can be reviewed and tied to a user or system.
14
New cards
Administrative control
A security control based on policies, procedures, training, or management decisions.
15
New cards
Technical control
A security control enforced through hardware, software, or system configuration.
16
New cards
Physical control
A security control that protects buildings, equipment, or physical access.
17
New cards
IT security control
A safeguard used to prevent, detect, respond to, or recover from security threats and reduce information-system risk.
18
New cards
Preventive control
A control designed to stop a security incident before it happens.
19
New cards
Detective control
A control designed to identify a security incident while it is happening or after it occurs.
20
New cards
Corrective control
A control designed to reduce damage or fix a problem after a security incident occurs.
21
New cards
Directive control
A control that tells users or systems what security behavior is required.
22
New cards
Deterrent control
A control designed to discourage someone from attempting an unwanted action.
23
New cards
Compensating control
An alternative control used when the preferred control cannot be implemented but the same risk still needs to be reduced.
24
New cards
Recovery control
A control designed to restore systems, data, or operations after a disruption.
25
New cards
Stuxnet
Malware that targeted Siemens industrial-control systems and changed PLC behavior while hiding those changes from operators, making it a strong example of an integrity attack.
26
New cards
CISO (Chief Information Security Officer)
The executive responsible for an organization's overall information-security strategy, priorities, and risk direction.
27
New cards
Security analyst
Monitors systems for threats and investigates suspicious or malicious activity.
28
New cards
System administrator
Configures, maintains, and secures systems and their settings.
29
New cards
Data owner
The person or role responsible for deciding who should be allowed to access specific data.
30
New cards
User
A person who uses organizational systems and is expected to follow security policies and report suspicious activity.
31
New cards
Security plan
A plan that identifies important assets and risks, then selects controls to reduce those risks.
32
New cards
What affects the size of a risk?
The likelihood that the harmful event will occur and the impact if it does.
33
New cards
What do backups primarily support?
Availability and recovery by allowing lost or damaged data to be restored.
34
New cards
What does encryption primarily protect?
Confidentiality by making data unreadable without the required key.
35
New cards
Why don't backups alone protect confidentiality?
A backup can still expose sensitive information if someone gains unauthorized access to it.
36
New cards
A student logs in but cannot open the gradebook. What happened?
Authentication succeeded, but authorization correctly prevented access to something the student is not allowed to use.
37
New cards
A camera records someone entering a server room. Classify the control.
It is a physical control because it protects a physical area and a detective control because it records activity for later review.
38
New cards
A public database allows anonymous access to customer addresses. Identify the vulnerability and main CIA impact.
The vulnerability is unrestricted anonymous access. The main impact is loss of confidentiality.
39
New cards
A hacker changes bank balances without reading or leaking them. Which CIA property is harmed?
Integrity, because the information was changed without authorization.
40
New cards
ISO/IEC 27001
An international standard that defines requirements for creating and maintaining an information security management system (ISMS).
41
New cards
NIST Cybersecurity Framework (NIST CSF)
A framework that helps organizations organize and improve how they manage cybersecurity risk.
42
New cards
COBIT (Control Objectives for Information and Related Technologies)
ISACA's framework for governing and managing enterprise information and technology.
43
New cards
CIS Controls (Center for Internet Security Controls)
A prioritized set of practical cybersecurity safeguards designed to reduce common security risks.
44
New cards
PCI DSS (Payment Card Industry Data Security Standard)
A security standard for organizations that store, process, or transmit payment card information.
45
New cards
HIPAA Security Rule
A U.S. requirement for protecting electronic protected health information (ePHI).
46
New cards
GDPR (General Data Protection Regulation)
An EU regulation governing how organizations collect, use, protect, and handle personal data.
47
New cards
SOX (Sarbanes-Oxley Act) IT Controls
A U.S. law requiring controls that help protect the accuracy and integrity of financial reporting and related information systems.
48
New cards
FISMA
A U.S. federal law requiring federal agencies to establish and maintain information-security programs for their systems and data.
49
New cards
CMMC (Cybersecurity Maturity Model Certification)
A U.S. Department of Defense program used to assess whether Defense Industrial Base contractors meet required cybersecurity practices.
50
New cards
Threat actor
A person or group capable of causing harm to an organization's information, systems, or other assets.
51
New cards
White hat
An authorized security tester who works within an approved scope to find and help fix security weaknesses.
52
New cards
Black hat
A malicious attacker who acts without authorization.
53
New cards
Gray hat
Someone who tests or accesses systems without authorization but may claim they are trying to help improve security.
54
New cards
Script kiddie
An inexperienced attacker who uses existing tools or code without fully understanding how they work.
55
New cards
Hacktivist
An attacker motivated mainly by a political, social, or ideological cause.
56
New cards
Insider threat
A trusted person with legitimate access who intentionally or accidentally causes harm to the organization.
57
New cards
Organized crime
A coordinated criminal group usually motivated by financial gain.
58
New cards
Nation-state
A government-backed threat actor pursuing goals such as espionage, disruption, or strategic advantage.
59
New cards
APT (Advanced Persistent Threat)
A well-resourced and persistent actor or campaign that pursues long-term objectives and may try to maintain access for an extended period.
60
New cards
Threat intelligence
Analyzed and contextualized information about threats that helps defenders make a security decision.
61
New cards
Indicator of compromise (IoC)
An observable artifact that may indicate a system has been compromised, such as a malicious file hash, IP address, or domain.
62
New cards
Tactics, techniques, and procedures (TTPs)
A way to describe attacker behavior: tactics are goals, techniques are general methods, and procedures are the specific ways those methods are carried out.
63
New cards
Attack vector
The path or method an attacker uses to reach a target or deliver an attack.
64
New cards
Attribution
The process of assessing who is most likely responsible for an attack.
65
New cards
White hat vs. gray hat
White hats have authorization to test. Gray hats do not have authorization, even if they claim a helpful purpose.
66
New cards
IoC vs. TTP
An IoC is a specific observable trace of an attack. A TTP describes the attacker's repeatable behavior.
67
New cards
Nation-state vs. organized crime
Nation-states usually pursue strategic or government objectives. Organized crime is usually motivated by money.
68
New cards
Threat data vs. threat intelligence
Threat data is a raw observation. Threat intelligence adds context and analysis so the information can support a defensive decision.
69
New cards
Threat model
A structured view of what asset is at risk, who may attack it, what they want, how they could reach it, what weakness they may exploit, and what control would reduce the risk.
70
New cards
Shelf life of threat intelligence
Threat intelligence can become outdated. Its usefulness depends on when it was collected, how reliable the source is, and whether it is still relevant to the environment.
71
New cards
How should threat actors be classified?
Use evidence such as authorization, motivation, resources, sophistication, and persistence instead of judging an actor from one technique.
72
New cards
When does threat data become threat intelligence?
When context and analysis make the raw data useful for a decision, such as deciding to hunt for, block, or prioritize a threat.
73
New cards
Attack surface
All the possible points where an attacker could interact with, enter, or exploit a system or environment.
74
New cards
Attack surface vs. attack vector
The attack surface is the full set of possible entry points. An attack vector is the specific path or method used in an attack.
75
New cards
Common attack vectors
Common vectors include email, removable media, direct physical access, remote access, supply chains, websites, and cloud services.
76
New cards
Malicious insider
A person with legitimate or former trusted access who intentionally uses that access to harm the organization.
77
New cards
Unintentional insider
A trusted person whose mistake, carelessness, or unsafe behavior causes harm without malicious intent.
78
New cards
Targeted vs. opportunistic attack
A targeted attack is aimed at a specific victim. An opportunistic attack searches for any victim that happens to be vulnerable.
79
New cards
Competitor as a threat actor
A competitor may become a threat actor if it attempts to gain another organization's information or advantage through unauthorized means such as espionage or an insider.
80
New cards
Tactic in a TTP
The attacker's objective or what they are trying to accomplish.
81
New cards
Technique in a TTP
The general method the attacker uses to accomplish a tactic.
82
New cards
Procedure in a TTP
The specific steps or implementation an attacker uses to perform a technique.
83
New cards
Examples of threat intelligence sources
Incident investigations, honeypots, academic research, information-sharing groups, and threat-data feeds.
84
New cards
What makes a threat-intelligence source useful?
Reliability, recency, relevance to the organization's environment, and whether the information supports a useful defensive action.
85
New cards
Why is attribution uncertain?
Attackers can reuse tools, share infrastructure, hide their identity, or plant misleading evidence, so attribution usually represents a level of confidence rather than absolute proof.
86
New cards
Social engineering
Manipulating people into revealing information, granting access, or taking a harmful action.
87
New cards
Phishing
Deceptive electronic communication sent to steal information or trigger action.
88
New cards
Spear phishing
Phishing tailored to a person or group.
89
New cards
Whaling
Phishing aimed at senior leaders or other high-value targets.
90
New cards
Smishing
Phishing through SMS or text messaging.
91
New cards
Vishing
Phishing through voice calls or voicemail.
92
New cards
Pretexting
Creating a believable story or role to obtain cooperation.
93
New cards
Impersonation
Pretending to be a trusted person or organization.
94
New cards
Tailgating
Following an authorized person into a restricted area without separate authorization.
95
New cards
Shoulder surfing
Watching a person enter or view sensitive information.
96
New cards
Dumpster diving
Recovering useful information from discarded materials.
97
New cards
Baiting
Offering something attractive to trigger unsafe behavior.
98
New cards
Urgency
Pressure designed to reduce verification and careful thought.
99
New cards
Business email compromise
Impersonation or account compromise used to redirect payments or sensitive business actions.
100
New cards
Reciprocity
The pressure to return a favor after receiving something first.