Chapter 1 IA Concepts
y concepts
Information system security concepts
Internet, world wide web.
Risk - likely hood that something bad will happen to an asset, threat - any action that could damage and asset, vulnerability - a weakness that allows a threat to be a risk(risk = threat x vulnerability
information system - hardware operating system and application software that work together to collect data.
Confidentiality, integrity, and availability (CIA)
Confidentiality - Private data of individuals, intellectual property of businesses, national security for countries and governments. Cryptography, encryption, and ciphertext.
Integrity - maintain valid, uncorrupted, and accurate information.
Availability - in the context of information security, the amount of time users can use a system, application, and data. Availability Time measurements - uptime, downtime, mean time for failure, mean time to repair, mean time between failures, recovery time objective(optimal time to get said thing back up).
The seven domains of an IT infrastructure
User domain, workstation domain, LAN(Local Area Network) domain, LAN-to-WAN(Wide Area Network) Domain, WAN domain, Remote access domain, System/Application domain.
Roles and Tasks, Responsibility, and accountability for each domain(CHATGPT)
The weakest link in the security of an IT infrastructure
The user is the weakest link in security
IT security policy framework and data classification standard.
Policy, standard, procedures, and guidelines
Policy hierarchy
Data classification standards
Risk - Is the level of exposure to some event that has an effect on asset, usually the likelihood that something bad will happen to an asset(Computer, A device, Database, etc)
Threat - is any action, either natural or human induced, that could damage an asset.
Vulnerability - is a weakness that allows a threat to be realized or to have an effect on an asset.
End-User License Agreement (EULA) - are license agreements between a user and a software vendor that protect themselves from the liability of their own vulnerabilities
Information system security - is the collection of activities that protect the information system and the data stored in it
Types of information commonly found within an IT infrastructure - Privacy data of individuals, Corporate intellectual property, online b2C and b2b transaction(online banking, purchases), Government intellectual property.
Current Laws and regulations related to information security include the following:
FISMA(Federal Information Security Management Act
FISMA(Federal information Security Modernization Act
SOX(Sarbanes-Oxley Act)
GLBA(Gramm-Leach-Bliley Act)
HIPAA(Health Insurance Portability and Accountability Act)
CIPA(Children's Internet Protection Act)
FERPA(Family Educational Rights and Privacy Act)
Tenants of information system security :
Confidentiality - Only authorized users can view information
Integrity - Only authorized users can change information
Availability - Information is accessible by authorized users whenever they request information
The seven Domains
User Domain - The people and the processes that access an organization's information system
Roles and Tasks - AUP
Responsibilities -
Accountability -
Work Station Domain - Can be any device that connects to the network, such as desktop or laptop computers, smart phones, etc.
Thin Client - can refer to a software or an actual computer with no hard drive that runs on a network and relies on a server to provide applications, data, and all processing.
Thick Client - has more fully featured hardware that contains a hard drive and application s and processes data locally, going to the server or cloud mainly for file stroage
Roles and task - Hardening
Responsibilities -
Accountabilities -
LAN Domain - is a collection of computers and devices connected to one another or to a common connection medium, which can include wires, fiber optic cables, or radio waves
Physical parts of a LAN domain - NIC(Network interface controller, Ethernet LAN, UTP(Unshielded twisted-pair, LAN switch, WAP(wireless access point.
Logical parts of a LAN Domain - System administrator, design of directory and file services, configuration of workstation and server TCP/IP software and communication protocols, design of virtual LAN's
Roles and Taks - Physical and logical configuration for users
Responsibilities -
Accountabilities -
LAN -to-WAN Domain - is where the IT infrastructure links to a WAN and the internet. (TCP and UDP)
Roles and Tasks -
Responsibilities -
Accountabilities -
WAN Domain - Connects Remote locations
Roles and Tasks -
Responsibilities -
Accountabilities -
Remote Access domain - Connects the remote users to the organizations IT infrastructure
Roles and Tasks -
Responsibilities -
Accountabilities -
System/Application Domain - Holds all the mission-critical systems, application, and data
Roles and Tasks -
Responsibilities -
Accountabilities -
IT Security Policy Framework - consists of policies, standards, procedures, and guidelines that reduce risks and threats
Policy - A short written statement that the people in charge of an organization have to set as a course of action or direction
Standard - Is a detailed written definition for hardware and software and how they are to be used
Procedures - Written instructions for how to use policies and standards
Guidelines - a suggested course of action for using the policies, standards, or procedures
Foundational IT Security Policies -
AUP
Security Awareness policy
Asset classification policy
Asset protections policy
Asset management policy
Vulnerability policy
Threat assessment and monitoring

Chapter 1 Topics
What unauthorized access and data breaches are unauthorized access means that the attacker obtains your authorized logon ID and password without your permission. Data breaches are attacks that occur on the internet of things that allows the hacker to have access to important information on the end user essentially harming someone's identity.
What information system security is the collection of activities that protect the information system and the data stored in it.
What the tenants of information system security are
What the seven domains of an IT infrastructure are
What the weakest link in an IT infrastructure is
How an IT security policy framework can reduce risk
How a data classification standard affects an it infrastructure's security needs
Chapter 1 Goals
Describe how unauthorized access can lead to a data breach
Relate how availability, integrity, and confidentiality requirements affect the seven domains of a typical IT infrastructure
Describe the risk, threat, and vulnerabilities commonly found within the seven domains
Identify a layered security approach throughout the seven domains
Develop an it security policy framework to help reduce risk from the common threats and vulnerabilities
Relate how a data classification standard affects the seven domains
