WGU ofFundamentals
Information
WGUSecurity
of
Fundamentals
Information
– Study
Security
of Information
Guide–
–Study
Lecture
Security
Guide
Summary
–
–Study
Lecture
and
Guide
Practice
Summary
– Lecture
Questions
and Practice
Summary
with Questions
Answers.pdf
and Practice
with Questions
Answers.pdf
with Answers.pdf
WGU
Fundamentals of
Information
Security – Study
Guide – Lecture
Summary and
Practice Questions
with Answers
WGU Fundamentals
WGU ofFundamentals
Information
WGUSecurity
of
Fundamentals
Information
– Study
Security
of Information
Guide–
–Study
Lecture
Security
Guide
Summary
–
–Study
Lecture
and
Guide
Practice
Summary
– Lecture
Questions
and Practice
Summary
with Questions
Answers.pdf
and Practice
with Questions
Answers.pdf
with Answers.pdf
,WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf
Information security keeping data, software, and hardware secure against unauthorized access, use,
disclosure, disruption, modification, or destruction
Health Insurance Portability and Accountability Act of HIPPA
1996
Health Information Technology for Economic and Clinical HITECH
Health Act
Payment Card Industry Data Security Standard PCI DSS
Federal Information Security Management Act of 2002 FISMA
What is CIA Confidentiality, Integrity, Availability
Confidentiality allowing only those authorized to access the data requested
Integrity Keeping data unaltered by accidental or malicious intent
Availability To access data when needed
WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf
,WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf
Parkerian hexad A model that adds three more principles to the CIA triad: possession/control,
utility, and authenticity
Possession Refers to the physical disposition of the media on which the data is stored
Authenticity Allows you to say whether you've attributed the data in question to the proper
owner or creator
Utility Refers to how useful the data is to you
The four categories of attacks Interception, Interruption, Modification, Fabrication
Interception Allows unauthorized users to access you data, applications, or environments.
Primarily attacks against confidentiality
Modification attacks that involve tampering with your assets. Primarily attacks Integrity and but
can affect Availability
Interruption attacks that cause your assets to become unusable or unavailable to you
temporary or permanent basis. Primarily attacks Integrity and but can affect
Availability
WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf
, WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf
Fabrication attacks that involve generating data, processes, communications, or other similar
activities with a system. Primarily attacks Integrity and but can affect Availability
Risk the likelihood that something bad will happen
Threats something that has potential to cause harm
Vulnerabilities Weaknesses, or holes, that threats can exploit to cause you harm.
Impact An additional step that takes into account the value of the asset being threatened
and uses it to calculate risk
The three different categories of controls Physical, technical/logical, and administrative
Physical controls To protect the physical environment in which your systems sit or where your data
is stored
Technical/logical controls Protects the system, networks and environments that process, transmit, and store
your data. (firewalls, AV, IDS, and IPS)
WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf WGU Fundamentals of information Security.pdf