Fundamentals
C836 –WGU
Fundamentals
of Information
C836 – Fundamentals
Security_
of Information
CoreSecurity_
ofConcepts,
Information
Core
Risk
Security_
Concepts,
Management,
Core
RiskConcepts,
and
Management,
Cybersecurity
Risk and
Management,
Study
Cybersecurity
Guide.pdf
and Study
Cybersecurity
Guide.pdfStudy Guide.pdf
WGU C836 – Fundamentals of
Information Security: Core Concepts,
Risk Management, and Cybersecurity
Study Guide
Guidehttps://www.stuvia.com/dashboard!@_)#*)(@$)($@*($@)($@*_
WGU C836 –WGU
Fundamentals
C836 –WGU
Fundamentals
of Information
C836 – Fundamentals
Security_
of Information
CoreSecurity_
ofConcepts,
Information
Core
Risk
Security_
Concepts,
Management,
Core
RiskConcepts,
and
Management,
Cybersecurity
Risk and
Management,
Study
Cybersecurity
Guide.pdf
and Study
Cybersecurity
Guide.pdfStudy Guide.pdf
,C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf
Terms in this set (186)
Information Security Protecting an organization's information and information
systems from unauthorized access, use, disclosure, disruption,
modification, or destruction.
Compliance Requirements that are set forth by laws and
industry regulations.
CIA Confidentiality, Integrity, Availability
Confidentiality Refers to our ability to protect our data from those who are
not authorized to use/view it
Integrity The ability to prevent people from changing your data in an
unauthorized or undesirable manner
Availability Refers to the ability to access our data when we need it
C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf
,C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf
Possession/Control refers to the physical disposition of the media on which the
data is stored. (tape examples where some are encrypted and
some are not)
Authenticity whether you've attributed the data in question to the proper
owner or creator. (altered email that says it's from one person
when it's not - violation of the authenticity of the email)
Utility refers to how useful the data is to you.
Attacks interception, interruption, modification, and
fabrication
Interception attacks that allow unauthorized users to access your data,
applications, or environments. Are primarily attacks against
confidentiality
C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf
, C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf
Interruption attacks that make your assets unusable or unavailable to you
temporarily or permanently. DoS attack on a mail server, for
example. May also affect integrity
Modification attacks involve tampering with our asset. Such attacks might
primarily be considered an integrity attack but could also
represent an availability attack.
Fabrication attacks involve generating data, processes, communications,
or other similar activities with a system. Fabrication attacks
primarily affect integrity but could be considered an
availability attack as well.
Risk is the likelihood that an event will occur. To have risk there
must be a
threat and vulnerability.
Threats are any events being man-made, natural or environmental that
could cause damage to assets.
C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf C836 - Fundamentals of Information Security (WGU.pdf