Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 22 pages
Other

D481 Security Foundations ISC2 SEC found all of what you need for exam Western Governors University

Document preview thumbnail
Preview 3 out of 22 pages

D481 Security Foundations ISC2 SEC found all of what you need for exam Western Governors University

Content preview

D481 Security Foundations ISC2 SEC FOUND all of
what you need for exam Western Governors University




Adequate Security - Security commensurate with the risk and the magnitude of harm
resulting from the loss, misuse or unauthorized access to or modification of information.
Source: OMB Circular A-130

Administrative Controls - Controls implemented through policy and procedures. Examples
include access control processes and requiring multiple personnel to conduct a specific
operation. Administrative controls in modern environments are often enforced in
conjunction with physical and/or technical controls, such as an access-granting policy
for new users that requires login and approval by the hiring manager.

Adverse Events - Events with a negative consequence, such as system crashes, network
packet floods, unauthorized use of system privileges, defacement of a web page or
execution of malicious code that destroys data.

Application Programming Interface (API) - A set of routines, standards, protocols, and tools for
building software applications to access a web-based software application or web tool.

Application Server - A computer responsible for hosting applications to user workstations. NIST
SP 800-82 Rev.2

Artificial Intelligence - The ability of computers and robots to simulate human intelligence and
behavior.

Asset - Anything of value that is owned by an organization. Assets include both tangible
items such as information systems and physical property and intangible assets such as
intellectual property.

Asymmetric Encryption - An algorithm that uses one key to encrypt and a different key to
decrypt the input plaintext.

Audit - Independent review and examination of records and activities to assess the adequac
of system controls, to ensure compliance with established policies and operational
procedures. NIST SP 1800-15B

Authentication - Access control process validating that the identity being claimed by a user

,or entity is known to the system, by comparing one (single-factor or SFA) or more (multi-
factor authentication or MFA) factors of identification.

Authorization - The right or a permission that is granted to a system entity to access a
system resource. NIST 800-82 Rev.2

Availability - Ensuring timely and reliable access to and use of information by authorized
users.

Baseline - A documented, lowest level of security configuration allowed by a standard or
organization.

Biometric - Biological characteristics of an individual, such as a fingerprint, hand
geometry, voice, or iris patterns.

Bit - The most essential representation of data (zero or one) at Layer 1 of the Open
Systems Interconnection (OSI) model.

Bot - Malicious code that acts like a remotely controlled "robot" for an attacker, with other
Trojan and worm capabilities.

Breach - The loss of control, compromise, unauthorized disclosure, unauthorized acquisition
or any similar occurrence where: a person other than an authorized user accesses or
potentially accesses personally

, identifiable information; or an authorized user accesses personally identifiable information
for other than an authorized purpose. Source: NIST SP 800-53 Rev. 5

Broadcast - Broadcast transmission is a one-to-many (one-to-everyone) form of sending
internet traffic.

Business Continuity (BC) - Actions, processes and tools for ensuring an organization can continue
critical operations during a contingency.

Business Continuity Plan (BCP) - The documentation of a predetermined set of instructions or
procedures that describe how an organization´s mission/business processes will be sustained
during and after a significant disruption.

Business Impact Analysis (BIA) - An analysis of an information system´s requirements,
functions, and interdependencies used to characterize system contingency requirements
and priorities in the event of a significant disruption. NIST SP 800-34 Rev. 1

Byte - The byte is a unit of digital information that most commonly consists of eight bits.

Checksum - A digit representing the sum of the correct digits in a piece of stored or
transmitted digital data, against which later comparisons can be made to detect errors in
the data.

Ciphertext - The altered form of a plaintext message so it is unreadable for anyone except the
intended recipients. In other words, it has been turned into a secret.

Classification - Classification identifies the degree of harm to the organization, its stakeholder
or others that might result if an information asset is divulged to an unauthorized person,
process or organization. In short, classification is focused first and foremost on
maintaining the confidentiality of the data, based on the data sensitivity.

Classified or Sensitive Information - Information that has been determined to require protection
against unauthorized disclosure and is marked to indicate its classified status and
classification level when in documentary form.

Cloud Computing - A model for enabling ubiquitous, convenient, on-demand network acces
to a shared pool of configurable computing resources (e.g., networks, servers, storage
applications, and services) that can be rapidly provisioned and released with minima
management effort or service provider interaction. NIST 800-145

Community Cloud - A system in which the cloud infrastructure is provisioned for exclusive
use by a specific community of consumers from organizations that have shared concerns
(e.g., mission, security requirements, policy and compliance considerations). It may be
owned, managed and operated by one or more of the organizations in the community, a
third party or some combination of them, and it may exist on or off premises. NIST 800-145

Confidentiality - The characteristic of data or information when it is not made available or
disclosed to unauthorized persons or processes. NIST 800-66

Configuration Management - A process and discipline used to ensure that the only changes

Document information

Uploaded on
March 4, 2025
Number of pages
22
Written in
2024/2025
Type
Other
Person
Unknown
$13.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
smartzone
3.6
(622)
Sold
3428
Followers
2298
Items
14823
Last sold
18 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions