ITEC 3710 Exam Questions with
Complete Solutions35
What are the IAS core principles - ANSWERS-Comprehensive
Independent
Legal and Regulatory Requirements
Living Document
Long Life Span
Customizable and Pragmatic
Risk Based Approach
Organizationally Significant
Strategic, Tactical and Operational
Concise, Well Structured Extensible
How should you develop an IAS - ANSWERS-Legal and Regulatory Requirements
- Consistent with existing laws and regulations.
Living Document
- Constantly updated
Long Life Span
- Constantly relevant to fundamentals
Customizable and Pragmatic
- Reflect identified organizational IA requirements + risk profiles
Risk Based Approach
- Broad enough to guide sub-components with diverse risk profiles
Organizationally Significant
,- IA should be significant in organizations strategy and ongoing operations
Strategic, Tactical and Operational
- IAS should assist senior managers + execs make strategic plans
Concise, well structured and Extensible
- High cohesion and low coupling
Why do we need IA? - ANSWERS-- Assets and infrastructure are constantly threatened
- Dynamic threat environment increases the need
- IA is not just a technology issue, also business + social
- The goal is to protect information and infrastructure that supports the mission and the vision
of the organizations
- Evaluate the sensitivity and criticality of applications and data and the organizations
acceptable risk level
What is IA and what are its 5 aspects? - ANSWERS-IA is the overarching appraoch for identifying,
understnading and managing risk through and organizations information and information
systems
The 5 aspects are
- Confidentiality
- Integrity
- Availability
- Nonrepudiation
- Authentication.
What are the aspects of Information Security (IS)? - ANSWERS-- Confidentiality
- Integrity
- Availablity.
,What is Information Protection (IP) and what are its aspects? - ANSWERS-- It is a subset of IS
- Protecting the confidentiality and integrity of information through policies and controls
- IP is required for ID and health info
What is Cybersecurity? - ANSWERS-- It is IS but the scope is to do with electronic systems CIA
- Primarily focused on networks and info systems
What is Confidentiality? - ANSWERS-- Assurance of secrecy where no one can read data except
for intended entity
- Prevail no matter what
What is Privacy? - ANSWERS-- Involved personal autonomy and control of information about
oneself
What is Integrity? - ANSWERS-- Assurance of accuracy of data and that it has neither been
corrupted nor modified improperly.
- Should be considered not only form a personnel perspective but also a systems perspective.
What is Availability - ANSWERS-- Assurance of data and resources being accessible to authorized
personnel
- Networks and systems should be able to perform predictably and acceptably.
What is Nonrepudiation? - ANSWERS-- Making sure messages are proved through the use of
digital signatures.
- Digital signatures are evidence that the information originated from the sender and prevents
denial of sending messages
, - Additionally, digital signatures may prove a reciever has recieved a message and that this
evidence can not be denied
What is Authentication? - ANSWERS-- Authentication validates ID provided by a user
- Makes sure entity presenting ID is actually who they are claiming to be
What is Authorization? - ANSWERS-- When a user presents second credential, the system uses
an access control matrix to prove associated privileges.
What is Accountability? - ANSWERS-- The act of being responsible for actions taken within a
system
- To ensure accountability, a system will log a users actions.
What is an Asset, Threat, Vulnerability, Risk and Controls? - ANSWERS-- Threats are natural,
deliverate or accident events that can cause asset loss
- Vulnerabilities are exploitable weakness that can lead to harm in the CIA triad
- Risks arise when threats exploit vulnerabilities
- Controls are protective measures that reduce risk, their types and effectiveness
- Likelihood is probability of risk occurrence.
What are Attackers? - ANSWERS-- Attackers penetrate an organizations system internally or
externally with or without authorization.
- Internal attackers can be disgruntled employees whose knowledge makes them capable
- External attackers threat are considered high risk
What is a Vulnerability? And what are some examples? - ANSWERS-- Inherent weaknesses
within information assets that threats can exploit
- Lack of antivirus, weak hiring procedures, inadequate physical access controls
Complete Solutions35
What are the IAS core principles - ANSWERS-Comprehensive
Independent
Legal and Regulatory Requirements
Living Document
Long Life Span
Customizable and Pragmatic
Risk Based Approach
Organizationally Significant
Strategic, Tactical and Operational
Concise, Well Structured Extensible
How should you develop an IAS - ANSWERS-Legal and Regulatory Requirements
- Consistent with existing laws and regulations.
Living Document
- Constantly updated
Long Life Span
- Constantly relevant to fundamentals
Customizable and Pragmatic
- Reflect identified organizational IA requirements + risk profiles
Risk Based Approach
- Broad enough to guide sub-components with diverse risk profiles
Organizationally Significant
,- IA should be significant in organizations strategy and ongoing operations
Strategic, Tactical and Operational
- IAS should assist senior managers + execs make strategic plans
Concise, well structured and Extensible
- High cohesion and low coupling
Why do we need IA? - ANSWERS-- Assets and infrastructure are constantly threatened
- Dynamic threat environment increases the need
- IA is not just a technology issue, also business + social
- The goal is to protect information and infrastructure that supports the mission and the vision
of the organizations
- Evaluate the sensitivity and criticality of applications and data and the organizations
acceptable risk level
What is IA and what are its 5 aspects? - ANSWERS-IA is the overarching appraoch for identifying,
understnading and managing risk through and organizations information and information
systems
The 5 aspects are
- Confidentiality
- Integrity
- Availability
- Nonrepudiation
- Authentication.
What are the aspects of Information Security (IS)? - ANSWERS-- Confidentiality
- Integrity
- Availablity.
,What is Information Protection (IP) and what are its aspects? - ANSWERS-- It is a subset of IS
- Protecting the confidentiality and integrity of information through policies and controls
- IP is required for ID and health info
What is Cybersecurity? - ANSWERS-- It is IS but the scope is to do with electronic systems CIA
- Primarily focused on networks and info systems
What is Confidentiality? - ANSWERS-- Assurance of secrecy where no one can read data except
for intended entity
- Prevail no matter what
What is Privacy? - ANSWERS-- Involved personal autonomy and control of information about
oneself
What is Integrity? - ANSWERS-- Assurance of accuracy of data and that it has neither been
corrupted nor modified improperly.
- Should be considered not only form a personnel perspective but also a systems perspective.
What is Availability - ANSWERS-- Assurance of data and resources being accessible to authorized
personnel
- Networks and systems should be able to perform predictably and acceptably.
What is Nonrepudiation? - ANSWERS-- Making sure messages are proved through the use of
digital signatures.
- Digital signatures are evidence that the information originated from the sender and prevents
denial of sending messages
, - Additionally, digital signatures may prove a reciever has recieved a message and that this
evidence can not be denied
What is Authentication? - ANSWERS-- Authentication validates ID provided by a user
- Makes sure entity presenting ID is actually who they are claiming to be
What is Authorization? - ANSWERS-- When a user presents second credential, the system uses
an access control matrix to prove associated privileges.
What is Accountability? - ANSWERS-- The act of being responsible for actions taken within a
system
- To ensure accountability, a system will log a users actions.
What is an Asset, Threat, Vulnerability, Risk and Controls? - ANSWERS-- Threats are natural,
deliverate or accident events that can cause asset loss
- Vulnerabilities are exploitable weakness that can lead to harm in the CIA triad
- Risks arise when threats exploit vulnerabilities
- Controls are protective measures that reduce risk, their types and effectiveness
- Likelihood is probability of risk occurrence.
What are Attackers? - ANSWERS-- Attackers penetrate an organizations system internally or
externally with or without authorization.
- Internal attackers can be disgruntled employees whose knowledge makes them capable
- External attackers threat are considered high risk
What is a Vulnerability? And what are some examples? - ANSWERS-- Inherent weaknesses
within information assets that threats can exploit
- Lack of antivirus, weak hiring procedures, inadequate physical access controls