security Terms
Protecting information and information systems from unauthorized access, use,
disclosure, disruption, modification, or destruction - CORRECT ANSWER-Information
Security
Companies that process credit card payments must comply with this set of standards -
CORRECT ANSWER-Payment Card Industry Data Security Standard (PCI DSS)
Used to keep something private or minimally known - CORRECT
ANSWER-Confidentially
Refers to the ability to prevent our data from being changed in an unauthorized or
undesirable manner. - CORRECT ANSWER-Integrity
Refers to the ability to access our data when we need it - CORRECT
ANSWER-Availability
A type of attack, primarily against confidentiality - CORRECT ANSWER-Interception
Something that has the potential to cause harm to our assets - CORRECT
ANSWER-Threat
A weakness that can be used to harm us - CORRECT ANSWER-Vulnerability
The likelihood that something bad will happen - CORRECT ANSWER-Risk
An attack that causes our assets to become unusable or unavailable for our use, on a
temporary or permanent basis - CORRECT ANSWER-Interruption attack
An attack that involves tampering with our assets - CORRECT ANSWER-Modification
attack
A model that adds three more principles to the CIA triad: Possession or Control,
Authenticity, and Utility - CORRECT ANSWER-Parkerian hexad
,The physical disposition of the media on which the data is stored - CORRECT
ANSWER-possession or control
Allows for attribution as to the owner or creator of the data in question - CORRECT
ANSWER-Authenticity
Refers to how useful the data is to us - CORRECT ANSWER-Utility
An attack that involves generating data, processes, communications, or other similar
activities with a system - CORRECT ANSWER-Fabrication attack
One of the first and most important steps of the risk management process - CORRECT
ANSWER-Identify assets
A multilayered defense that will allow us to achieve a successful defense should one or
more of our defensive measures fail - CORRECT ANSWER-defense in depth
Based on rules, laws, policies, procedures, guidelines, and other items that are "paper"
in nature - CORRECT ANSWER-administrative controls
Sometimes called technical controls, these protect the systems, networks, and
environments that process, transmit, and store our data - CORRECT ANSWER-logical
controls
Controls that protect the physical environment in which our systems sit, or where our
data is stored - CORRECT ANSWER-physical controls
Involves putting measures in place to help ensure that a given type of threat is
accounted for - CORRECT ANSWER-migrating risk
The risk management phase that consists of all of the activities that we can perform in
advance of the incident itself, in order to better enable us to handle it - CORRECT
ANSWER-preparation phase
The risk management phase where we detect the occurrence of an issue and decide
whether it is actually an incident so that we can respond to it appropriately - CORRECT
ANSWER-detection and analysis phase
, The risk management phase where we determine specifically what happened, why it
happened, and what we can do to keep it from happening again - CORRECT
ANSWER-Post-incident activity phase
To completely remove the effects of the issue from our environment - CORRECT
ANSWER-Eradication
Taking steps to ensure that the situation does not cause any more damage than it
already has, or at the very least, lessen any ongoing harm - CORRECT
ANSWER-Containment
Restore to a better state (either to the state prior to the incident, or if we did not detect
the problem immediately, prior to when the issue started) - CORRECT
ANSWER-recover
Something that supports our claim to identity, either in our personal interactions or in
computer systems, e.g. social security cards - CORRECT ANSWER-Identity verification
Authentication requirements help prevent this crime - CORRECT ANSWER-Falsifying
identification
A set of methods we use to establish a claim of identity as being true - CORRECT
ANSWER-Authentication
A password is an example of this type of factor - CORRECT ANSWER-Something you
know
An iris scan is an example of this type of factor - CORRECT ANSWER-Something you
are
A swipe card is an example of this type of factor - CORRECT ANSWER-Something you
have
The time delay between your keystrokes is an example of this type of factor -
CORRECT ANSWER-Something you do
Being at a specific terminal is an example of this type of factor - CORRECT
ANSWER-where you are