ITSY 1300-29001 Fundamentals Of Information
Security Test Review (Questions & A+ Solutions)
Save
Terms in this set (85)
What is unauthorized is when an attacker gains your authorized access. It
access, and how can it lead allows the attacker access to everything that access
to data breaches? would have access to.
this law regulates the financial practice and governance
SOX (Sarbanes-Oxley Act)
of corporations
The Health Insurance Portability and Accountability Act,
a federal law protecting the privacy of patient-specific
HIPAA health care information and providing the patient with
control over how this information is used and
distributed.
federal info security management act - US law requires
FISMA federal agencies to create, document and implement
security program
"Graham-Leach-Bliley Act" (Financial Services
Modernization Act of 1999) repealed a 1933 law that
barred the consolidation of financial institutions and
insurance companies. Included within GLBA are multiple
GLBA
sections relating to the privacy of financial information.
Companies must provide written notice to consumers of
their privacy rights and explain the company's
procedures for safeguarding data.
Payment Card Industry Data Security Standard, a
PCI DSS security standard created by the Payment Card Industry
Security Standards Council (PCI SSC)
1974 Family Educational Rights and Privacy Act (Buckley
Amendment). Assures confidentiality of student records.
FERPA Parents are afforded rights to examine, review, request
changes if inaccurate, and stipulate person who has
access.
, Children's Internet Protection Act (2001)
The law places restrictions on the use of funding that is
available through the Library Services and Technology
Act (LSTA) of the Elementary and Secondary Education
Act (ESEA), and on the Universal Service discount
program known as the E-rate (discounts for Internet
CIPA
access or internal connections).
Requires Internet safety policies (AUPs) and technology
which blocks or filters certain material from being
accessed through the Internet.
Deadline for compliance with CIPA was July 1, 2004,
following the Supreme Court ruling in 2003.
Something an organization does to help reduce risk.
Explain what a security Examples will vary, including security awareness
control is, and list three training, IT security policy frameworks, layered security
examples. solution for IT infrastructure, periodic security risk
assessments, enabling monitoring, and so forth.
NIC Card (Network interface Card)
LAN Switch (Type I & II)
List three physical elements Wireless Access Point (WAP)
of the LAN domain. File & Print Servers
UTP
Ethernet LAN
System Admin
Design of Virtual LANs
List three logical elements Design of server disk storage space
of the LAN domain. server TCP/IP software and communication protocols
VLAN design
backup/recovery
Confidentiality, Integrity, Availability. As close to a 'code'
for Information Security as it is possible to get, it is the
What is the CIA triangle? boiled down essence of InfoSec. Confidentiality-
keeping data secure. Integrity- keeping data intact.
Availability- keeping data accessible.
Define confidentiality Confidentiality is the process of encryption
Define Integrity integrity is the process of keeping data intact
Define Availability availability is keeping data accessible.
Security Test Review (Questions & A+ Solutions)
Save
Terms in this set (85)
What is unauthorized is when an attacker gains your authorized access. It
access, and how can it lead allows the attacker access to everything that access
to data breaches? would have access to.
this law regulates the financial practice and governance
SOX (Sarbanes-Oxley Act)
of corporations
The Health Insurance Portability and Accountability Act,
a federal law protecting the privacy of patient-specific
HIPAA health care information and providing the patient with
control over how this information is used and
distributed.
federal info security management act - US law requires
FISMA federal agencies to create, document and implement
security program
"Graham-Leach-Bliley Act" (Financial Services
Modernization Act of 1999) repealed a 1933 law that
barred the consolidation of financial institutions and
insurance companies. Included within GLBA are multiple
GLBA
sections relating to the privacy of financial information.
Companies must provide written notice to consumers of
their privacy rights and explain the company's
procedures for safeguarding data.
Payment Card Industry Data Security Standard, a
PCI DSS security standard created by the Payment Card Industry
Security Standards Council (PCI SSC)
1974 Family Educational Rights and Privacy Act (Buckley
Amendment). Assures confidentiality of student records.
FERPA Parents are afforded rights to examine, review, request
changes if inaccurate, and stipulate person who has
access.
, Children's Internet Protection Act (2001)
The law places restrictions on the use of funding that is
available through the Library Services and Technology
Act (LSTA) of the Elementary and Secondary Education
Act (ESEA), and on the Universal Service discount
program known as the E-rate (discounts for Internet
CIPA
access or internal connections).
Requires Internet safety policies (AUPs) and technology
which blocks or filters certain material from being
accessed through the Internet.
Deadline for compliance with CIPA was July 1, 2004,
following the Supreme Court ruling in 2003.
Something an organization does to help reduce risk.
Explain what a security Examples will vary, including security awareness
control is, and list three training, IT security policy frameworks, layered security
examples. solution for IT infrastructure, periodic security risk
assessments, enabling monitoring, and so forth.
NIC Card (Network interface Card)
LAN Switch (Type I & II)
List three physical elements Wireless Access Point (WAP)
of the LAN domain. File & Print Servers
UTP
Ethernet LAN
System Admin
Design of Virtual LANs
List three logical elements Design of server disk storage space
of the LAN domain. server TCP/IP software and communication protocols
VLAN design
backup/recovery
Confidentiality, Integrity, Availability. As close to a 'code'
for Information Security as it is possible to get, it is the
What is the CIA triangle? boiled down essence of InfoSec. Confidentiality-
keeping data secure. Integrity- keeping data intact.
Availability- keeping data accessible.
Define confidentiality Confidentiality is the process of encryption
Define Integrity integrity is the process of keeping data intact
Define Availability availability is keeping data accessible.