Security Principles Chapter 1 Questions And
Correct Answers
Adequate Security - Answer Security commensurate with the risk and magnitude of
harm resulting from the loss, misuse, or unauthorized access to or modification of
information. Source: OMB Circular A-130
Administrative Controls-Answer Controls implemented through policy and procedures.
Examples include access control processes and requiring multiple personnel to conduct
a specific operation. Administrative controls in modern environments are very often
enacted in concert with physical and/or technical controls, an example of which would
be an access-granting policy for new users that requires login and approval by the
hiring manager.
Artificial Intelligence The ability of computers and robots to simulate human thought
processes and behavior.
Asset Anything of value owned by an organization. Assets include both physical items
such as information systems and other physical property, and intangible assets such as
intellectual property.
Authentication - The process by which the eligibility of a station, originator, or individual
to have access to specific categories of information is verified. Usually a security
measure intended to protect against false transmissions by establishing the validity of a
transmission, message, station, or originator.
Authorization- The permission or right granted to a system entity to have access to a
system resource. NIST 800-82 Rev.2
Availability - Answer Timely and reliable accessibility and use of information by
authorized users.
, Baseline - Answer Formal, documented minimum level of security configuration of an
information system that can be permitted by a standard or organization.
Biometric -Answer A personal characteristic or trait that distinguishes an individual,
such as fingerprint, hand geometry, voice, or iris patterns
Bot - Answer A malicious code that acts as a remotely controlled "robot" for an
attacker, but also has other Trojan and worm capabilities.
Classified or Sensitive Information - Answer Information that has been determined to
require protection against unauthorized disclosure and is marked to indicate its
classified status and classification level when in documentary form.
Confidentiality - Answer The characteristic of data or information when it is not made
available or disclosed to unauthorized persons or processes. NIST 800-66
Criticality - A measure of the extent to which an organization is dependent on the
information or information system in accomplishing a mission or business function. NIST
SP 800-60 Vol. 1, Rev. 1
Data Integrity - Answer The property that data has not been altered in an unauthorized
way. Data integrity covers data in storage, during processing and while in transit.
Source: NIST SP 800-27 Rev A
Encryption - Answer The process and act of converting the message from its plaintext to
ciphertext. Sometimes it is also referred to as enciphering. Both terms in some literature
are used synonymously, with similar meanings.
General Data Protection Regulation (GDPR) - Answer In 2016, the European Union
passed comprehensive legislation that addresses personal privacy, deeming it an
individual human right.
Governance - Answer How an organization is controlled; typically includes all elements
Correct Answers
Adequate Security - Answer Security commensurate with the risk and magnitude of
harm resulting from the loss, misuse, or unauthorized access to or modification of
information. Source: OMB Circular A-130
Administrative Controls-Answer Controls implemented through policy and procedures.
Examples include access control processes and requiring multiple personnel to conduct
a specific operation. Administrative controls in modern environments are very often
enacted in concert with physical and/or technical controls, an example of which would
be an access-granting policy for new users that requires login and approval by the
hiring manager.
Artificial Intelligence The ability of computers and robots to simulate human thought
processes and behavior.
Asset Anything of value owned by an organization. Assets include both physical items
such as information systems and other physical property, and intangible assets such as
intellectual property.
Authentication - The process by which the eligibility of a station, originator, or individual
to have access to specific categories of information is verified. Usually a security
measure intended to protect against false transmissions by establishing the validity of a
transmission, message, station, or originator.
Authorization- The permission or right granted to a system entity to have access to a
system resource. NIST 800-82 Rev.2
Availability - Answer Timely and reliable accessibility and use of information by
authorized users.
, Baseline - Answer Formal, documented minimum level of security configuration of an
information system that can be permitted by a standard or organization.
Biometric -Answer A personal characteristic or trait that distinguishes an individual,
such as fingerprint, hand geometry, voice, or iris patterns
Bot - Answer A malicious code that acts as a remotely controlled "robot" for an
attacker, but also has other Trojan and worm capabilities.
Classified or Sensitive Information - Answer Information that has been determined to
require protection against unauthorized disclosure and is marked to indicate its
classified status and classification level when in documentary form.
Confidentiality - Answer The characteristic of data or information when it is not made
available or disclosed to unauthorized persons or processes. NIST 800-66
Criticality - A measure of the extent to which an organization is dependent on the
information or information system in accomplishing a mission or business function. NIST
SP 800-60 Vol. 1, Rev. 1
Data Integrity - Answer The property that data has not been altered in an unauthorized
way. Data integrity covers data in storage, during processing and while in transit.
Source: NIST SP 800-27 Rev A
Encryption - Answer The process and act of converting the message from its plaintext to
ciphertext. Sometimes it is also referred to as enciphering. Both terms in some literature
are used synonymously, with similar meanings.
General Data Protection Regulation (GDPR) - Answer In 2016, the European Union
passed comprehensive legislation that addresses personal privacy, deeming it an
individual human right.
Governance - Answer How an organization is controlled; typically includes all elements