Chapter 6 Key Terms Flashcards
Access control
Access control is the ability to permit or deny access to resources on a network or computer.
Access control policy
An access control policy defines the steps and measures that are taken to control access to objects.
Access control system
An access control system includes policies, procedures, and technologies that are implemented to control access to objects.
Authentication
Authentication is the process of validating identity. It includes the identification process, a user providing input to prove identity, and the system accepting that input as valid.
Authorization
Authorization is granting or denying access to an object based on the level of permissions or the actions allowed with the object.
Auditing
Auditing, also referred to as accounting, is maintaining a record of the activity within the information system.
Objects
Objects are data, applications, systems, networks, and physical space.
Subjects
Subjects are users, applications, or processes that need access to objects.
Identification
The initial process of confirming the identity of a user requesting credentials. This occurs when a user enters a user ID at logon.
Authentication
The verification of the issued identification credentials. It is usually the second step in the identification process and establishes that you are who you say you are.
Multifactor authentication
A method of confirming identity by using two or more pieces of evidence (or factors) to an authentication mechanism.
False negative
An error that occurs when a person who should be allowed access is denied access.
False positive
An error that occurs when a person who should be denied access is allowed access.
Crossover error rate
The point at which the number of false positives matches the number of false negatives in a biometric system.
Processing rate
The number of subjects or authentication attempts that can be validated.
Authorization
The process of controlling access to resources, such as computers, files, or printers.