Computer Security Principles and Terminology Flashcards
Computer Security definition
measures and controls that ensure confidentiality, integrity, and availability of information processed and stored by a computer, including software, hardware, firmware, information data, and telecommunications
Essential Network and Computer Security Requirements
Confidentiality
Integrity
Availability
Accountability
Authenticity
Confidentiality
The preservation of authorized restrictions on information access and disclosure (protecting personal privacy and proprietary information)
Integrity
Guarding against improper information modification or destruction, including ensuring information nonrepudiation and authenticity
Availability
ensuring timely and reliable access to and use of information
Low Impact
limited adverse effect on the effected (organizations, individuals)
Moderate Impact
Serious adverse effect on the effected
High
Severe or catastrophic adverse effect
Adversary (threat agent)
Individual, group, organization, or government that conducts or has the intent to conduct detrimental activities
Attack
Any kind of malicious activity that attempts to collect, disrupt, deny, degrade, or destroy information system resources or the information itself
Countermeasure
A device or technique that has as its objective the impairment of the operational effectiveness of undesirable or adversarial activity, or the prevention of espionage, sabotage, theft, or unauthorized access to or use of sensitive information or information systems
Risk
A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of 1) the adverse impacts that would arise if the circumstance or event occurs; and 2) the likelihood of occurrence
Security Policy
A set of criteria for the provision of security services. It defines and constrains the activities of a data processing facility in order to maintain a condition of security for systems and data
System Resource (Asset)
A major application, general support system, high impact program, physical plant, mission critical system, personnel, equipment, or a logically related group of systems
Threat
Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation through a information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service