Domain 1 Flashcards
Security Principles
Adequate Security
proper level of security that is equivalent to the level of risk potential
Administrative Controls
controls implemented through policy & procedure
Artificial Intelligence
ability of human intelligence/behavior to be replicated by computer/robots
Asset
anything of value owned by an organization & needs protection (e.g. laptop with sensitive data)
Authentication
act of identifying/verifying eligibility to access information
Authorization
right/permission granted to an entity to access a resource
Availability
principle of the CIA triad that sets the standard that data will be accessible/usable in a timely/reliable manner
Baseline
documented lowest-level of security configuration allowed by a standard &/or organization
Biometric
biological characteristics of individual. “something you are”. (e.g. fingerprint, iris scan)
Bot
malicious code that can be controlled remotely
Classified/Sensitive Information
protected information
Confidentiality
principle of the CIA triad that sets the standard that data is not made available/disclosed to unauthorized people or processes
Criticality
degree of importance/necessity of information &/or system
Data Integrity
property that data has not been altered in an unauthorized manner (in storage, processing, &/or transit)
Encryption
converting plaintext to ciphertext. “enciphering”
GDPR
General Data Protection Regulation. EU legislation passed in 2016 that defines personal privacy as an individual human right regardless of nationally
Governance
process of how an organization is managed & aspects of how decisions are made (including policies, roles, & procedures)
HIPAA
Health Insurance Portability & Accountability Act. National standards of electronic healthcare transactions while protecting PHI
Impact
magnitude of harm that could be caused by a threat exploiting a vulnerability
Information Security Risk
potential adverse impacts to an organization’s operations, assets, individuals, etc
Integrity
principle of the CIA triad that sets the standard that information maintained in a way that ensures completeness, accuracy, internal consistency, & usefulness
ISO
International Organization of Standards. Sets voluntary international standards with the IEC & ITU