Fundamental of security Flashcards
this is test 1
what is Information Security
Act for protecting data and information from unauthorized access,unlawful modification and disruption,disclosure , and corruption and destruction
what is information System Security
Act for protecting the system that holds and process the critical information
confidentiality
Ensure that Information is only accessible by authorized person
integrity
Ensure that data remain accurate and unaltered unless the modification is required
Availability
Ensure that information and resources are accessible and functional when needed by by authorized users
Non-repudiation
Guaranteeing that a specific action or event has taken place and cannot be denied by parties involved
AAA of security
Authentication , Authorization , Accounting
Authorization
Permissions and privileges granted to users or entities after they have been authenticated
Accounting
Act of tracking user activities and resource usage, typically for audit or billing purposes
Security Controls
Measures or mechanisms put in place to mitigate risks and protect the confidentiality , integrity , and availability information system and data
Type of Security Controls
Technical , Managerial , Operations , Physical
Zero Trust
Security model that operates on the principle that no one , whether inside or outside the organization, should be trusted by default
Control Plane
Consists of adaptive identity, threat scope reduction,policy-driven access control,and secured zones
Data Plane
Focused on the subject / system,policy engine ,
policy administrator , and establish policy enforcement points
Data Masking
Method that involves obscuring
data within a database to make
it inaccessible for unauthorized
users while retaining the real
data’s authenticity and use
for authorize user