Fundamentals Of Security Flashcards
What is Information Security?
Act of protecting data and information from unauthorized access, unlawful modification and disruption, disclosure, and corruption and destruction.
What is Information Systems Security?
Act of protecting the systems that hold and the process critical data
What is confidentiality?
Ensures that information is only accessible to those with the appropriate authorisation.
Confidentiality is important for 3 main reasons. What are they?
- to protect personal privacy
- to maintain business advantage
- to achieve regulatory compliance
What is a threat?
Anything that could cause harm, loss, damages or compromise to our information technology systems.
What is a vulnerability?
Any weakness in the system design or implementation.
List the 5 basics methods to ensure confidently.
- Encryption
- Access Controls
- Data Masking
- Physical Security Measures
- Training and Awareness
What is Data Masking?
Method that involves obscuring specific data within database to make it inaccessible for unauthorised
users while retaining the real data’s authenticity and for authorized users.
What is integrity?
Helps ensure that information and data remain accurate and unchanged from its original state unless intentionally modified by an authorised individual.
Integrity is important for three reasons. What are they?
- To ensure data accuracy
- To maintain trust
- To ensure the system operability
What are 5 methods utilised to maintain integrity?
- Hashing
- Digital Signature
- Checksums
- Access Controls
- Regular Audits
What is availability?
Ensuring that information, systems and resources are accessible and operational when needed by authorised users
What are the benefits of ensuring availability?
- ensuring business continuity
- maintaining customer trust
- upholding an organisations reputation
What is redundancy?
Duplication of critical components or functions of a system the intention of enhancing its reliability.
Name the 4 types of redundancy to consider
- Server redundancy
- Data redundancy
- Network redundancy
- Power redundancy
What is non-repudiation?
A security measure that ensures individuals or entities
Involved in communication or transaction cannot deny participation or authenticity of actions.
List three reasons non- repudiation is important?
- to confirm the authenticity of digital transactions
- to ensure the integrity of critical communications
- to provide accountability in digital processes