Information Security Flashcards
What is the Primary Objective to information security?
To Ensure the Confidentiality, Integrity, and Availability of electronic info and resources
Information Security wants to make sure these things are as strong as possible
What is the Info Security Triad?
Confidentiality
Integrity
Availability
What is meant by Confidentiality?
Limiting the access of information to a select group of people
how much protection should be applied for who should have access to your info
What is meant by Integrity?
Make sure the info and info systems are running the way that they should be, and are not corrupted by unauthorized changes
What is meant by Security?
You want the info and info systems to be available to authorized users when they want/need it
What are Vulnerabilities?
any security laps or weakness with people, hardware, software or architecture
What are Threats?
the source of the bad stuff, anything that can mess up our C.I.A.
What are Risks?
Overall equation, involving threats and vulnerabilities and safeguards put in place and you get a risk picture, overall picture of likelihood of something bad happening
What is Defense in Depth?
Preparing/Taking Security Measures
the best way to approach info security is to follow a multi-faceted model, often called Defense in Depth
Various models exists (DOD, NSA)
What are the 2 Advantages of Defense in Depth?
- Help you make better decision with asset allocation
2. Make sure you don’t overlook something