Introduction Flashcards

1
Q

How do we define information security?

A

IS is about ensuring

  • Confidentiality
  • Integrity
  • Availability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Confidentiality in IS?

A

Confidentiality is the principle of restricting access to information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Integrity in IS?

A

Integrity is about preventing improper or unauthorized change of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Availability in IS?

A

Availability is about making sure that information is accessible when needed (by authorized persons)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Authentication?

A

confirming the identity of an entity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Non-Repudiation?

A

an entity’s inability to refute an earlier action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a threat?

A

a potential danger to an (information) asset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an attack?

A

an action that actually leads to a violation of security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a vulnerability?

A

a weakness that makes an attack possible

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are Security Controls?

A

mechanisms to protect information against

  • unauthorized access (ensuring confidentiality)
  • unauthorized modification (ensuring integrity)
  • destruction/denial-of-service (ensuring availability)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the three types of controls?

A
  • Physical
  • Technical
  • Administrative
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are three examples of Physical Controls?

A

locks
security guards
alarms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are three examples of Technical Controls?

A

passwords
antivirus software
encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are three examples of Administrative Controls?

A

staff training
clear responsibilities
policies and procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Why are administrative controls important?

A

Security is only as strong as the weakest link

Very often, people are the weakest link

How well did you know this?
1
Not at all
2
3
4
5
Perfectly