Introduction Flashcards
How do we define information security?
IS is about ensuring
- Confidentiality
- Integrity
- Availability
What is Confidentiality in IS?
Confidentiality is the principle of restricting access to information
What is Integrity in IS?
Integrity is about preventing improper or unauthorized change of data
What is Availability in IS?
Availability is about making sure that information is accessible when needed (by authorized persons)
What is Authentication?
confirming the identity of an entity
What is Non-Repudiation?
an entity’s inability to refute an earlier action
What is a threat?
a potential danger to an (information) asset
What is an attack?
an action that actually leads to a violation of security
What is a vulnerability?
a weakness that makes an attack possible
What are Security Controls?
mechanisms to protect information against
- unauthorized access (ensuring confidentiality)
- unauthorized modification (ensuring integrity)
- destruction/denial-of-service (ensuring availability)
What are the three types of controls?
- Physical
- Technical
- Administrative
What are three examples of Physical Controls?
locks
security guards
alarms
What are three examples of Technical Controls?
passwords
antivirus software
encryption
What are three examples of Administrative Controls?
staff training
clear responsibilities
policies and procedures
Why are administrative controls important?
Security is only as strong as the weakest link
Very often, people are the weakest link