Lecture 1 Flashcards
What are the three fundamental principles of information security?
Confidentiality, Integrity, and Availability (CIA Triad).
What is a vulnerability in information security?
A weakness in an information system that could be exploited.
Define a security threat.
A potential event or action that could exploit a vulnerability and cause harm.
What is the principle of least privilege?
Users and systems should only have the minimal level of access necessary to perform their tasks.
What does ‘fail-safe default’ mean in security design?
Systems should default to a secure state when an error occurs.
Why is ‘separation of privilege’ important?
It ensures that no single entity has complete control over a system, reducing risk.
Name two types of security mechanisms mentioned in the lecture.
Access control and authentication.
What is non-repudiation in security?
Ensuring that an entity cannot deny its actions.
Give an example of a modern security concern related to IoT.
Smart devices being hacked, such as microphones being turned into surveillance devices.
What is GDPR?
The General Data Protection Regulation, which strengthens data protection laws in the EU.