Lesson 2 Definitions Flashcards

1
Q

Sensitive Information

A

Information where the loss, misuse, or unauthorized access or modification could adversely affect the national interest or the conduct of federal programs, or the privacy to which individuals are entitled under 5 U.S.C. Section 552a (the Privacy Act).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Federal Contract Information (FCI)

A

Information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Controlled Unclassified Information (CUI)

A

Information that requires safeguarding or dissemination controls pursuant to and consistent with law, regulations, and government-wide policies, excluding information that is classified under Executive Order 13526, Classified National Security Information, December 29, 2009, or any predecessor or successor order, or the Atomic Energy Act of 1954, as amended.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Controlled Technical Information (CTI)

A

Technical Information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Export-Controlled Information (ECI)

A

Any information or material that cannot be released to foreign nationals or representatives of a foreign entity, without first obtaining approval or license from the Dept. of State for items controlled by ITAR or the Dept. of Commerce for items controlled by the Export Administration Regulations (EAR).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Covered Defense Information (CDI)

A

Terms used to identify information that requires protection under DFARS Clause 252.204-7012. Unclassified CTI or other information, as described in the CUI Registry, that requires safeguarding or dissemination controls pursuant to and consistent with the law, regulations, and government-wide policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Lawful government purpose

A

Any activity, mission, function, operation, or endeavor that the U.S. Government authorizes or recognizes as within the scope of its legal authorities or the legal authorities of non-executive branch entities (such as state and local law enforcement).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Data Integrity

A

Property that data has not been altered in an unauthorized manner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Confidentiality

A

Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Personally Identifiable Information (PII)

A

Information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a speficic individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Multifactor Authentication (MFA)

A

A mechanism that provides for added protection of data through electronic methods

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Awareness

A

A learning process that sets the state for training by changing individual and organizational attitudes to realize the importance of security and the adverse consequences of its failure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Awareness and Training Program

A

Explains proper rules of behavior for the use of agency information systems and information. The program communicates information technology (IT) security policies and procedures that need to be followed. (i.e., NSTISSD 501, NIST SP 800-50)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Configuration Management

A

A collection of activities focused on establishing and maintaining the integrity of information technology products and systems, through control of processes for initializing, changing, and monitoring the configurations of those products and systems throughout the system development life cycle.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Encryption

A

The process of changing plaintext into cipher text

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Network Segmentation

A

The use of physical devices such as firewalls or logical separation such as subnetting to create distinct segments in your internal network

17
Q

Demilitarized Zone (DMZ)

A

A small section of a private network that is located between two firewalls and made available for public access

18
Q

Dissemination control

A

Method of managing sensitive information distribution so that it doesn’t spread more widely than allowed by law, regulation, or government-wide policy

19
Q

Decontrolling CUI

A

Decontrolling occurs when an authorized holder, consistent with CUI regulations and the CUI Registry, removes safeguarding and dissemination controls from CUI that no longer requires such controls.

20
Q

Record

A

Agency records and Presidential papers or Presidential records (or Vice-Presidential), as those terms are defined in 44 U.S.C. 3301 and 44 U.S.C. 2201 and 2207. Records are also items created or maintained by a Government contractor, licensee, certificate holder, or grantee that are subject to the sponsoring agency’s control under the terms of the entity’s agreement with the agency.

21
Q

Media sanitization

A

The actions taken to render data written on media unrecoverable by both ordinary and extraordinary means.