LO1 Flashcards
Understand what is meant by cyber security.
Confidentiality
Information that is protected against unintended or unauthorised access. Rules which restrict access only to those who need to know.
Availability
The level of assurance that the data will be available to those who need it, when they want it.
E.g. Patients medical records are available if they are to come into A & E and need treatment.
Integrity
The level of assurance that the data available is accurate and up to date
Cyber security incident
An unwanted/unexpected event, such as an intrusion into a computer system/network, such as the spread of malware.
Unauthorised access
Activity intended to gain access to data, networks, computer system hardware or software without the permission of the owner or other responsible individuals or organisations.
Information Disclosure
Allowing information to pass to any person or organisation without permission from the owner.
Modification of Data
Data is entered, amended, stored and deleted by those with authorisation. Done by accident or on purpose.
Unauthorised inspection
Reviewing or reading data without permission from the appropriate owner.
Data destruction
Data is intentionally destroyed
Hacking
Gaining access to systems/data that you are not allowed to have access to. Any way that is possible rather than being given a legitimate username and password.
Escalation of privileges (Vertical)
The invader obtains or legally obtains access to a system (low level access). By finding a flaw in the system they are able to increase their access level and therefore access to data.
Escalation of privileges (Horizontal)
The invader does not add higher levels of access but gains access through normal users areas.
For example a stolen username and password.
Inaccessible data
This is restricting the access to data.
Most accounts will have an automatic lock out feature meaning after multiple attempts of username and password combinations will result automatic account lockout.
Disclosure of Government Information
The regulation on what and how information from the government can be shared.
We have both the Official Secrets Act and the Freedom of information legislation which both impact how we gain access to information.
Official Secrets Act
States it is illegal to disclose government information that is in the interests of security within the country