Modules Flashcards

1
Q

What does CIA stand for?

A

Confidentiality, Integrity, and Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define Confidentiality

A

Confidentiality relates to permitting authorized access to information, while at the same time protecting information from improper disclosure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define Availability

A

Availability means that systems and data are accessible at the time users need them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define Integrity

A

Integrity is the property of information whereby it is recorded, used and maintained in a way that ensures its completeness, accuracy, internal consistency and usefulness for a stated purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the security professional’s obligation?

A

to regulate access—protect the data that needs protection yet permit access to authorized individuals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Confidentiality is a difficult balance to achieve because

A

When many system users are guests or customers, and it is not known if they are accessing the system from a compromised machine or vulnerable mobile application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Personally Identifiable Information (PII)?

A

It is a term related to the area of confidentiality. It pertains to any data about an individual that could be used to identify them. 

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Other terms related to confidentiality are….

A

protected health information (PHI), which is information regarding one’s health status, andclassified or sensitive information, which includes trade secrets, research, business plans and intellectual property

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is sensitivity?

A

a measure of the importance assigned to information by its owner, or the purpose of denoting its need for protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is sensitive information?

A

information that if improperly disclosed (confidentiality) or modified (integrity) would harm an organization or individual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Example of sensitive information:

A

In many cases, sensitivity is related to the harm to external stakeholders; that is, people or organizations that may not be a part of the organization that processes or uses the information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How does the National Institute of Standards and Technology (NIST) define confidentiality?

A

It is the characteristic of data or information when it is not made available or disclosed to unauthorized persons or processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Personally Identifiable Information (PII)?

A

Any information that can be used to distinguish or trace an individual’s identity, such as name, Social Security number, date and place of birth, mother’s maiden name, or biometric records; and any other information that is linked or linkable to an individual, such as medical, educational, financial and employment information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

protected health information (PHI)

A

Information regarding health status, the provision of healthcare or payment for healthcare as defined in HIPAA (Health Insurance Portability and Accountability Act).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

classified or sensitive information

A

Information that has been determined to require protection against unauthorized disclosure and is marked to indicate its classified status and classification level when in documentary form.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

sensitivity

A

A measure of the importance assigned to information by its owner, for the purpose of denoting its need for protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Integrity 

A

measures the degree to which something is whole and complete, internally consistent and correct

15
Q

The concept of integrity applies to:

A
  • information or data
  • systems and processes for business operations
  • organizations
  • people and their actions
16
Q

Data integrity

A

the assurance that data has not been altered in an unauthorized manner

17
Q

What requires the protection of the data in systems and during processing to ensure that it is free from improper modification, errors or loss of information and is recorded, used and maintained in a way that ensures its completeness?

A

Data Integrity

18
Q

What does data integrity cover?

A

Data integrity covers data in storage, during processing and while in transit.

19
Q

Information must be

A

accurate, internally consistent and useful for a stated purpose.

20
Q

The ________________ of information ensures that information is correct on all related systems so that it is displayed and stored in the same way on all systems.

A

internal consistency

21
Q

__________________, as part of data integrity, requires that all instances of the data be identical in form, content and meaning.

A

Consistency

22
Q

What refers to the maintenance of a known good configuration and expected operational function as the system processes the information?

A

System integrity

23
Q

Ensuring integrity begins with an awareness of__________, which is the current condition of the system.

A

state

24
Q

Specifically, this awareness concerns the ability to document and understand the state of data or a system at a certain point, creating a ___________.

A

baseline

25
Q

For example, abaselinecan refer to the current state of the information—whether it is protected. Then, to preserve that state, the information must always continue to be protected through a _____________.

A

transaction

26
Q

If the baseline matches the current state, then……….

A

the integrity of the data or the system is intact

27
Q

If the baseline doesn’t match the current state then………

A

the integrity of the data or the system has been compromised

28
Q

Going forward from that baseline, the integrity of the data or the system can always be ascertained by comparing what?

A

the baseline with the current state

29
Q

___________ is a primary factor in the reliability of information and systems.

A

Integrity

30
Q

The need to safeguard information and system integrity may be dictated by………

A

laws and regulations.

31
Q

Often, it is dictated by the needs of the organization to access and use what?

A

reliable, accurate information

32
Q

Data integrity

A

The property that data has not been altered in an unauthorized manner. Data Integrity covers data in storage, during processing and while in transit.

33
Q

System integrity

A

The quality that a system has when it performs its intended function in an unimpaired manner, free from unauthorized manipulation of the system, whether intentional or accidental.

34
Q

state

A

The condition an entity is in at a point in time.

35
Q

baseline

A

A documented, lowest level of security configuration allowed by a standard or organization.

36
Q

Availability can be defined as

A

(1) timely and reliable access to information and the ability to use it

(2) for authorized users, timely and reliable access to data and information services

37
Q

What is the core concept of availability?

A

Data is accessible to authorized users when and where it is needed and, in the form, and format required.

This does not mean that data or systems are available 100% of the time. Instead, the systems and data meet the requirements of the business for timely and reliable access.

38
Q

Some systems and data are far more critical than others, so the security professional must ensure that

A

the appropriate levels of availability are provided.

39
Q
A