Session 01 : Intro to IS Flashcards

1
Q

Elements of Information Security?

A
  1. Confidentiality : authorized to have access
  2. Integrity : trustworthiness of Data of resources
  3. Availability : available when required
  4. Authenticity : quality of being genuine
  5. Non-Repudiation : Guarantee or Assurance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are Information Security Threats?

A

Potential events circumstances that can cause harm to an organziation information system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Types of Cyber Security Threats?

A
  1. Malware attacks
  2. Phishing
  3. DOS attack
  4. Insider threats
  5. APTs (Advanced Presistent Threats)
    an intruder gains access to a network and remains undetected for an extended period to steal data or distrupt operations.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are vulnerabilities?

A

Weaknesses or flaws in a system whether in software, hardware, or organizational processes that can be exploited by attackers to compromise security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Common Cybersecurity Vulnerabilities?

A
  1. Outdated SW
  2. Weak Credentials
  3. Misconfigurations
  4. Zero-Day Vulnerabilities
  5. Poor Input Sanitization
  6. Unsecured APIs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

3 primary conditions must be existing for a successful attack?

A

Attack = Motive(goal) + Method + Vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Classification of attacks?

A
  • Passive Attacks
  • Active Attacks
  • Close-in Attacks
  • Insider Attacks
  • Distribution Attacks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Information Security Risk Management?

A

The process of identifying, assessing, and managing risks that could threaten an organization’s information assets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

IS Risk Management Phases?

A
  1. Risk identification
  2. Risk assessment
  3. Risk treatment
  4. Risk monitoring and review
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Methodologies for IS risk management?

A
  1. ISO/IEC 27001
  2. NIST SP 800-30
How well did you know this?
1
Not at all
2
3
4
5
Perfectly