Font size
WorksheetsIAS 1
Total questions: 78
Worksheet time: 1hrs 18mins
First operating system created with security as its primary goal
(a)
The quality or state of being secure—to be free from danger
(a)
he protection of all communications media, technology, and content
(a)
A subset of communications security; the protection of voice and data networking components, connections, and content
(a)
Protection of the confidentiality, integrity, and availability of information assets
(a)
subject or object’s ability to use, manipulate, modify, or affect another subject or object
(a)
the organizational resource that is being protected
(a)
an intentional or unintentional act that can damage or otherwise compromise information and the systems that support it
(a)
Security mechanisms, policies, or procedures that can successfully counter attacks, reduce risk, resolve vulnerabilities, and otherwise improve security within an organization.
(a)
² A technique used to compromise a system
(a)
² A condition or state of being exposed; in information security, exposure exists when a vulnerability is known to an attacker
(a)
A single instance of an information asset suffering damage or destruction, unintended or unauthorized modification or disclosure, or denial of use
(a)
² The entire set of controls and safeguards, including policy, education, training and awareness, and technology, that the organization implements to protect the asset
(a)
² The probability of an unwanted occurrence, such as an adverse event or loss
(a)
² the quantity and nature of risk they are willing to accept
(a)
² Any event or circumstance that has the potential to adversely affect operations and assets
(a)
² The specific instance or a component of a threat
(a)
² An occurrence of an event caused by a threat agent
(a)
A category of objects, people, or other entities that represents the origin of danger to an asset—in other words, a category of threat agents
(a)
² A potential weakness in an asset or its defensive control system(s)
(a)
² Computer is used as an active tool to conduct attack
(a)
Computer is the entity being attacked
(a)
² describes how data is genuine or original rather than reproduced or fabricated
(a)
² an attribute of information that describes how data is accessible and correctly formatted for use without interference or obstruction.
(a)
² describes how data is free of errors and has the value that the user expects.
(a)
² describes how data is protected from disclosure or exposure to unauthorized individuals or systems.
(a)
² describes how data is whole, complete, and uncorrupted
(a)
² how data has value or usefulness for an end purpose.
(a)
² how the data’s ownership or control is legitimate or authorized.
(a)
ü entire set of components necessary to use information as a resource in the organization
(a)
ü The protection of physical items, objects, or areas from unauthorized access and misuse.
(a)
² includes applications (programs), operating systems, and assorted command utilities.
(a)
² physical technology that houses and executes the software, stores and transports the data, and provides interfaces for the entry and removal of information from the system
(a)
² stored, processed, and transmitted by a computer system must be protected
(a)
² always been a threat to information security
(a)
² written instructions for accomplishing a specific task.
(a)
² created much of the need for increased computer and information security
(a)
ü A method of establishing security policies and/or practices that begins as a grassroots effort in which systems administrators attempt to improve the security of their systems.
(a)
dictate the nature and types of systems development activities that will be used
(a)
ü systems owners and software developers would collaborate to define specifications and create systems
(a)
ü increase the speed at which requirements were collected and software was prototyped, thus allowing more iterations in the design process
(a)
ü focuses on integrating the need for the development team to provide iterative and rapid improvements to system functionality and the need for the operations team to improve security and minimize the disruption from software release cycles
(a)
ü a process of using the DevOps methodologies of an integrated development and operations approach that is applied to the specification, creation, and implementation of security control systems.
(a)
² Methodology for design and implementation of information system
(a)
² Formal approach to problem solving based on structured sequence of procedures
(a)
² A type of SDLC in which each phase of the process “flows from” the information gained in the previous phase, with multiple opportunities to return to previous phases and make adjustments.
(a)
² At the end of each phase of the traditional SDLC comes a _____ or _____
(a)
ü What problem is the system being developed to solve?
(a)
ü Consists of assessments of:
² The organization
² Current systems
² Capability to support proposed systems
(a)
ü Blueprint for the designed solution
ü Necessary data support and structures identified
ü Technologies to implement physical solution determined
(a)
ü Technologies to support the alternatives identified and evaluated in the logical design are selected
(a)
ü Needed software created
(a)
ü Longest and most expensive phase
(a)
A methodological approach to the development of software that seeks to build security into the development life cycle rather than address it at later stages
(a)
ü Identifies process, outcomes, goals, and constraints of the project (SecSDLC)
(a)
SecSDLC
ü Documents from investigation phase are studied
ü Analysis of existing security policies or programs
ü Analysis of documented current threats and associated controls
ü Analysis of relevant legal issues that could impact design of the security solution
(a)
Creates and develops blueprints for information security (SecSDLC)
(a)
ü Needed security technology is evaluated (SecSDLC)
(a)
Security solutions are acquired, tested, implemented, and tested again (SecSDLC)
(a)
ü Perhaps the most important phase, given the everchanging threat environment (SecSDLC)
(a)
ü security considerations are key to diligent and early integration, thereby ensuring that threats, requirements, and potential constraints in functionality and integration are considered. (NIST)
(a)
This section addresses security considerations unique to the second SDLC phase (NIST)
(a)
ü During this phase, the system will be installed and evaluated in the organization’s operational environment.
(a)
systems are in place and operating, enhancements and/or modifications to the system are developed and tested, and hardware and/or software is added or replaced.
(a)
provides for disposal of a system and closeout of any contracts in plac
(a)
translates the strategic plans of the organization as a whole into strategic information plans for the information systems or data processing division of the organization
² An executive-level position that oversees the organization’s computing technology and strives to create efficiency in the processing and access of the organization’s information.
(a)
² Primarily responsible for assessment, management, and implementation of IS in the organization
(a)
ü A number of individuals who are experienced in one or more facets of required technical and nontechnical areas:
(a)
² A senior executive who promotes the project and ensures its support, both financially and administratively, at the highest levels of the organization.
(a)
² A project manager who may also be a departmental line manager or staff unit manager, and who understands project management, personnel management, and information security technical requirements.
(a)
² People who understand the organizational culture, existing policies, and requirements for developing and implementing successful policies.
(a)
² People who understand financial risk assessment techniques, the value of organizational assets, and the security methods to be used.
(a)
² Dedicated, trained, and well-educated specialists in all aspects of information security from both a technical and nontechnical standpoint
(a)
² people with the primary responsibility for administering systems that house the information used by the organization.
(a)
Those whom the new system will most directly affect
(a)
² responsible for the security and use of a particular set of information
(a)
² responsible for storage, maintenance, and protection of information
(a)
² end users who work with information to perform their daily jobs supporting the mission of the organization
(a)
