WorksheetsIAS Midterm Reviewer
Total questions: 72
Worksheet time: 39mins
Protection of the confidentiality, integrity, and availability of information assets, whether in storage, processing, or transmission, via the application of policy, education, training and awareness, and technology.
The quality or state of being secure to be free from danger or harm
security
confidentiality
A model designed to guide policies for information security within an organization.
Software Assurance
NIST Approach
C.A.I Triangle
C.I.A Triangle
Ensures that only users with the rights, privileges, and need to access information are able to do so.
(a)
Whole, complete, and uncorrupted
Availability
Confidentiality
Enables authorized users—people or computer systems—to access information without interference or obstruction and to receive it in the required format.
Confidentiality
Quality
Integrity
Ensures that only users with the rights, privileges, and need to access information are able to do so.
Confidentiality
Integrity
Availability
Quality
It places the responsibility of successful information security on a single staff member or security department.
Bottom-Up Approach
Top-Down Approach
It is initiated by upper management who issue policy, procedures, and processes, dictate goals and expected outcomes of project.
Top-Down Approach
Bottom-Up Approach
A methodological approach to the development of software that seeks to build security into the development life cycle rather than address it at later stages
Software Assurance (SA)
It adopted a simplified SLDC for their approach, based on five phases: initiation, development/acquisition/implementation/assessment, operation/maintenance, and disposal.
NIST Approach
Software Assurance (SA)
Security Systems Development Life Cycle
CIO stands for
(a)
CISO stands for
(a)
The senior technology officer responsible for advising senior executives on strategic planning
Primarily responsible for assessment, management, and implementation of IS in the organization.
Chief Information Security Officer (CISO)
A number of individuals who are experienced in one or more facets of required technical and nontechnical areas.
Information Security Project Team
Team of Experts
Senior Experts
Responsible for the security and use of a particular set of information.
Data Custodian
Data Owner
Responsible for storage, maintenance, and protection of information
Data Custodian
Data Owner
End users who work with information to perform their daily jobs supporting the mission of the organization.
Data Custodian
Data Analyst
Data Users
It is based on the way individuals perceive systems technologists since computers became commonplace.
“Security Artisan” Idea
“Authority Artisan” Idea
“Service Artisan” Idea
A website hosted by Mitre that serves as a tool that security professionals can use to understand attacks.
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Security Pattern Enumeration and Classification (CSPEC)
Common Attack Pattern Information and Classification (CAPIC)
The unauthorized duplication, installation, or distribution of copyrighted computer software, which is a violation of intellectual property.
When an unauthorized person gains access to information an organization is trying to protect.
Espionage or Trespass
A person who stealthily manipulates a maze of computer networks, systems, and data to find information.
Master of several programming languages, networking protocols, and operating systems, and exhibits a mastery of the technical environment of the chosen targeted system.
Decoder
Cracker
Expert Hacker
Cybersecurity Hacker
Commonly associated with software copyright bypassing and password decryption.
cracker
The application of computing and network resources to try every possible password combination.
A variation of the brute force attack that narrows the field by using a dictionary of common passwords and includes information related to the target user.
Hash values are used to gain access to an encrypted password file
Dictionary Attacks
Rainbow Tables
Brute Force
Social Engineering Password Attacks
Human error or failure is used as a mechanism to gain password information
Phishing attack
Shoulder surfing attack
Malware attack
Social engineering password attack
It is called “acts of God” as it presents the most dangerous threats that occur with little warning and beyond control of people.
Forces of nature
Acts performed without intent or malicious purpose or in ignorance by an authorized user.
Human Error of Failure
It is called cyberextortion and common in the theft pf credit card numbers.
Cyberextortion
Information Extortion
to destroy an asset or damage the image of an organization
Accessing systems and damaging destroying critical data.
Online Activism
Unlawful attacks and threats of attacks against computers, networks and the information stored therein when done to intimidate or coerce a government or its people in furtherance of political or social objectives.
Online Activism
Leveraging social media to perform fundraising, raise awareness of social issues, gather support for legitimate causes, and promote involvement.
Positive Online Activism
It consists of specially crafted software that attackers trick users into installing on their systems to overwhelm the processing capabilities of online systems or to gain access to protected systems by hidden means.
Software Attacks
Occur when a manufacturer distributes equipment containing defects that can cause the system to perform outside of expected parameters, resulting in unreliable service or lack of availability.
Technical Hardware Failures
Purposeful shortcuts perceived as bugs or errors left by programmers for benign or malign reasons.
Technical Hardware Failures
Technical Software Failures
The legal obligation of an entity extending beyond criminal or contract law; includes the legal obligation to make restitution.
Policy
Liability
Jurisdiction
Due Care
The legal standard requiring a prudent organization to act legally and ethically and know the consequences of actions.
Due care
Due Diligence
The court’s right to hear a case if the wrong was committed in its territory or involved its citizenry.
It functions as organizational laws that must be crafted and implemented with care to ensure they are complete, appropriate, and fairly applied to everyone.
(a)
Strongly promotes education and provides discounts for student members.
Association of Computing Machinery (ACM)
International Information Systems Security Certification Consortium, Inc. (ISC)
System Administration, Networking, and Security (SANS) Institute
Information Systems Audit and Control Association (ISACA)
Focuses on the development and implementation of information security certifications and credentials.
International Information Systems Security Certification Consortium, Inc. (ISC)
System Administration, Networking, and Security (SANS) Institute
Information Systems Audit and Control Association (ISACA)
Association of Computing Machinery (ACM)
Professional research and education cooperative organization that offers a set of certifications called the Global Information Assurance Certification (GIAC).
System Administration, Networking, and Security (SANS) Institute
Information Systems Audit and Control Association (ISACA)
Information Systems Security Association (ISSA)
Provides IT control practices and standards, and includes many information security components within its areas of concentration.
Information Systems Audit and Control Association (ISACA)
System Administration, Networking, and Security (SANS) Institute
Information Systems Security Association (ISSA)
Its primary mission is to bring together qualified information security practitioners for information exchange and educational development.
Information Systems Security Association (ISSA)
Information Systems Audit and Control Association (ISACA)
. System Administration, Networking, and Security (SANS) Institute
It sets the long-term direction to be taken by the organization and each of its component parts.
It focuses on short-term undertakings that will be completed within one or two years.
Strategic Planning
Tactical Planning
It is derived from tactical planning to organize the ongoing, day-to-day performance of tasks.
It represents the strategic controlling function of an organization’s senior management, which is designed to ensure informed, prudent strategic decisions made in the best interest of the organization.
(a)
According to Information Technology Governance Institute (ITGI), it includes all of the accountabilities and methods undertaken by the board of directors and executive management.
Information Security Operations
Information Security Governance
Information Security Management
Oversee overall corporate security posture
Chief Executive Officer
Chief Security Officer
Chief Information Officer
Standards in actuality, are adopted widely by an industry and its customers.
De facto Standards
De jure Standards
Facto Standards
Standards that are according to law and endorsed by a formal standards organization.
De facto standards
De jure standards
Jure Standards
Facto Standards
also known as general security policy, organizational security policy, IT security policy, or information security policy.
Enterprise Information Security Policy
Issue-specific Security Policy
Systems-Specific Security Policy
It requires frequent updates, and contains a statement about the organization’s position on a specific issue.
Issue-specific Security Policy
Systems-Specific Security Policy
Enterprise Information Security Policy
It functions as standards or procedures to be used when configuring or maintaining systems.
Systems-Specific Security Policy
Issue-specific Security Policy
Enterprise Information Security Policy
It is the responsibility of the CISO and is a control measure designed to reduce incidents of accidental security breaches by employees
Security Education, Training and Awareness (SETA) Program
Contingency Planning (CP)
Business Impact Analysis (BIA)
Disaster Recovery Planning (DR)
It provides strategic planning to assure the continuous availability of information systems and in preparation for adverse events that become incidents or disasters.
Contingency Planning (CP)
Business Impact Analysis (BIA)
Disaster Recovery Planning (DR)
Crisis Management
A systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident or emergency.
The process of preparing an organization to handle a disaster and recover from it, whether the disaster is natural or man-made.
Disaster Recovery Planning (DR)
Business Continuity Planning
Crisis Management
prepares an organization to reestablish or relocate critical business operations during a disaster that affects operations at the primary site.
Business Continuity Planning
Disaster Recovery Planning (DR)
Business Impact Analysis (BIA)
Crisis Management
It focuses first and foremost on the people involved.
Risk Identification
Risk Assessment
Risk Control
Determination of the extent to which the organization’s information assets are exposed or at risk.
Risk Identification
Risk Control
Risk Assessment
Application of controls to reduce the risks to an organization’s data and information systems.
Risk Assessment
Risk Control
Risk Identification
Describes an assessment of the likelihood of an attack combined with its expected probability of success if it targets your organization (attack success probability).
Loss Frequency
Determining how much of an information asset could be lost in a successful attack.
Loss Magnitude
Loss Event Frequency
Attack Success Probability
Process of seeking out and studying the practices used in other organizations that product
(a)
Sometimes enforced in civil courts, where large damages can be awarded to plaintiffs who bring suits against organizations.
Law
Policy
Lawsuits
