Font size
WorksheetsIT 323 Reviewer
Total questions: 91
Worksheet time: 1hrs 3mins
a “well-informed sense of assurance that the information risks and controls are in balance.”
Security professionals must review the origins of this field to understand its impact on our understanding of information security today
(a)
Original communication by mailing tapes
Advanced Research Project Agency (ARPA)
Examined feasibility of redundant networked communications
Larry Roberts developed ARPANET from its inception
ARPANET is predecessor to the Internet
(a)
ARPANET grew in popularity
Potential for misuse grew
Fundamental problems with ARPANET security
Individual remote sites were not secure from unauthorized users
Vulnerability of password structure and formats
(a)
Early focus of computer security research
System called Multiplexed Information and Computing Service
First operating system created with security as its primary goal
Mainframe, time-sharing OS developed in mid-1960s
GE, Bell Labs, and MIX
(a)
Networks of computers became more common
Need to interconnect networks grew
Internet became first manifestation of a global network of networks
Initially based on de facto standards
In early Internet deployments, security was treated as a low priority
(a)
Millions of computer networks communicate
Many of the communication unsecured
Ability to secure a computer’s data influenced by the security of every computer to which it is connected
Growing threat of cyber attacks has increased the need for improved security
(a)
- The quality or state of being secure—to be free from danger
- protection of information and its critical elements
(a)
The protection of all communications media, technology, and content.
(a)
Protection of the confidentiality, integrity, and availability of information assets, whether in storage, processing, or transmission, via the application of policy, education, training and awareness, and technology.
(a)
need to secure the physical location of computer technology from outside threats.
(a)
A subset of communications security; the protection of voice and data networking components, connections, and content.
(a)
A subject or object’s ability to use, manipulate, modify, or affect another subject or object.
(a)
This is type of Key IS Concepts which organizational resource that is being protected.
(a)
Type of Key IS Concept which an intentional or unintentional act that can damage or otherwise compromise information and the systems that support it.
(a)
This is Type of Key IS Concepts which a technique used to compromise a system.
(a)
Type of Key IS Concept which the single instance of an information asset suffering damage or destruction, unintended or unauthorized modification or disclosure, or denial of use
(a)
The probability of an unwanted occurrence, such as an adverse event or loss.
(a)
A condition or state of being exposed; in information security, exposure
exists when a vulnerability is known to an attacker.
(a)
The entire set of controls and safeguards, including policy, education, training and awareness, and technology, that the organization implements to protect the asset.
The terms are sometimes used interchangeably with the term security program, although a security program often comprises managerial aspects of security, including planning, personnel, and subordinate programs.
(a)
A computer can be either the subject of an attack—an agent entity used to conduct the attack—or the object of an attack: the target entity.
A computer can also be both the subject and object of an attack. For example, it can be compromised by an attack (object) and then used to attack other systems (subject).
(a)
Any event or circumstance that has the potential to adversely affect operations and assets.
The term threat source is commonly used interchangeably with the more generic term threat.
While the two terms are technically distinct, in order to simplify discussion, the text will continue to use the term threat to describe threat sources.
(a)
The specific instance or a component of a threat.
(a)
A potential weakness in an asset or its defensive control system(s).
For example, a flaw in a software package, an unprotected system
port, and an unlocked door. Some well-known vulnerabilities have been examined,
documented, and published; others remain latent (or undiscovered).
(a)
entire set of components necessary to use information as a resource in the organization: Software, Hardware, Data, People, Procedures and Networks.
(a)
Securing information assets is an incremental process that requires coordination, time, and patience. Information security can begin as a grassroots effort in which systems administrators attempt to improve the security of their systems
Bottom-Up Approach
Top-Down Approach
The most successful approach in information security implementations initiated by upper management that dictates the goals and expected outcomes of the project.
Bottom-Up Approach
Top-Down Approach
Methodology for design and implementation of information system
(a)
Formal approach to problem solving based on structured sequence of procedures.
(a)
What problem is the system being developed to solve?
Objectives, constraints, and scope of project specified
Preliminary cost-benefit analysis developed
(a)
A type of SDLC in which each phase of the process “flows from” the information gained in the previous phase, with multiple opportunities to return to previous phases and make adjustments.
(a)
begins with the information gained during the investigation phase. This phase consists primarily of assessments of the organization, its current systems, and its capability to support the proposed systems.
(a)
the information gained from the analysis phase is used to begin creating a systems solution for a business problem.
Logical design
Physical design
Specific technologies are selected to support the alternatives identified and evaluated in this phase.
Physical design
Logical design
Components are ordered, received, and tested. Afterward, users are trained and supporting documentation created.
(a)
Longest and most expensive of the process. This phase consists of the tasks necessary to support and modify the system for the remainder of its useful life cycle.
(a)
Typically considered the top information security officer in an organization. The CISO is usually not an executive-level position, and frequently the person in this role reports to the CIO.
(a)
such as trade secrets, copyrights, trademarks, or patents, are intangible assets that may be attacked via software piracy or the exploitation of asset protection controls.
Compromises to intellectual property
Deviation in quality of service
Organizations rely on services provided by others. Losses can come from interruptions to those
Deviation in quality of service
Espionage or trespass
Asset losses may result when electronic and human activities breach the confidentiality of information.
Espionage or trespass
Forces of nature
A wide range of natural events can overwhelm control systems and preparations to cause losses to data and availability
Forces of nature
Human error or failure
Losses to assets may come from intentional or accidental actions by people inside and outside the organization.
Human error or failure
Information extortion
Stolen or inactivated assets may be held hostage to extract payment of ransom.
Information extortion
Sabotage or vandalism
- Losses may result from the deliberate sabotage of a computer system or business, or from acts of vandalism. These acts can either destroy an asset or damage the image of an organization.
Sabotage or vandalism
Software attacks
- Losses may result when attackers use software to gain unauthorized access to systems or cause disruptions in systems availability.
Software attacks
Techinical hardware failures or error
- Technical defects in hardware systems can cause unexpected results, including unreliable service or lack of availability
Technical hardware failure or error
Technical software
Software used by systems may have purposeful or unintentional errors that result in failures, which can lead to loss of availability or unauthorized access to information.
Technical software
Technological obsolescence
Antiquated or outdated infrastructure can lead to unreliable and untrustworthy systems that may result in loss of availability or unauthorized access to information.
Technological obsolescence
Theft
can result from a wide variety of attacks.
Theft
Technological obsolescence
Acts of trespass can lead to unauthorized real or virtual action that enable information gathers to enter premises or systems without permission
Hackers
Cracker
commonly associated with software copyright bypassing and password decryption. With the removal of the copyright protection, software can be easily distributed and installed. With the decryption of user passwords from stolen system files, user accounts can be illegally accessed. In current usage, the terms hacker and cracker both denote criminal intent
Cracker
Hackers
attempting to guess or reverse-calculate a password is often called cracking.
Password attacks
cracker
the application of computing and network resources to try every possible password combination
Brute force
Rainbow tables
is a variation of the brute force attack that narrows the field by using a dictionary of common passwords and includes information related to the target user
Dictionary
Brute force
a far more sophisticated and potentially much faster password attack is possible if the attacker can gain access to an encrypted password file
Rainbow tables
Social engineering
used by attackers to gain system access or information that may lead to system access.
Social Engineering
Pretexting
a form of social engineering in which the attacker provides what appears to be legitimate communication, but it contains hidden or embedded code that redirects the reply to a third-party site in an effort to extract personal or confidential information
Phishing
Pretexting
attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential information.
Pretexting
Phishing
A hacker who attacks systems to conduct terrorist activities via networks or Internet pathways.
cyberterrorist
cyberwarfare
hacktivist
Formally sanctioned offensive operations conducted by a government or state against information or systems of another government or state. Sometimes called information warfare.
cyberwarfare
cyberterrorist
hacktivist
A hacker who seeks to interfere with or disrupt systems to protest the operations, policies, or actions of an organization or government agency.
hacktivist
cyberwarfare
cyberterrorist
A software program or hardware appliance that can intercept, copy, and interpret network traffic.
Packet sniffer
Spoofing
Man-in-the-middle
A technique for gaining unauthorized access to computers using a forged or modified source IP address to give the perception that messages are coming from a trusted host.
Spoofing
Packet sniffer
Man-in-the-middle
a group of attacks whereby a person intercepts a communications stream and inserts himself in the conversation to convince each of the legitimate parties that he is the other communications partner.
Man-in-the-middle
Spoofing
Packet sniffer
- sometimes enforced in civil courts, where large damages can be rewarded to plaintiffs who bring suits against organization.
- a system of rules, regulation, and principles established by governments
Law
Policy
moral principles that govern behavior and decision-making, distinguishing right from wrong
(a)
- refers to principles of right or wrong behavior
(a)
- Guidelines that dictate certain behavior within the organization.
Policy
Law
sets the long-term direction to be taken by the organization and each of its component parts.
Strategic planning
Tactical planning
Operational planning
focuses on short-term undertakings that will be completed within one or two years.
Tactical planning
Strategic planning
Operational planning
derived from tactical planning to organize the ongoing, day-to-day performance of tasks.
Operational planning
Tactical planning
Strategic planning
A standard that has been widely adopted or accepted by a public group rather than a formal standards organization. Contrast with a de jure standard.
De facto standards
De jure standards
a standard that has been formally evaluated, approved, and ratified by a formal standards organization. Contrast with a de facto standard.
De jure standards
De facto standards
also known as a general security policy, organizational security policy, IT security policy, or information security policy.
high-level information security policy that sets the strategic direction, scope, and tone for all of an organization’s security efforts.
Enterprise Information Security Policy (EISP)
Issue-specific security policy, or ISSP
are formalized as written documents readily identifiable as policy,
Issue-specific security policy, or ISSP
Enterprise Information Security Policy (EISP)
Specifications of authorization that govern the rights and privileges of users to a particular information asset.
Access Control Lists (ACL)
Issue-specific security policy, or ISSP
is any resource with economic value that an individual, corporation, or country owns or controls with the expectation that it will provide future benefit
Disaster recovery planning (DRP)
Business continuity planning (BCP)
The actions taken by senior management to develop and implement the BC policy, plan, and continuity teams in preparation for adverse events that become incidents or disasters.
Business continuity planning (BCP)
Disaster recovery planning (DRP)
The actions taken during and after a disaster
Crisis Management
Risk Assessment
the process of identifying, assessing, and mitigating potential risks that could negatively impact an individual, organization, or project.
RISK MANAGEMENT
Risk Assessment
determination of the extent to which the organization’s information assets are exposed or at risk
Risk Assessment
Risk Identification
The recognition, enumeration, and documentation of risks to an organization’s information assets.
Risk Identification
Risk Assessment
The application of controls that reduce the risks to an organization’s information assets to an acceptable level.
RIsk Control
Risk Identification
An attempt to improve information security practices by comparing an organization’s efforts against practices of a similar organization or an industry-developed standard to produce results it would like to duplicate. Sometimes
Benchmarking
Baselining
the process of conducting a baseline
Baselining
Benchmarking
current location of file or folder
pwd
cd
touch
create file
touch
chmod
change directory
cd
pwd
mkdir
create folder
mkdir
touch
command use to move folder or file
mv
cd
command use to remove/delete
rm
mv
command use to change file permission
chmod
ls
