What is information security?
Information security protects information and the systems that handle it from unauthorized access, change, disclosure, disruption, or destruction.
Study 1 Foundations of Information Security with 12 free online flashcards. Review key terms, definitions, and concepts with this interactive flashcard deck.
What is information security?
Information security protects information and the systems that handle it from unauthorized access, change, disclosure, disruption, or destruction.
What does confidentiality protect?
Confidentiality means information is accessible only to authorized people or systems.
What does integrity protect?
Integrity means information and systems are protected from unauthorized or improper changes.
What does availability ensure?
Availability means information and services are usable when authorized users need them.
What is a threat in information security?
A threat is a circumstance or event that could cause harm, such as an attack, power outage, or accidental deletion.
What is a vulnerability?
A vulnerability is a weakness that a threat could exploit or trigger, such as an unpatched server or excessive permissions.
What does information security risk describe?
Risk describes the possibility of harm and its consequences. Assessment considers likelihood and impact in context, including relevant threats and vulnerabilities.
What are common ways to respond to risk?
Risk responses include reducing risk with safeguards, avoiding the risky activity, sharing or transferring some consequences, or knowingly accepting remaining risk.
What is threat modeling for?
Threat modeling is a structured way to reason about how a system could be attacked or fail, so protections can be considered early and updated as the system changes.
What is a trust boundary?
A trust boundary is a point where information or control passes between different levels of trust.
What are the main stages of threat modeling?
A basic threat modeling process defines scope and assets, maps the system, identifies threat scenarios, assesses and prioritizes them, then selects and reviews safeguards.
What does least privilege require?
Least privilege gives each user, process, or service only the permissions needed for its task, and only for as long as needed.