Free Online Flashcard Deck

1 Foundations of Information Security Free Online FlashCards

Study 1 Foundations of Information Security with 12 free online flashcards. Review key terms, definitions, and concepts with this interactive flashcard deck.

12 cards
01
Front

What is information security?

Back

Information security protects information and the systems that handle it from unauthorized access, change, disclosure, disruption, or destruction.

02
Front

What does confidentiality protect?

Back

Confidentiality means information is accessible only to authorized people or systems.

03
Front

What does integrity protect?

Back

Integrity means information and systems are protected from unauthorized or improper changes.

04
Front

What does availability ensure?

Back

Availability means information and services are usable when authorized users need them.

05
Front

What is a threat in information security?

Back

A threat is a circumstance or event that could cause harm, such as an attack, power outage, or accidental deletion.

06
Front

What is a vulnerability?

Back

A vulnerability is a weakness that a threat could exploit or trigger, such as an unpatched server or excessive permissions.

07
Front

What does information security risk describe?

Back

Risk describes the possibility of harm and its consequences. Assessment considers likelihood and impact in context, including relevant threats and vulnerabilities.

08
Front

What are common ways to respond to risk?

Back

Risk responses include reducing risk with safeguards, avoiding the risky activity, sharing or transferring some consequences, or knowingly accepting remaining risk.

09
Front

What is threat modeling for?

Back

Threat modeling is a structured way to reason about how a system could be attacked or fail, so protections can be considered early and updated as the system changes.

10
Front

What is a trust boundary?

Back

A trust boundary is a point where information or control passes between different levels of trust.

11
Front

What are the main stages of threat modeling?

Back

A basic threat modeling process defines scope and assets, maps the system, identifies threat scenarios, assesses and prioritizes them, then selects and reviews safeguards.

12
Front

What does least privilege require?

Back

Least privilege gives each user, process, or service only the permissions needed for its task, and only for as long as needed.