2.1 - Summarise fundamental security concepts Flashcards

(11 cards)

1
Q

What is the C in the CIA triad?

A

Confidentiality - Assurance that information is not exposed to unauthorised individuals, processes, or devices. It covers data in storage and transit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the I in the CIA triad?

A

Integrity - the principle that systems are trustworthy, and work as intended, and the data is complete and accessible when needed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the A in the CIA triad?

A

Availability - the principle that information systems and supporting infrastructure are operating and accessible when needed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 4 supporting principles?

A

Authentication - Process of verifying identify

Authorisation - Process of approving access

Accounting - Process of tracing actions to the source

Non-repudiation - Process of assuring the validity and origin of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is privacy?

A

The right of an individual to control the use of their personal information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 4 out of the 8 OECD privacy principles

A

Collection limitation, data quality, purpose specification, use limitation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Collection limitation from OECD privacy principles?

A

There is a limit amount of personal data that can be collected, collected data should be obtained lawfully and fair means and with knowledge and consent from the subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Data quality from OECD privacy principles?

A

Personal data collected should be relevant to the business, it should be accurate, complete and kept up to date

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Purpose specification from OECD privacy principles?

A

Personal data collected should align with the purpose of collection. It should be told no later than at the time of data collection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Use limitation from OECD privacy principles?

A

Personal data should not be disclosed or used for other purposes other than what has be specified with the consent of the individual or authority of law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Strategic alignment?

A

Every security and privacy objective must be aligned with the needs of the organisation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly