Chapter 1 Flashcards
(14 cards)
CIA Triad
Confidentiality, Integrity, and Availability
Confidentiality
Ensures that unauthorized individuals are not able to gain access to sensitive information.
Integrity
Ensures that there are no unauthorized modifications to information or systems, either intentionally unintentionally.
Availability
Ensures that information and systems are ready to meet the needs of legitimate users at the time those users request them.
Nonrepudiation
Means that someone who performed some action, such as sending a message, cannot later deny having taking that action.
DAD Triad
Disclosure, Alteration, and Denial
Disclosure
Exposure of sensitive information to unauthorized individuals, otherwise known as data loss.
Alteration
Unauthorized modification of information and is a violation of integrity.
Denial
The disruption of an authorized users legitimate access to information. Violates Availability
Financial Risk
The risk of monetary damage to the organization as the result of a data breach.
Reputational Risk
When the negative publicity surrounding a security breach causes the loss of goodwill among customers, employees, suppliers, and other stakeholders.
Strategic Risk
The risk that an organization will become less effective in meeting it’s major and objectives as result of the breach.
Operational Risk
The risk to the organization’s ability to carry out its day-to-day functions.
Compliance Risk
When a security breach causes an organization to run afoul of legal or regulatory requirements.