Module 10 - Cybersecurity principles, practices and processes Flashcards
(67 cards)
Which model breaks down data protection into three dimensions to guide cybersecurity practices?
The Cybersecurity cube
Which principle ensures that data is only accessible to authorized entities?
Confidentiality
What are the three security principles at the core of the cybersecurity cube?
Confidentiality, Integrity and Availability (CIA)
Which principle guarantees the accuracy, consistency, and trustworthiness of data?
Integrity
What are the three data states represented in the second dimension of the cybersecurity cube?
Data in transit, Data at rest, Data in process
Which principle focuses on ensuring data is accessible when needed by authorized users?
Availability
What are the three safeguard categories in the cybersecurity cube’s third dimension?
People, Policies and Practices, Technology
What safeguard dimension involves setting up rules and controls to guide secure behavior?
Policies and practices
What safeguard dimension focuses on increasing human awareness and skills in cybersecurity?
People
Which substitution technique enhances confidentiality by replacing sensitive data with meaningless tokens?
Tokenization
How does tokenization differ from encryption?
Tokens have no relationship to the original data and are useless outside of the system
Which technology manages and restricts access to copyrighted digital content like music and e-books?
DRM (Digital Rights Management)
Which technology helps control access to organizational documents such as emails and files?
IRM (Information Rights Management)
What type of information includes data that can identify an individual, like medical or credit records?
Personal information
What type of data includes sensitive internal details like trade secrets or customer lists?
Business information
Which category of data includes government information labeled as secret, confidential, or restricted?
Classified information
Which privacy technique turns identifiable information into anonymous, irreversible data?
Data anonymization
Which principle refers to the accuracy, consistency, and trustworthiness of data throughout its lifecycle?
Data integrity
What is the level of data integrity need for a healthcare organization ?
Critical level-{inaccurate prescription data can be life-threatening}
How is data integrity prioritized in e-commerce or analytics-based businesses?
High level -{data is validated and verified frequently to ensure accuracy}
What level of data integrity need applies to public data from search engines and online sales?
Mid level -{limited verification and reduced trust}
Which types of platforms have a low level of integrity need due to unverified user content?
Blogs and personal social media pages
Which principle ensures that information and systems remain accessible to authorized users when needed?
Availability