Study 2 Flashcards
(53 cards)
What is the CIA Triad?
Confidentiality, Integrity, Availability
What is due care?
Taking reasonable actions to prevent harm
What does ISO 27001 specify?
Information security management system (ISMS) requirements
Who is responsible for data classification?
The data owner
What is data remanence?
Residual representation of data that remains after attempts to remove or erase it
What is defense in depth?
Layered security approach to protect assets
What does a firewall do?
Filters network traffic based on predefined rules
What is the purpose of IPSec?
Provides secure network communications using authentication and encryption
What is multifactor authentication (MFA)?
Authentication using two or more factors from different categories
What does RBAC stand for?
Role-Based Access Control
What is a vulnerability assessment?
Identifying and quantifying vulnerabilities in a system
What is the purpose of a security audit?
Evaluate compliance with security policies and standards
What is an incident response plan?
A set of procedures for detecting, responding to, and recovering from incidents
What does SIEM stand for?
Security Information and Event Management
What is the main goal of secure coding practices?
Prevent common vulnerabilities such as buffer overflows and injection attacks
What is the purpose of the OWASP Top 10?
Highlight the most critical security risks to web applications
What is confidentiality in the CIA triad?
Ensuring information is accessible only to those authorized.
What is integrity in the CIA triad?
Assurance that information is accurate and has not been altered.
What is availability in the CIA triad?
Ensuring timely and reliable access to information.
What is due diligence?
Ongoing activities to ensure due care is being applied.
What is the primary purpose of security governance?
To align security with business objectives.
What are administrative controls?
Policies, procedures, and guidelines that define roles and responsibilities.
What is risk appetite?
The level of risk an organization is willing to accept.
What is data classification?
Process of categorizing data based on sensitivity and impact.