Shared Flashcard Set

Details

ITEC CH14
ITEC CH14
18
Computer Science
Undergraduate 4
04/20/2013

Additional Computer Science Flashcards

 


 

Cards

Term
Risk
Definition
Concept at the heart of information security
Term
Threat
Definition
Type of action that has potential to cause harm
Term
Threat agent
Definition
Person or element with power to carry out a threat
Term
Vulnerability
Definition
Flaw or weakness that allows threat agent to bypass security
Term
Risk
Definition
Likelihood threat agent will exploit the vulnerability
Term
Privilege
Definition
Subject’s access level over an object, such as a file
Term
Privilege management
Definition
Process of assigning and revoking privileges to objects
Term
Privilege auditing
Definition
Periodically reviewing a subject’s privileges over an object
Objective: determine if subject has the correct privileges
Term
Controlling Risk
Definition
Threat
Threat agent
Vulnerability
Risk
Privilege
Privilege management
Privilege auditing
Change management
Term
(CMT)
Change management team
Definition
Body responsible for overseeing the changes
Composed of representatives from all areas of IT, network security, and upper management
Proposed changes must first be approved by CMT
Term
Incident handling
Definition
Planning, coordination, communications, and planning functions needed to resolve incident
Term
What Is a Security Policy?
Definition
Document that outlines protections to ensure organization’s assets face minimal risks
Term
Standard
Definition
Collection of requirements specific to system or procedure that must be met by everyone
Term
Guideline
Definition
Collection of suggestions that should be implemented
Term
Acceptable use policy
Definition
Policy that defines actions users may perform while accessing systems
Users include employees, vendors, contractors, and visitors
Typically covers all computer use
Generally considered most important information security policy
Term
Privacy policy
Definition
Also called personally identifiable information policy
Outlines how organization uses personal information it collects
Term
Disposal and destruction policy
Definition
Addresses disposal of confidential resources
Describes how to dispose of equipment, records, and data
Term
Social networking
Definition
Grouping individuals based on some sort of affiliation
Can be physical or online
Supporting users have an ad free experience!