/
AI Flashcards
Save to my account
Sign up
AI Flashcards
Information System Security Essentials
Study
1
Question
What is an Information System (IS)?
Page 1
Answer
An Information System (IS) is the entire set of software, hardware, network, data, people, and procedures necessary to use information as a resource in an organization — more than just computer hardware.
2
Question
List the five core components of an Information System.
Page 1
Answer
The five core components of an Information System are hardware, software, data, procedures, and people.
3
Question
What are the main purposes of using Information Systems in organizations?
Page 1
Answer
Information Systems are used to support decision-making, manage operations, and achieve organizational goals by transforming raw data into useful information.
4
Question
How does the document define "security" in the context of information systems?
Page 1
Answer
Security entails protection from harm/theft/attack/malicious injury — i.e., protecting systems and information against damage, theft, or malicious actions.
5
Question
What is Information System Security (ISS)?
Page 2
Answer
Information System Security (ISS) is the protection of an information system against any breaches, including preventing unauthorized access, modification of information, and denial of service to authorized users.
6
Question
Name three types of breaches the text highlights that ISS protects against.
Page 2
Answer
ISS protects against (1) unauthorized access, (2) modification of information (in storage, processing, or transit), and (3) denial of service to authorized users.
7
Question
Who is primarily responsible for information system security within an organization according to the notes?
Page 2
Answer
While every member of an organization has responsibility for information system security, the Chief Information Officer (CIO) plays a critical role in overseeing and coordinating security efforts.
8
Question
What is the difference between information security and cybersecurity as described in the notes?
Page 2
Answer
Information security is a broad field that protects all information assets — digital or physical. Cybersecurity is a narrower subfield that focuses specifically on protecting digital assets from online threats carried out in cyberspace (Internet-related crimes and unauthorized access to systems and data connected to the Internet).
9
Question
Define physical security in the context of IS security.
Page 2
Answer
Physical security is the protection of personnel, hardware, software, networks, and data from physical breaching actions and events (e.g., fire, flood, natural disasters, burglary, theft, vandalism, terrorism) and includes measures such as walls, locks, guards, and access controls.
10
Question
List common physical threats that physical security aims to protect against.
Page 2
Answer
Common threats include fire, flood, natural disasters, burglary, theft, vandalism, and terrorism.
11
Question
In the D3R physical security model, what does the 'Deter' level aim to achieve?
Page 2
Answer
The 'Deter' level aims to keep intruders out of the secured area and prevent attempts by making the target appear too difficult or risky to be worth the effort — it is the outermost layer of defense.
12
Question
Give examples of common deterrent methods used in physical security.
Page 2
Answer
Common deterrent methods include fences, barbed wire, commercial video cameras, visible cameras, fencing, bright security lighting, warning signs, highly visible security guards or patrols, and access controls.
13
Question
What pre-employment personnel security step is recommended to reduce insider risks?
Page 4
Answer
Conduct comprehensive background checks and have new hires sign non-disclosure agreements (NDAs) before granting them access — these act as both vetting and legal deterrents.
14
Question
How should an organization manage the ongoing suitability of employees regarding security?
Page 4
Answer
Manage ongoing suitability by continuous monitoring, continuous vetting/re-investigation, mandatory security awareness training (initial and regular refreshers), segregation of duties, enforcing need-to-know/least privilege, and performance/behavioral monitoring to spot risk indicators.
15
Question
Why is segregation of duties important for insider risk management?
Page 4
Answer
Segregation of duties prevents a single person from controlling an entire critical process, reducing the potential for fraud and errors — for example, separating the person who authorizes a payment from the person who processes it.
16
Question
Explain the 'Need-to-Know/Least Privilege' principle.
Page 4
Answer
The Need-to-Know/Least Privilege principle ensures employees only have the minimum access rights necessary to perform their current job functions, reducing exposure to sensitive information and potential misuse.
17
Question
What is the role of mandatory security awareness training in insider risk reduction?
Page 4
Answer
Mandatory security awareness training (initial and regular refresher, at least annually) educates employees on threats (e.g., phishing), proper procedures, and organizational policies, which reduces human error and insider-related risks.
18
Question
What should an organization do when an employee departs to manage security risks?
Page 4
Answer
During departure (voluntary or involuntary), immediately revoke access, reclaim credentials, transfer and wipe data if necessary, and conduct an exit interview — procedures must be immediate and comprehensive.
19
Question
What is OPSEC and what does it focus on protecting?
Page 4
Answer
OPSEC (Operations Security) is a security and risk management process that classifies information, determines what is required to protect sensitive information, and prevents it from falling into the wrong hands by identifying and protecting Critical Information while viewing operations through the eyes of an adversary.
20
Question
Give one good practice for OPSEC mentioned in the notes.
Page 4
Answer
One good OPSEC practice is having formal, documented change-management processes for all changes to IT systems, infrastructure, or processes.
21
Question
What is TRANSEC and what does it protect?
Page 6
Answer
TRANSEC (transmission security) refers to measures designed to protect transmissions from interception and exploitation, ensuring the transmission method is secured against eavesdropping or tampering.
22
Question
Define EMSEC (emission security).
Page 6
Answer
EMSEC is a construct that analyzes the risk that electromagnetic signals may be picked up deliberately by special listening devices or unintentionally between devices; it protects signals in wireless communications from being intercepted via emitted electromagnetic radiation.
23
Question
What is network security according to the notes?
Page 6
Answer
Network security is the protection of the underlying networking infrastructure from unauthorized access, misuse, or theft by creating a secure infrastructure for devices, applications, and users to work in a secure manner.
24
Question
What is the primary function of a firewall in network security?
Page 6
Answer
A firewall monitors and filters incoming and outgoing network traffic based on predetermined security rules; it acts as a barrier between a trusted internal network and untrusted external networks (like the Internet).
25
Question
How does an Intrusion Prevention System (IPS) differ from an Intrusion Detection System (IDS)?
Page 6
Answer
An IPS actively monitors network or system activities for malicious activity and can automatically take action (block or drop malicious packets) because it sits directly in the traffic path, whereas an IDS only alerts on suspicious activity without automatically intervening.
26
Question
What does a VPN (Virtual Private Network) provide for users over a public network?
Page 6
Answer
A VPN extends a private network across a public network, allowing users to send and receive data securely as if their computing devices were directly connected to the private network by creating a secure, encrypted tunnel between the user's device and the private network.
27
Question
What is the function of Network Access Control (NAC)?
Page 6
Answer
Network Access Control (NAC) limits access to network resources to only authorized users and devices, enforcing policies that determine who and what can connect to the network.
28
Question
What is the goal of email security as described in the notes?
Page 7
Answer
Email security includes technologies and processes designed to protect email accounts and communications from external threats, data loss, and unauthorized access.
29
Question
What does web security aim to protect?
Page 7
Answer
Web security involves measures taken to protect web browsers, web servers, and web applications from attacks (e.g., injection attacks, XSS, server compromises).
30
Question
What is wireless security concerned with protecting?
Page 7
Answer
Wireless security focuses on specific protocols and practices designed to secure devices connected to a wireless network (Wi‑Fi), protecting wireless transmissions and preventing unauthorized access.