Share these flash cards

With group: None
HTML link to set: Tiny link:
Share on Facebook Share on MySpace

All 51 terms

TermDefinition
downtimethe period of time during which an IS is not available
blackouttotal loss of electricity
brownoutpartial loss of electricity; could be handled by connecting a voltage regulator between PCs and electric netowrk to smoth drops/surges
need for uninterruptible power supply (UPS)backup power
vandalismdeliberate destruction
datathis unique resource is the primary concern for security
keystroke loggingrecord individual keystrokes
social engineeringcon artists pretending to be service people who then steal passwords and valuable info
identity theftpretending to be another person
phishinga bogus website that requests users to "update" their personal data
spear phishinguse stolen personal info to obtain entry codes to attack org. sys and to steal money from online accounts
honeytokena bogus record in a networked database used to entice intruder to retrieve it and to alert security personnel who can then combat hackers
honeypota server containing a mirrored copy of a database or a bogus database, invalid records is set up to make intruders think they've accessed a production database; then security personnel can look at intruders' traces and learn of vulnerable points in configuration of servers
virusspreads from computer to computer; damages applications and data files, disrupt data communications
wormspreads in a network without human intervention; attacks PCs without need to send e-mail or to open receieved files
antivirus softwareprotects against viruses
trojan horsea virus disguised as legitimate software
logic bombsoftware that lies dormant until a certain event takes place or until PC's inner clock reaches specific time
denial of service (DoS)an attacker launches a large number of information requests that slows down legitimate traffic to site
distributed denial of service (DDoS)an attacher launches a DoS attack from multiple computers, usually from hijacked personal PCs
hijackingan attack using some or all of a PC's resources without the consent of its owner; often doen by DDoS attack, installing software bot on PC, purpose is usually to send spam
controlsconstraints and restrictions imposed on a user or a system that can be used to secure against risks and to ensure that nonsensical data is not entered, can reduce damage caused to sys, apps, and data
reliable applicationa control measure that is an application that can resist inappropriate usage such as incorrect data entry or processing
backupa control measure that consists of periodic duplication of all data
redundant arrays of independent disks (RAID)a control measure that consists of a set of disks programmed to replicate stored data
access controlscontrol measures taken to ensure only authorized users have access to a computer, network, application, or data; i.e. physical locks, software locks
biometrica control measure that uses unique physical characteristics such as fingerprints, retinal scans, or voiceprints
atomic transactiona control measure that is a set of indivisible transactions that ensures that only full entry occurs in all the appropriate files to guarantee integrity of data; all of the transactiosn in the set must be completely executed or none can be
audit traila control measure that is a series of documented facts that help detect who recorded which transactions, at what time, and under whose approval
information systems auditora person whose job is to find and investigate fraudulent cases
firewalla security measure that screens that activity of a person who logs on to a website and allows retrieval and viewing of certain material, but blocks attempts to change the info or to access other resources that reside on same PC or PCs connected to it; best defense against unauthorized access over Internet; integrated into routers
demilitarized zone approach (DMZ)one end of the network is connected to the trusted network, and the other end to the Internet, which provides a barrier b/w the Internet and a company's org. network, which is usually an intranet
proxy serverrepresents another server that employes a firewall and is placed between the Internet and the trusted network when there is no DMZ
authenticationsecurity measure that is the process of ensuring that you are who you say you are
encryptionsecurity measure that codes a message into an unreadable form by scrambling the transmitted info
plaintextthe original message
ciphertextthe encoded message
keya unique combination of bits that must be used to decipher the ciphertext used by receiving PC
public-key encryptionuses two keys, one public and one private
symmetric encryptionwhen the sender and the recipient use the same key
asymmetric encryptionboth a public and a private key are used
transport layer security (TLS)a protocol for transactions on the Web that uses a combination of public key and symmetric key encryption
digital signaturea security measure to authenticate online messages; implemented with public keys that authenticates the identiy of the sender of a message and guarantees that it hasn't been altered by others
message digestunique finger rpint of file used to create a digital signature when sending encrypted message
digital certificatescomputer files that associate one's identity with one's public key, holder's name, a serial number, expiration dates; issued by certificate authority
certificate authority (CA)a trusted 3rd party that issues public keys
single sign-on (SSO)a user must enter his or her name/password only once which saves employees time
redundancyorganizations run all system and transactions on 2 computers in parallel to protect against loss of data and biz; very expensive
business recovery plana plan about how to recover from a disaster
mission-critical applicationswhen developing a biz recover plan, one needs to prioritize recovery needs and these softwares are those that the business need to conduct operations
hot sitesalternative sites that a business can use when a disaster occurs; backup sites provide desks, PC sys, internet links

Set Information

Terms 51
Creator tingtingh88
Created May 1, 2009
Groups None
Subjects None
Access Anyone
Edit Creator Only
Get rid of ads on Quizlet
Pop out

Discuss

No Messages
Last Message: never

You must be logged in to discuss this set.

Top Users

  1. tingtingh88 - 131 scores

Most Missed Words

  1. transport layer security (TLS) a protocol for transactions on the Web that uses a combination of public key and symmetric key encryption - 4 misses
  2. redundant arrays of independent disks (RAID) a control measure that consists of a set of disks programmed to replicate stored data - 3 misses
  3. demilitarized zone approach (DMZ) one end of the network is connected to the trusted network, and the other end to the Internet, which provides a barrier b/w the Internet and a company's org. network, which is usually an intranet - 2 misses
  4. reliable application a control measure that is an application that can resist inappropriate usage such as incorrect data entry or processing - 2 misses
  5. digital certificates computer files that associate one's identity with one's public key, holder's name, a serial number, expiration dates; issued by certificate authority - 2 misses
  6. single sign-on (SSO) a user must enter his or her name/password only once which saves employees time - 1 miss
  7. access controls control measures taken to ensure only authorized users have access to a computer, network, application, or data; i.e. physical locks, software locks - 1 miss