MIS 464 Midterm Exam - Questions and Answers History of Information Security • Computer security began immediately after the first mainframes were developed. • Groups developing code-breaking computations during World W
...
MIS 464 Midterm Exam - Questions and Answers History of Information Security • Computer security began immediately after the first mainframes were developed. • Groups developing code-breaking computations during World War II created the first modern computers. • Physical controls limiting access to sensitive military locations to authorized personnel • Rudimentary in defending against physical theft, espionage, and sabotage ARPANET (1960's)was an early packet-switching network and the first network to implement the TCP/IP protocol suite. Both technologies became the technical foundation of the Internet. Multics 1960's First OS with integrated security, Mainframe, time sharing OS. CIA Triad Identifies the three traditional goals or characteristics of Information. Stands for Confidentiality, Integrity, Availability Confidentiality Information is not made available or disclosed to unauthorized individuals, entities, or processes Availability Applications and the Information is available when needed Authenticity Authenticity refers to the veracity of the claim of origin or authorship of the information Utility Utility means usefulness Risk The probability that something unwanted will happen Protection profile or security posture The entire set of controls and safeguards, including policy, education, training and awareness, and technology, that the organization implements to protect the asset. Asset This is the organizational resource being protected. Control, safeguard, or countermeasure security mechanisms, policies, or procedures that can successfully counter attacks, reduce risk, resolve vulnerabilities, and otherwise improve the security within an organization Exploit A technique used to compromise a system Exposure In the Information Security Domain, this exists when a vulnerability known to an attacker exists Access This is a subject or object's ability to use, manipulate, modify, or affect another subject or object Loss A single instance of an information asset suffering damage or unintended or unauthorized modification or disclosure Subjects and attacks These terms describe when a system used to conduct an attack, or the target of an attack Attack These terms describe when a system used to conduct an attack, or the target of an attack Vulnerability These terms describe when a system used to conduct an attack, or the target of an attack Threat agent the specific instance or a component of a threat Threat This term describes people, objects, or other entities that presents a potential risk to an assets value Business Needs for Security
[Show More]