FULL SOLUTIONS VERIFIED
⫸ Information Security (InfoSec). Answer: The protection of
information and its critical elements including the systems and
hardware that store, process, and transmit it.
⫸ Threat. Answer: Any event or circumstance that can have a
negative impact on an information system.
⫸ Threat Agent. Answer: Person or event that exploits a threat.
⫸ Attack. Answer: Act that exploits vulnerability to damage or steal
information.
⫸ Exploit. Answer: A technique or tool used to take advantage of a
system vulnerability.
⫸ Vulnerability. Answer: A weakness in a system that can be
exploited to cause harm.
⫸ Risk. Answer: The probability that a vulnerability will be
exploited by a threat agent.
,⫸ Risk Management. Answer: The process of identifying,
evaluating, and controlling risk.
⫸ Risk Control. Answer: Strategies to reduce risk to an acceptable
level.
⫸ Confidentiality. Answer: Ensuring information is accessible only
to authorized individuals.
⫸ Integrity. Answer: Ensuring information is whole, uncorrupted,
and accurate.
⫸ Availability. Answer: Ensuring information and systems are
accessible when needed.
⫸ Authentication. Answer: Confirming identity of a user or device.
⫸ Authorization. Answer: Granting permission to access resources
after authentication.
⫸ Accountability. Answer: Tracking user actions to hold them
responsible for their activities.
⫸ Nonrepudiation. Answer: Ensures the sender cannot deny sending
or receiving a message.
,⫸ Security Perimeter. Answer: A boundary that separates trusted
internal systems from untrusted external networks.
⫸ Proxy Server. Answer: Intermediary that filters and forwards
requests to servers.
⫸ Demilitarized Zone (DMZ). Answer: An isolated subnetwork
where external-facing services operate with limited internal network
access.
⫸ Security Framework. Answer: A more detailed version of the
blueprint that maps controls to processes.
⫸ Security Policy. Answer: High-level directives that define how
security is managed and enforced.
⫸ Enterprise Information Security Policy (EISP). Answer: The
organization's long-term, high-level security position and philosophy.
⫸ Issue-Specific Security Policy (ISSP). Answer: Policy addressing
specific issues like email, Internet, or social media use.
⫸ System-Specific Policy (SysSP). Answer: Policy with technical
configuration rules and access control definitions.
, ⫸ Standard. Answer: A detailed statement of what must be done to
comply with policy.
⫸ Guideline. Answer: Recommended actions; flexible and not
mandatory.
⫸ Chief Information Officer (CIO). Answer: Executive responsible
for IT systems.
⫸ Chief Information Security Officer (CISO). Answer: Executive
responsible for InfoSec program.
⫸ Data Owner. Answer: The person responsible for a specific set of
information.
⫸ Data Custodian. Answer: Responsible for the storage and
protection of data.
⫸ Data User. Answer: Anyone who uses data legally and authorized.
⫸ Data Trustee. Answer: Individual appointed to oversee
management and coordination of data handling.
⫸ Champion. Answer: The senior-level executive who promotes the
information security project, secures funding, provides strategic
direction, and removes barriers that may obstruct progress.