SYSTEMS SECURITY WITH AN A+ QUESTIONS AND ANSWERS
BREAKDOWN
An organization-wide policy that defines what is allowed and disallowed
regarding use of IT assets by employees.
Acceptable use policy (AUP)
A mathematical formula that quantifies the amount of uptime for a system
compared to the amount of downtime. Usually displayed as a ratio or percentage.
Availability
A physiological or behavioral human-recognition system (i.e., a fingerprint
reader, a retina scanner, a voice-recognition reader, etc.).
Biometric
A brand name for a line of smartphones and PDA handheld mobile devices.
BlackBerry
A plan for how to handle outages to IT systems, applications, and data access in
order to maintain business operations.
Business continuity plan (BCP)
A prerequisiste analysis for a business continuity plan that prioritizes mission-
critical systems, applications, and data and the impact of an outage or downtime.
Business impact analysis (BIA)
A globally recognize information systems security professional certification
offered by (ISC)2.
Certified Information Systems Security Professional (CISSP)
A federal law enacted by Congress to address concerns about access to
offensive content over the Internet on school and library computers.
Children's Internet Protection Act (CIPA)
The opposite of cleartext. Data sent as ciphertext is not visible and not
decipherable.
Ciphertext
The opposite of ciphertext. Data sent as cleartext is visible and decipherable.
, Cleartext
The requirement to keep information private or secret.
Confidentiality
The blocking of specific keywords or phrases in domain-name can be prevented
from being accessed with content filters.
Content filtering
The study or practice of hiding information.
Cryptography
The act of securing and protecting individuals, businesses, organizations, and
governments that are connected to the Internet and the Web.
Cybersecurity
The global online virtual world created by the Internet where individuals,
businesses, organizations, and governments connect to one another.
Cyberspace
A definition of different data types.
Data classification standard
An exterior network that acts as a buffer zone between the public Internet and an
organization's IT infrastructure (i.e, LAN-to-WAN Domain).
Demilitarized zone (DMZ)
A written plan for how to handle major disasters or outages and recover mission-
critical systems, applications, and data.
Disaster recovery plan (DRP)
The amount of time that an IT system, application, or data is not available to
users.
Downtime
The buying and selling of goods and services online through a secure Web site,
with payment by credit card or direct debit from a checking account.
E-commerce
The act of transforming cleartext data into undecipherable ciphertext.
Encryption