CSCI 340 Test 2
Active tag ANS✔✔ a type of RFID tag (remotely powered computer chips
that augment physical objects with computing capabilities). They contain
auxiliary batteries on board. Can be detected from 100+ meters away.
Administrative controls ANS✔✔ are the policy, standards, and procedures
that guide employees when conducting the organization's business. Pre-
employment screening of personnel and a change management process are
also examples of administrative controls.
Assignment of responsibilities for program implementation ANS✔✔ a policy
should state responsibilities of personnel and departments related to the
program. This includes the role of managers, users, and the IT organization.
This is also referred to as the program's delegation of authority. The policy can
also serve as the basis for establishing employee accountability.
Badvertisements ANS✔✔ a technique for turning website visitors into
unwitting click-fraudsters. The attack is easier to accomplish than that of
infecting a machine with malware, as all it requires is that a user visit a web
site in JavaScript-enabled browser.
Baseline metrics ANS✔✔ starting point to know how far you've come
(Framework provides a metric). The director decided to start with baseline
metrics from IT security risk. This would help her determine whether systems
were already in compliance. It would also provide a baseline when assessing
systems in the future.
, BIOS (Basic Input Output System) ANS✔✔ the BIOS is special software that
interfaces the major hardware components of your computer with the
operating system. It is usually stored on a Flash memory chip on the
motherboard but sometimes the chip is another type of ROM. The first thing
the BIOS does is check the information stored in a tiny (64 bytes) amount of
RAM located on a complementary metal oxide semiconductor (CMOS) chip.
Interrupt handlers are small pieces of software that act as translators between
the hardware components and the operating system
Bootable Device ANS✔✔ a bootable USB flash drive can be used to launch
an OS (circumvent security software - USB boot by changing BIOS settings on
memory chip). It is possible to copy the SAM file by booting the machine with
another OS (bootable USB). The SAM file can be coped to a directory of the
connected USB drive.
Browser extension ANS✔✔ browser plug-ins typically connected to other
web servers (see figure online). TG attacks generate fraudulent transactions
from the user's computer, through malicious browser extensions. Transaction
generators typically live inside the user's browser as a browser extension, SSL
provides no defense.
Charter ANS✔✔ the program framework policy, or information security
charter is the "capstone" document for the information security program. The
charter is a required document. This document establishes the information
security program and its framework. This high-level policy defines: The
program's purpose and mission, the program's scope within the organization,
assignment of responsibilities for program implementation, and compliance
management.
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Schoolflix. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $14.99. You're not tied to anything after your purchase.