What does the CIA triad stand for in information security?
What is information security?
The protection of information’s confidentiality, integrity, and availability.
How does information security differ from cybersecurity?
What does confidentiality mean in the CIA triad?
Data is accessed only by authorized personnel.
What does integrity mean in the CIA triad?
Data is accurate, complete, and tamper-proof.
What does availability mean in the CIA triad?
Data is accessible when needed.
What does the DAD triad represent?
What is a control in information security?
A measure implemented to mitigate risk.
What are the 3 categories of security controls?
What are examples of administrative controls?
What are examples of technical controls?
What are examples of physical controls?
What is risk management?
The identification, assessment, and mitigation of potential harm.
What is a risk in risk management?
A potential harm.
What is a threat in risk management?
A threat delivers harm.
What is the typical formula for calculating risk?
Risk score = severity of harm * probability of occurrence
What was the first EU-US data transfer framework?
Safe Harbor Agreement
What led to the invalidation of Safe Harbor?
Snowden revelations and Schrems I case
Schrems I: showed US surveillance violated EU data rights
What replaced Safe Harbor in 2016?
EU-US Privacy Shield
What did Schrems II case result in?
Invalidated EU-US Privacy Shield
What replaced Privacy Shield in 2023?
EU-US Data Privacy Framework
What US executive order addressed Schrems II concerns?
Executive Order 14086
What are 3 legal mechanisms for EEA data transfers to third countries?
What are examples of appropriate safeguards?