What is the definition of a ‘threat’ in the context of software security?
A risk or potential danger that can exploit a vulnerability
What does ‘vulnerability’ refer to in software security?
A weakness in a system that can be exploited by threats
What is a ‘threat vector’?
A path or method used by a threat to access a system
What does the CIA triad stand for?
What is the main goal of confidentiality in information security?
To keep sensitive information undisclosed to unauthorized parties
What does integrity ensure in data security?
That data remains accurate, consistent, and trustworthy
What is the purpose of availability in the context of security?
To ensure that data and services are accessible when needed
Define ‘fault tolerance’ in software systems.
The ability of a system to continue operating after a failure
What are the roles of backups in data recovery?
To restore data and services after a failure
What does access control include?
What is encryption?
The process of encoding information to be accessible only by authorized users
What do secure communication protocols like SSL/TLS do?
Protect data during transmission from unauthorized changes
What is the purpose of cryptographic hashes?
To ensure data integrity by providing a unique output for given input
Fill in the blank: _______ are used to verify the authenticity of a message.
[Digital signatures]
What does PCI DSS stand for?
Payment Card Industry Data Security Standards
What is the primary purpose of PCI DSS?
To ensure companies have a secure environment
True or False: PCI DSS applies only to companies that directly process credit card transactions.
False
Fill in the blank: PCI DSS is a set of _______ designed to protect card information.
[data security standards]
What does the acronym ‘GDPR’ stand for?
General Data Protection Regulation
True or False: GDPR and PCI DSS are unrelated data protection standards.
False
What is a key requirement under PCI DSS for companies handling payment information?
Implementing strong access control measures
List three main areas that PCI DSS covers.
Fill in the blank: Companies must regularly _______ their compliance with PCI DSS.
[assess]
What does a secure environment help prevent?
Data breaches and fraud