Information Security (InfoSec) uses specific terms to describe concepts, processes, and elements involved in protecting information. Understanding these terms is essential for studying or working in cybersecurity.
Anything valuable that needs protection. Examples: data, hardware, software, networks, people.
Anything that has the potential to cause harm to an asset. Examples: hackers, malware, natural disasters.
A weakness or flaw in a system that can be exploited by a threat. Examples: outdated software, weak passwords.
The possibility of a threat exploiting a vulnerability and causing damage. Risk = Threat × Vulnerability
An attempt to damage, steal, or gain unauthorized access to information. Examples: phishing attacks, ransomware attacks.
A method or tool used to take advantage of a vulnerability. Example: code that exploits a software bug.
Measures taken to reduce risk or protect assets. Types:
Ensuring information is accessible only to authorized people. Example: encryption.
Ensuring information remains accurate and unaltered. Example: hashing, checksums.
Ensuring information and systems are available when needed. Example: backups, redundant servers.
Verifying the identity of a user or device. Examples: passwords, biometrics, OTP.
Determining what an authenticated user is allowed to do. Examples: user roles, access levels.
Tracking actions of users to ensure responsibility. Example: audit logs.
Ensuring a person cannot deny performing an action. Example: digital signatures.
Any event that compromises the security of data or systems. Examples: data breach, malware infection.
Steps taken to handle and recover from a security incident. Examples: detection → containment → eradication → recovery.
Converting data into unreadable form to protect confidentiality. Example: AES, RSA.
A security device or software that filters network traffic to prevent unauthorized access.
Malicious software designed to harm systems. Types: viruses, worms, trojans, ransomware.
Tricking people into revealing confidential information. Examples: phishing, pretexting.
Information security terminology provides the foundation needed to understand how threats, vulnerabilities, and controls interact. Mastering these terms is essential for learning cybersecurity and applying proper protection techniques.
Open this section to load past papers