~/ learn/ comp-400/ cards/ Security Concepts, Assets, and the CIA Model
1 of 33

The standard definition of computer security names the three objectives it preserves, and it also names what is protected. What does it name there?

The standard definition of computer security names the three objectives it preserves, and it also names what is protected. What does it name there?

Answer

An automated information system's resources: hardware, software, firmware, data and telecommunications

Options - A. An automated information system's resources: hardware, software, firmware, data and telecommunications - B. The confidentiality, integrity and availability of the organisation’s data - C. The network perimeter and every device attached to it - D. The organisation’s staff, contractors and third-party suppliers - E. The policies, standards and procedures the organisation has formally approved Why - A. Correct — this is the resources clause, and it is the half of the definition most answers drop. - B. This is the objectives half stated twice. It says what is preserved but never says what is protected, and it silently narrows the scope to data. - C. Too narrow and the wrong axis: a perimeter is a place, not a resource class, and firmware and data are not "attached devices". - D. People are the subject of personnel security and of the privacy obligation, but the definition’s scope clause is about system resources. - E. Policy is one of the three separable questions in a security strategy, not the thing the definition puts in scope.

Stallings & Brown 5e ch1 §1.1; NISTIR 7298

space flip · ← → navigate · esc to exit
NORMAL ~/memra/library/4aad0272-6b48-40de-90b6-27d8d174054b/flashcard utf-8 LF