click below
click below
Normal Size Small Size show me how
Security 1.1
| Term | Definition |
|---|---|
| Authentication | Proving that a subject is who or what it claims to be |
| Mandatory | Model type where rights are pre-determined |
| Availability | Information is readily accessible those those authorized |
| Identification | Creating an account or ID that uniquely represents the user, device, or process |
| Discretionary | Model type where object owner can allocate rights |
| Authorization | Determining what rights subjects should have on each resource |
| Identify | Develop security policies and capabilities |
| IAM | identity and Access Management system |
| Detect | Perform ongoing, proactive monitoring to ensure that controls are effective and capable of protecting against new threats |
| respond | identify, analyze, contain, and eradicate threats to systems and data security |
| recover | Implement cybersecurity resilience to restore systems and data if other controls are unable to prevent attacks |
| Access control system | Ensures that an information system meets the goals of the CIA Triad |
| non repudiation | A person cannot deny doing something such as creating, modifying, or sending a resource |
| Gap analysis | Process that identifies how an organization's security systems deviate from those required or recommended |
| NIST | National Institute of Standards and Technology |
| Confidentiality | Information can only be read by people who access authorization |
| cybersecurity framework | Guides the selection and configuration of controls |
| accounting | Tracking authorized usage of a resource or use of rights by a subject |
| protect | Procure/develop, install, operate, and decommission IT hardware and software assests |
| Integrity | Data is stored and transferred as intended |