Approved Definitions
Acceptable Level of Risk- To reduce the risk level of all its information and information processing assets/processes to an acceptable level, such that critical business is not affected. At all times there should remain a “Risk Level” for any given asset/process that is below an “Acceptable Risk Level” as set by the management. Acceptable Risk is the risk level that the management is prepared to accept as business risk.
Access Control- a security technique that regulates who or what can view or use resources in a computing environment. Access control is a fundamental component of data security that dictates who's allowed to access and use company information and resources. Using authentication and authorization to ensure users are who they say they are and that they have appropriate access to company data.
Account- "Account" means the following examples, but not limited to, (M365 User accounts, GSuite User Accounts, etc.) and where the account is associated to either an individual user (i.e.. user account) or service (i.e. service account). "Shared Accounts" are accounts that are used by more than one person however are not recommended or encouraged for use without appropriate compensating controls and may be against policy if used without approval.
Access Control System- a security technique that regulates who or what can view or use resources in a computing environment.
Advanced Encryption Standard (AES)- applies a series of mathematical transformations to each 128-bit block of data. Because the computational requirements of this approach are low, AES can be used with consumer computing devices such as laptops and smartphones, as well as for quickly encrypting large amounts of data. AES256 number corresponds to the bit wise strength of the algorithm. Please visit nist.gov or Wikipedia for more details.
AKA- also known as
Alert- A notification generated by a monitoring system indicating a potential issue or anomaly.
American Standard Code for Information Interchange (ASCII) - is the most common character encoding format for text data in computers and on the internet. ASCII includes 128 English characters used as text in computers, telecommunications equipment, and other devices.
Anti-Malware Protection- A program or application that separates malicious software from legitimate applications to prevent damage to the computer or compromise to the company.
APP Entity- is either an agency (largely referring to a federal government entity and/or office holder) or an organization (which includes an individual, body corporate, partnership, unincorporated association, or trust) under the Australian Privacy Principles (APPs).
Application Administration Account- Any account that is for the administration of an application (e.g., Oracle database administrator, System administrator) and has elevated permissions to perform administrative functions.
Application Authentication- allows users to enter their credentials and store them in the application server password cache so that they are not prompted when they next run an application on that application server.
Asymmetric Cryptosystem- A method of encryption in which two different keys are used: one for encrypting and one for decrypting the data (e.g., public-key encryption). Single key encryption and decryption is symmetric encryption.
Audit- a formal examination of an organization's or individual's processes, and adherence to policies, procedures, laws and regulations.
Audit Trail- a detailed, step-by-step chronological record by which accounting, records, project details, or other data can be tracked and traced to their source.
Authentication- an act, process, or method of showing something (such as using a password or app) to be real, true, or genuine. An expansion of singular authentication is multifactor authentication that is commonly referred to as "something you know, something you have" and may include, but not limited to, biometrics, geographical location, keys, one time codes, authentication links, etc.
Authority- The power or right to make decisions and enforce compliance within the scope of the assigned responsibilities.
Automated Audit Trail- an increasing number of new forms of audit evidence, which may include alerts from continuous monitoring or audit procedures, analytic contingency tables (e.g., if “event” occurs, initiate an additional audit module), or forward-looking data from operations that creates a detailed, chronological record whereby records, activities, project details, or other data are tracked and traced in an irrefutable format.
Availability and Uptime- The number of times services are running and accessible to the customer. Uptime is tracked and reported on a per calendar month and is commonly referred to as "five 9s" meaning 99.999% uptime.
Backup Data- All user-level and system-level data maintained by the company that is backed up regularly and tested on a periodic basis.
Back-Out Process- a contingency plan component of the IT service management framework. It is implemented prior to any software or system upgrade, installation, integration, or transformation to ensure automated system business operations, should a new system fail to deliver not clear post-implementation testing.
Bandwidth Capacity Monitoring- ensuring that the network has the resources it needs to prevent an impact on business-critical applications from the standpoint of resource utilization. Bandwidth capacity monitoring is commonly associated with the speed and "bandwidth" of an Internet or network connection but could also be associated with an individual and the amount of "bandwidth" available to the individual to perform activities.
Business Continuity (BC)- concerns determining prior to an emergency or disaster how to keep business operations running in another location or by using alternative tools, processes, procedures, decisions, and activities following a disaster or emergency to ensure that an organization can continue to function through an operational interruption. It is about making proactive and reactive plans to help your organization avoid crises and disasters and to be able to quickly return to 'business as usual' should they occur. Business continuity involves two distinct areas: business continuity planning and business continuity management. To perform true BC a BIA must be performed.
Business Continuity Planning (BCP)- is concerned with keeping business operations running perhaps in another location or by using alternative tools and processes following a disaster. To perform true BC a BIA must be performed.
Business Impact Analysis (BIA)- predicts the consequences of disruption of a business function and process and gathers information needed to develop recovery strategies through a systematic process. It includes a method for analyzing how disruptions may impact an organization and is a required activity to uncover RPO (Recovery Point Objective) and RTO (Recovery Time Objective). A BIA is a required activity for any aspect of business continuity.
Business Sensitive Information (BSI)- any confidential or proprietary business information, collected or created while conducting business, including company related information, and information related to clients and prospective clients.
BYOD- Bring Your Own Device
Cable Modem- Cable companies provide Internet access over Cable TV coaxial cable. A cable modem accepts this coaxial cable and can receive data from the Internet.
California Consumer Privacy Act (CCPA) - as of January 1, 2020 - "The Act", also known as 2020 California Proposition 24, expands existing data privacy laws by allowing consumers greater control of their personal data and establishing the California Privacy Protection Agency.
CCPA- California Consumer Privacy Act.
CFO- Chief Financial Officer.
Change Advisory Board (CAB)- a group of people who run formal CAB meetings to assess, prioritize, authorize, and schedule changes as part of the change control process. Review changes prior to the meeting. Assess and recommend the approval or rejection of proposed changes in a timely manner.
Change Management- an IT practice designed to minimize disruptions to IT services while making changes to critical systems and services.
Change Management Window- a predefined time when it has been agreed with the business that system changes can be carried out.
CIO- Chief Information Officer
CISO- Chief Information Security Officer
Cleartext - Unencrypted data such as FTP, HTTP, or Telnet and can also mean sensitive information, such as passwords or protected information, stored in an unencrypted format.
CMMC- Cybersecurity Maturity Model Certification- is a tiered framework developed by the U.S. Department of Defense (DoD) to verify that contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) have implemented adequate cybersecurity practices to protect sensitive defense information.
Common Vulnerability Scoring System (CVSS)- an open framework for communicating the characteristics and severity of software vulnerabilities and it provides a way to capture the principal characteristics of a vulnerability and produce a numerical score reflecting its severity.
Confidential Information- all non-public information or material disclosed or provided by one party to the other, either orally or in writing, or obtained by the recipient party from a third party or any other source, concerning any aspect of the business or affairs of the other party or its affiliates, including any information or material pertaining to products, formulae, specifications, designs, processes, plans, policies, procedures, workforce members, work conditions, legal and regulatory affairs, assets, inventory, discoveries, trademarks, patents, manufacturing, packaging, distribution, sales, marketing, expenses, financial statements and data, customer and supplier lists, raw materials, costs of goods and relationships with third parties. Confidential Information also includes any notes, analyses, compilations, studies or other material or documents which contain, reflect, or are based, in whole or in part, on the Confidential Information.
Controller- is a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Controlled Unclassified Information (CUI)- is information that requires safeguarding or dissemination controls consistent with applicable laws, regulations, and Government-wide policies.
COO- Chief Operation Officer.
Corporate Enterprise Management System- large-scale software packages that can track and control all the complex operations of a business. These systems are used as a central command hub to help automate the business and make reporting and decision making easier.
Corporate Ethics- The broad area dealing with the way in which a company behaves towards, and conducts business with, its internal and external stakeholders, including employees, investors, creditors, customers, and regulators.
Corporate Information Systems- contain data that needs to be shared among two or more agency organizations. Corporate systems include any system that is used by or is of benefit to more than one organization to create, update, or delete corporate data.
Credential Service Provider (CSP)- A trusted entity that issues or registers user tokens and issues electronic credentials to users. The CSP may encompass registration authorities (RA) and verifiers that it operates. A CSP may be an independent third party or may issue credentials for its own use.
Critical Failure Alert- High priority alert that requires immediate attention and that has a high impact on company resources and stops business operations. It also causes loss of reputation. This could be ransomware or hardware failure resulting in a security breach.
Cryptography- associated with the process of converting ordinary plain text into unintelligible text and vice-versa. It is a method of storing and transmitting data in a particular form so that only those for whom it is intended can read and process it. Cryptography not only protects data in case of theft or alteration but can also be used for user authentication. Generally there are only two forms of cryptography (Symmetrical and Asymmetrical) however quantum encryption is becoming more popular.
CSO- Chief Security Officer.
CTO- Chief Technology Officer.
Customer Confidential Information- means any information or compilation of information, not known, which is provided to the Company Parties by their customers or potential customers, is proprietary to the customer or potential customer and relates to the customer’s or potential customer’s existing or reasonably foreseeable business.
Customer Production Environments- is where the latest versions of software, products, or updates are pushed live to the intended users. Think of it as the final phase of production. This is the environment where the end user can see, experience, and interact with the new product.
CVS- Common Vulnerability Scan.
CVSS- Common Vulnerability Scoring System
Data- facts and statistics collected for reference or analysis or the quantities, characters, or symbols on which operations are performed by a computer, being stored and transmitted in the form of electrical signals, and recorded on magnetic, optical, or mechanical recording media.
Data Backup- See Backup Data
Data Exposure- is when data is left exposed in a database or server for anyone to see. Sensitive data can include anything from personally identifiable information (PII), such as Social Security numbers, banking information, to login credentials.
Data Processing Register- a record of processing activities that includes significant information about data processing, including data categories, the group of data subjects, the purpose of the processing and the data recipients.
Data Processing Subjects- (also referred to as “Individuals” or “PII Principals”) is an identified, or identifiable, natural person whom data is collected, processed, or stored where the data is associated with the natural person.
Data Recovery Point- recovery point (RPO) and time (RTO) objectives should be defined to adjust the backup configuration appropriately and make sure the objectives can be met.
Data Subjects- (also referred to as “Individuals”) an identified or identifiable natural person to whom personal data relates.
DBA- (Doing Business As) is a legal term that refers to a business under a name different from its officially registered legal name.
DC- Data Center
DD254- Classified Contract where there is classified or sensitive information and how the information must be handled.
Demilitarized Zone (DMZ)- a host or network that acts as a secure and intermediate network or path between an organization's internal network and the external, or non-propriety, network and serves as a section of a network that serves as a neutral territory so as to protect the intranet from outside threats.
Denial of Service (DoS) Attack- an attack meant to shut down a machine or network, making it inaccessible to its intended users. DoS attacks accomplish this by flooding the target with traffic or sending it information that triggers a crash. In both instances, the DoS attack deprives legitimate users (i.e., employees, members, or account holders) of the service or resource they expected.
Denial of Service (DoS) Testing- Testing that results in a device being inaccessible, or functional, to the needs of the company and/or clients of the company.
DEV- Typically stands for "developer" or "development". It can refer to a person who writes code (developer) or the process of creating software (development) or an environment where development occurs.
Develop Branch- A long-lived branch in a Git-based workflow used as the integration branch for ongoing feature development. It is created from the main branch and serves as the base for feature branches and release branches. Completed features are merged into develop, and when a release is finalized, the release branch is merged into both develop and main to incorporate changes and keep all branches up to date.
DevOps- a combination of cultural philosophies, practices, and tools that increases an organization's ability to deliver applications and services at high velocity and evolving and improving products at a faster pace than organizations using traditional software development and infrastructure management processes.
Digital Subscriber Line (DSL)- a form of high-speed Internet access competing with cable modems. DSL works over standard phone lines.
Disaster Recovery (DR)- concerns determining prior to an emergency or disaster how to restore normal business operations after the disaster takes place.
Disaster Recovery Planning (DRP)- is concerned with restoring normal business operations after the disaster takes place.
Discipline- means ethical behavior, living by the values of the organization and fairness in dealing.
Distributed Denial of Service (DDoS) Attack- is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic. DDoS attacks achieve effectiveness by utilizing multiple compromised computer systems as sources of attack traffic.
DLP- Data Loss Protection
Doxing- searching for and publishing private or identifying information about (a particular individual) on the internet, typically with malicious intent.
DR- Disaster Recovery
Dual Homing- Having concurrent connectivity to more than one network from a computer or network device. Examples include: Being logged into the Corporate network via a local Ethernet connection, and dialing into an internet service provider (ISP).
Due Diligence- reasonable steps taken by a person to satisfy a legal requirement.
Eavesdropping- An eavesdropping attack occurs when a hacker intercepts, deletes, or modifies data that is transmitted between two devices. Eavesdropping, also known as sniffing or snooping, relies on unsecured network communications to access data in transit between devices.
EM- Emergency Maintenance.
Encrypt- convert (information or data) into a cipher or code, especially to prevent unauthorized access. Also, to encrypt is to conceal data in (something) by converting it into a code.
Encryption- the process of encoding information. This process converts the original representation of the information, known as plaintext, into an alternative form known as ciphertext.
EOL- End of Life
EOS- End of Support
ERT- Emergency Response Team, see DRP for list.
European General Data Protection Regulation (GDPR)- a legal framework that sets guidelines for the collection and processing of personal information from individuals who live in the European Union (EU). The GDPR will levy harsh fines against those who violate its privacy and security standards, with penalties reaching into the tens of millions of euros.
EVP- stands for Executive Vice President.
Export Administration Regulations (EAR)- are a set of regulations found at 15 C.F.R. § 730. The EAR describes how the US Commerce Department regulates export and export restrictions: whether a person may export something from the U.S.; re-export something from a foreign country; or transfer something from one person to another in a foreign country. The EAR applies to physical objects (referred to as “commodities”) and intellectual property including technology and software.
Feature Branch- A branch is a copy of a code line, managed in a version control system (VCS). A feature branch is a copy of the main codebase where an individual or team of software developers can work on a new feature until it is complete.
FedRamp- Federal Risk and Authorization Management Program- is a U.S. government-wide initiative that standardizes the security assessment, authorization, and continuous monitoring of cloud products and services used by federal agencies.
Federal Contract Information (FCI)- Information provided by or generated for the government under a contract that is not intended for public release. FCI is used to deliver or support the delivery of a product or service to a federal agency, but does not include information that is lawfully available to the public or simple transactional data. While FCI is not classified as Controlled Unclassified Information (CUI), it must still be protected under federal regulations, such as those outlined in FAR 52.204-21.
File or Database Object Permissions- control what user is permitted to perform which actions on a file or database.
File Transfer Protocol Security (FTPS)- a standard communication protocol used for the transfer of computer files from a server to a client on a computer network. FTP is built on a client–server model architecture using separate control and data connections between the client and the server.
FIPS- stands for Federal Information Processing Standards.
Firewall- a part of a computer system or network which is designed to block unauthorized access while permitting outward communication.
Firmware- is a specific class of computer software that provides the low-level control for a device's specific hardware. Firmware is held in non-volatile memory devices such as ROM, EPROM, EEPROM, and Flash memory. Some firmware memory devices are permanently installed and cannot be changed after manufacture. Common reasons for updating firmware include fixing bugs or adding features to the device.
FSO- stands for Facility Security Office, DoD contracts and DD254 or above require an FSO.
Full Disk Encryption- an encryption at the hardware level. Encrypts the entire storage mechanism including swap files, system files, and hibernation files.
GDPR- stands for General Data Protection Regulation. See European General Data Protection Regulation.
Geographical Coverage- All locations where the organization operates, including headquarters, branch offices, and remote work sites including any off-site activities, such as business trips, conferences, and client visits, where employees represent the organization.
Git Commit Hash- similar to how we use fingerprints or retinal scans to identify humans, a hash is a digital signature of compiled software code that allows a person to know if the code has been changed in some way. This allows those that download the compiled code to know that the downloaded code is safe by comparing the public hash to the hash the user performed.
Git Tag- Used to capture the specific point in the history that is further used to point to a released version. A tag does not change like a branch.
Gross Misconduct- Serious behavior or actions that violate fundamental workplace standards and may warrant immediate dismissal. This includes, but is not limited to, acts such as theft, fraud, physical violence, harassment, or any severe breach of company policies, ethical standards, or legal obligations.
Hardened- refers to providing various means of protection in a computer system. Protection is provided in various layers and is often referred to as defense in depth. Protecting in layers means to protect at the host level, the application level, the operating system level, the user level, the physical level and all the sublevels in between. Each level requires a unique method of security.
Hashed- When a password has been “hashed” it means it has been turned into a scrambled representation of itself. A user's password is taken and (using a key known to the site) the hash value is derived from the combination of both the password and the key, using a set algorithm. Files may also be "hashed" to come up with a unique hash value that helps determine if a file has been modified or not.
Hashing- the process of turning a password into a scrambled representation of itself. A user's password is taken and (using a key known to the site) the hash value is derived from the combination of both the password and the key, using a set algorithm.
High Failure Alert- Alerts that are likely to result in demonstrable impact to the company, infrastructure and resources and may likely halt business operations.
Hostile Cybersecurity Event- any real or suspected adverse event in relation to cyber security that violates an explicitly or implicitly applicable security policy resulting in unauthorized access, denial of service or disruption, unauthorized use of a computer resource for processing or storage of information or changes to data, information without authorization. A cybersecurity event may be related to different threats: data breaches and leaks, intentional theft of insider data and trade secrets, privilege abuse, and even phishing attacks.
Hostile Insider- an individual with authorized access to an organization's systems, data, or networks who intentionally misuses that access to cause harm, often for personal gain, revenge, or to benefit an external adversary.
Hostile Party- See Threat Actor
HR- Human Resources
HSM- Hardware Security Module
HTTP- Hypertext Transfer Protocol. An unencrypted protocol commonly used on the Internet and using TCP port 80.
ID- most commonly stands for identification or identity.
IDS- Intrusion Detection Systems - a system that monitors network traffic for suspicious activity and alerts when such activity is discovered.
Impact- (or consequence) refers to the extent to which a risk event might affect the organization.
IMT- Incident Management Team.
Incident- An event that has been identified as having an impact on the security, availability, processing integrity, confidentiality, or privacy of systems and data.
Incident Management (IM)- concerns the activities of the organization to identify, analyze, and correct hazards that could lead to loss or disruption.
Information Resources- The valuable data and information used by an organization and generated by human or processing activities. This includes resources required to produce information, including hardware, software, technical support, users, facilities, data systems, and data.
Information Security Event- Any occurrence related to information assets or the environment indicating a possible compromise of policies or failure of controls or an unmapped situation that can impact security.
Information Security Incident- Any event that threatens the confidentiality, integrity, or availability of organization systems, applications, data, or networks.
Examples of organization systems include, but are not limited to:
- Servers
- Desktop computers
- Laptop computers
- Workstations
- Mobile devices
- Network equipment
Examples of security incidents include:
- Unauthorized access
- Potential violation of company approved policies
- Potential data and privacy breach
- Intentionally targeted but unsuccessful unauthorized access
- Accidental disclosure of confidential data
- Infection by malware
- Denial-of-Service (DoS) attack
- Theft or loss of an organization system or asset
- The theft or physical loss of computer equipment
- Loss or theft of tablets, smartphones, or other mobile devices
- A server known to have sensitive data is accessed or otherwise compromised by an unauthorized party
- A firewall accessed by an unauthorized entity
- A DDoS (Distributed Denial of Service) attack
- The act of violating an explicit or implied security policy
- A virus or worm uses open file shares to infect from one to hundreds of desktop computers
- An attacker runs an exploit tool to gain access to a server's password file
- Any event that affects the availability of our product or service
- Any event that compromises the contractual commitments to our clients
- Failure of information security controls with a likelihood of disrupting business operations
Information Security Management System (ISMS)- defines and manages controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities.
Information System (IS)- An integrated set of components for collecting, storing, and processing data, and for delivering information, knowledge, and digital products to support decision-making and coordination within an organization.
Inherent Risk- The likelihood of an impact occurring when a threat compromises an unprotected asset. The current risk as it appears to the risk assessor before applying any control measures.
Input- what is put in, taken in, or operated on by any process or system.
Input Validation- also known as data validation, is the proper testing of any input supplied by a user or application. Input validation prevents improperly formed data from entering an information system. Because it is difficult to detect a malicious user who is trying to attack software, applications should check and validate all input entered into a system.
Intended Use- the use for which the device or system is designed according to the data supplied by the manufacturer on the labeling, in the instructions, policies, or promotional materials.
International Trafficking in Arms Regulation (ITAR)- a United States regulation to restrict and control the export of defense and military related technologies to safeguard U.S. national security and further U.S. foreign policy objectives.
iOS- The operating system for Apple's iPhone, iPad, and other Apple mobile devices is referred to as iOS.
IoT Devices- pieces of hardware, such as sensors, actuators, gadgets, appliances, or machines, that are programmed for certain applications and can transmit data over the internet or other networks.
IP- Intellectual Property
IPS- Intrusion Prevention Systems - Software that has all the capabilities of an intrusion detection system (IDS) and can also attempt to stop trespass incidents.
IPsec- Internet Protocol Security - a secure network protocol suite that authenticates and encrypts the packets of data to provide secure encrypted communication between two computers over an Internet Protocol network. It is used in virtual private networks (VPNs).
ISO 27001- International Organization for Standardization- internationally recognized standard for an Information Security Management System (ISMS)
IT- Information Technology
IT Asset- refers to anything (tangible or intangible) that has value to an organization, including a computing device, IT system, IT network, IT circuit, software (both installed and physical), virtual computing platform (common in the cloud and virtualized computing), and related hardware (e.g., locks, cabinets, keyboards), as well as people and intellectual property (including software).
Jailbroken (iOS)- A jailbroken device permits root access within the operating system and provides the right to install software not available through the App Store. Apple views jailbreaking as a violation of the end-user license agreement, and strongly cautions device owners not to try to achieve root access through the exploitation of vulnerabilities.
Joint Controllers- are two or more controllers that make decisions on why and how to process personal data.
Key Management- refers to management of cryptographic keys in a cryptosystem. This includes dealing with the generation, exchange, storage, use, crypto shredding (destruction) and replacement of keys. It includes cryptographic protocol design, key servers, user procedures, and other relevant protocols.
Key Phrase- Used to encrypt or decrypt data.
LAN- Local Area Network – A network of interconnected devices that may or may not have access to the Internet.
Least Privilege- Users will only be granted access to data for the purpose of executing their responsibilities and duties. The right to access data shall not be granted unless there is a legitimate business or service need.
Legal Violations- Any conduct that violates local, state, or federal laws.
Likelihood- How often the risk event might happen (e.g. per procedure/episode or within a specified timeframe).
Load Balancer- refers to efficiently distributing incoming network traffic across a group of backend servers, also known as a server farm or server pool.
Locked Print- allows print jobs to be sent securely to the printer and held there until the person who printed physically arrives at the printer to pick the jobs up.
Low Failure Alert- Unlikely to impact business operations, infrastructure, resources and could include onboarding or offboarding of users.
LTS- long-term support.
Malware- software that is specifically designed to disrupt, damage, or gain unauthorized access to a computer system.
Man in the Middle (MitM) Attack- a type of cyberattack in which communications between two parties is intercepted, often to steal login credentials or personal information, spy on victims, sabotage communications, or corrupt data.
Massachusetts General Law Chapter 93H and 201 CMR 17- requires that any companies or persons who store or use personal information (PI) about a Massachusetts resident develop a written, regularly audited plan to protect personal information. Both electronic and paper records will need to comply with the new law. If a Massachusetts resident's information is leaked or captured, there could be grave consequences for the business that allowed the breach and for the individual whose information was leaked. Therefore, making changes to keep residents' information secure will be required to avoid security breaches and fines.
MD5 Hash- a one-way cryptographic function that accepts a message of any length as input and returns as output a fixed-length digest value to be used for authenticating the original message. The MD5 hash function was originally designed for use as a secure cryptographic hash algorithm for authenticating digital signatures.
MDM- Mobile Device Management
Medium Failure Alert- May impact business operations, infrastructure and resources and could include a project or user software or hardware failure.
MFA- Multifactor Authentication, a security process that requires users to provide multiple forms of verification to access an account or system. It adds an extra layer of security beyond just a password, making it significantly harder for unauthorized individuals to gain access.
MFOA- Multiple Factors of Authentication.
Misconduct- means failure to obey orders, rules, or instructions, or failure to discharge the duties for which an individual was employed; Substantial disregard of the employer's interests or employee's duties and obligations to the employer; Carelessness or negligence of such degree or recurrence as to manifest equal culpability or wrongful intent; or Failure to comply with established policies and procedures enforced from time to time.
However, mere inefficiency, unsatisfactory conduct, failure to perform as the result of inability or incapacity, a good faith error in judgment or discretion is not termed as misconduct.
Mobile Device Management (MDM) Software- is a type of security software used by an IT (Information Technology) department to monitor, manage, and secure employees' mobile devices (laptops, smartphones, tablets, etc.) that are deployed across multiple mobile service providers and across multiple mobile operating systems being used in the organization.
Network Attached Storage (NAS)- is a storage device connected to a network that allows storage and retrieval of data from a centralized location for authorized network users and heterogeneous clients. NAS systems are flexible and scale-out, meaning that as you need additional storage, you can add on to what you have.
Network Identifiable Information (NII)- Network information that identifies a person.
NOC- Network Operations Center
On-premise- physically located at the headquarters where SOC 2 is implemented. Can also be referred as "onprem" or "on-prem".
OS- Operating System, also iOS.
Other Critical Incidents- Any other critical incidents as determined by the HR department and senior management that justify immediate termination.
Output Validation- the process of checking your work to determine if your work accomplished what you intended it to accomplish.
Partial Disk Encryption- an encryption method wherein various parts of a storage mechanism are separately encrypted.
Password- A word or phrase used to support authenticating a user or account.
Payment Card Industry Data Security Standard (PCI-DSS)- a set of security standards designed to ensure that ALL companies that accept, process, store or transmit credit card information maintain a secure environment.
PDA- Personal Data Assistant
Penetration Testing- an authorized simulated cyberattack on a computer system, performed to evaluate the security of the system. The test is performed to identify weaknesses (also referred to as vulnerabilities), including the potential for unauthorized parties to gain access to the system's features and data, as well as strengths, enabling a full risk assessment to be completed.
Personal Data- (also referred to as “Data”) any information about an identifiable individual.
Examples of personal data include (but are not limited to):
- Name, date of birth and social security or other identity card number
- Contact information such as mailing address, email address and phone numbers, credit card and financial account numbers.
- Health or medical information
- Information contained in employee files, including employment history and evaluations.
- Information collected during the application and hiring process.
- Information related to employee benefits, such as dependents, beneficiaries, and insurance policy information.
Properly anonymized and de-identified or aggregated data that can not be reverse engineered to determine the natural person(s) is not personal data.
Personal Identifiable Information (PII)- Any representation of information that permits the identity of an individual to whom the information applies to be reasonably inferred by either direct or indirect means.
Physical Access Controls- a security technique that regulates who or what can view or use resources in a computing environment. It is a type of physical security designed to restrict or allow access to a certain area or building. They are often installed to protect businesses and property from vandalism, theft, and trespassing, and are especially useful in facilities that require higher levels of security and protection. Unlike physical barriers like retaining walls, fences or strategic landscaping, physical access control procedures control who, how and when a person can gain entry.
PM- Project Manager, also see SPM.
Privacy Incident- Any event that has resulted in (or could result in) unauthorized use or disclosure of PII/PHI where persons other than authorized users have access (or potential access) to PII/PHI, or use it for an unauthorized purpose.
Privileged Access- a term used to designate special access or abilities above and beyond that of a standard user.
Processor- is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Proprietary Encryption- An algorithm that has not been made public or has not withstood public scrutiny. The developer of the algorithm could be a vendor, an individual, or the government.
Protected Health Information (PHI)- Any information in a medical record that can identify a person.
Pseudonymization- processing personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such information is kept separately.
PT or PST - Pacific Standard Time.
Pull Request- an event that takes place in software development when a contributor or developer is ready to begin the process of merging new code changes with the main project repository.
No entries
RA or RAs- Risk Assessment- a systematic process of evaluating the potential risks that may be involved in a projected activity or undertaking.
RDP - Remote Desktop Protocol - a Microsoft protocol designed to facilitate application data transfer security and encryption between client users, devices, and a virtual network server. It enables a remote user to add a graphical interface to the desktop of another computer. RDP is compatible with multiple types of local area network (LAN) protocols and topologies.
Remote Access- Any access to the corporate network through a non-corporate controlled network, device, or medium.
Remote Wipe- Software that remotely deletes data stored on a remote device.
Removable Media- Device or media that is readable and/or writeable by the end user and is able to be moved from computer to computer without modification to the computer. This includes flash memory devices such as thumb drives, cameras, MP3 players, etc.; removable hard drives; optical disks such as CD and DVD disks; floppy disks and any commercial music and software disks not provided by the company.
Residual Risks- The risk that remains after a safeguard is applied. Residual risk does not take into account potential negative impacts to the organization when safeguards are applied.
Responsibility- The tasks or duties assigned to a specific role.
Restricted Use Data- licensed datasets containing sensitive information or information that enables the potential identification of respondents through inference typically held to higher information security standards to prevent unauthorized disclosure. Data may also be restricted use because of confidentially promises or proprietaries.
Right of Access- a fundamental principle in data protection policies, granting individuals the right to access and control their personal information held by organizations, including knowing what data is being collected about them and requesting corrections or erasure if necessary.
Right of Data Portability- allows individuals to request a copy or transfer of their personal data in machine-readable format, enabling them to move it to another organization.
Right of Erasure- allows individuals to request the deletion or removal of their personal data from an organization's records, in certain circumstances such as no longer being necessary for the original purpose.
Right of Notification- requires organizations to inform data subjects in the event of a personal data breach, providing timely and detailed information about the incident.
Right of Rectification- allows individuals to request corrections or updates to their personal data held by an organization, ensuring that the information is accurate and up to date. This right enables data subjects to correct errors, update outdated information, or dispute incorrect records, which helps maintain the accuracy and reliability of their personal data.
Right of Restriction of Processing- allows individuals to request that an organization limits or suspends processing of their personal data, in cases such as inaccurate information or marketing purposes.
Right to Object- allows individuals to object to the processing of their personal data, including for direct marketing purposes or profiling.
Right to Object to Automated Processing or Profiling- allows individuals to object to the automated processing or profiling of their personal data, including decisions based on automated methods.
Risk- is a function of the likelihood of a given threat source exercising a particular potential vulnerability, and the resulting impact of that adverse event on the organization.
Risk Management- the forecasting and evaluation of potential threats together with the identification of procedures to avoid or minimize their impact.
Risk Owner- A risk owner is an accountable point of contact for an enterprise risk at the senior leadership level. Leadership may delegate coordination efforts to mitigate and manage the risk with various individuals who own parts of the risk.
Risk Rating- A measurement of the risk useful for assessing the priority for control measures for the treatment of different risks.
Role- A specific position or job title within the organization.
Role Based Access- Users will be assigned access rights to data based on functional roles they assume while performing company related business.
Root- the process by which one gains access to the administrative commands and functions of an operating system. The highest level user in Linux based environments.
Rooted (Android)- Rooting is the process of allowing users of the Android mobile operating system to attain privileged control (known as root access) over various Android subsystems.
RSA- an asymmetric algorithm that uses a publicly known key for encryption, but requires a different key, known only to the intended recipient, for decryption. In this system, appropriately called public key cryptography (PKC), the public key is the product of multiplying two huge prime numbers together.
SaaS- Software as a Service.
Safety Violations- Actions that pose a significant threat to the safety and well-being of employees, clients, or the public.
Salted- Key derivation functions take a password, a salt, and a cost factor as inputs then generate a password hash. Their purpose is to make each password guessing trial by an attacker who has obtained a password hash file expensive and therefore the cost of a guessing attack high or prohibitive.
SCD- Secure Cryptographic Device
SDT- Scheduled Down Time.
Secret(s)- Information such as password, key, or other confidential information. SECRET can also refer to a classification of information relating to National Security.
Secure File Transfer Protocol (SFTP)- Network protocol that provides file access, file transfer, and file management functionalities over any reliable data stream.
Secure Shell (SSH)- a cryptographic network protocol for operating network services securely over an unsecured network. Its most notable applications are remote login and command-line execution.
Secure Socket Layer (SSL) Virtual Private Network (VPN)- is a virtual private network (VPN) created using the Secure Sockets Layer (SSL) protocol to create a secure and encrypted connection over a less-secure network, such as the Internet.
Security Breaches- Unauthorized access or misuse of company information, data breaches, or compromising the integrity of the organization’s systems.
Security Incident- Any event that threatens the confidentiality, integrity, or availability of organization systems, applications, data, or networks.
Examples of organization systems include, but are not limited to:
- Servers
- Desktop computers
- Laptop computers
- Workstations
- Mobile devices
- Network equipment
Examples of Security Incidents include, but aren't limited to:
- Unauthorized access
- Intentionally targeted but unsuccessful unauthorized access
- Accidental disclosure of Confidential Data
- Infection by malware
- Denial-of-service (DoS) attack
- Theft or loss of an organization system
- The theft or physical loss of computer equipment known to store SSNs
- Loss or theft of tablets, smartphones or other mobile device
- A server known to have sensitive data is accessed or otherwise compromised by an unauthorized party
- A firewall accessed by an unauthorized entity
- A DDoS (Distributed Denial of Service) attack
- The act of violating an explicit or implied security policy
- A virus or worm uses open file shares to infect from one to hundreds of desktop computers
- An attacker runs an exploit tool to gain access to a server's password file.
Segregation of Duties- where any one user doesn't have the ability to perform activities without another person involved.
Sensitive Information- Information, which, if made available to unauthorized persons, may adversely affect the company, its programs, or participants served by its programs. Examples include, but are not limited to, personal identifiers and, financial information.
Server- A device that performs activities and runs services to support users or other external activities.
Service- A program that runs on a server to perform activities.
Service Level Agreement (SLA)- a service-level agreement is a commitment between a service provider and a client. Aspects of the service – quality, availability, responsibilities – are agreed between the service provider and the service user.
SFTP- An encrypted version of FTP
Single Sign On (SSO)- a session and user authentication service that permits a user to use one set of login credentials (for example, a name and password) to access multiple applications. SSO can be used by enterprises, smaller organizations, and individuals to ease the management of various usernames and passwords.
SLA- Service Level Agreements.
SNMP- Simple Network Management Protocol. There are currently three different versions of SNMP with each version more secure than the previous version.
SOC- Security Operations Center
SOC 2- System and Organization Controls 2. It's a compliance and privacy standard developed by the American Institute of Certified Public Accountants (AICPA) that assesses how service organizations manage sensitive customer data and related systems.
Social Responsibility- means that businesses, in addition to maximizing shareholder value, should act in a manner that benefits society.
Solid-State Drives (SSDs)- a storage device that uses integrated circuit assemblies to store data persistently, typically using flash memory, and functioning as secondary storage in the hierarchy of computer storage.
SOW- Statement of Work.
SPAM- "spam" as it refers to unsolicited emails or messages is not a true acronym. While some humorous "backronyms" exist, like "Stupid Pointless Annoying Messages".
Special Categories of Personal Data- certain types of sensitive personal data subject to additional protection under the GDPR.
Special categories of personal data include:
- Personal data revealing racial or ethnic origin
- Personal data revealing political opinions
- Personal data revealing religious or philosophical beliefs
- Personal data revealing trade union membership
- Genetic data and biometric data processed to uniquely identify a natural person
- Data concerning health
- Data concerning a natural person’s sex life or sexual orientation
Split-Tunneling- Simultaneous direct access to a non-corporate network (such as the Internet, or a home network) from a remote device while connected into the corporate network via a VPN tunnel. VPN Virtual Private Network (VPN) is a method for accessing a remote network via "tunneling" through the Internet.
SPM- Stockholder Project Manager, also see PM.
SSH- Secure Shell Version 1
SSH2- Secure Shell Version 2.
SSN- Social Security Number(s) or SSNs.
Stakeholder- Individuals or groups who have a vested interest in the alert or incident, including IT staff, management, and affected clients.
Storage Area Network (SAN)- A specialized, high-speed network that provides block-level access to consolidated data storage. SANs are typically used to connect servers to storage devices such as disk arrays and tape libraries, making them appear as locally attached drives to the operating system. SANs are separate from the local area network (LAN) and are composed of hosts, switches, storage devices, and other components interconnected through various technologies and protocols.
Symmetric Cryptosystem- A method of encryption in which the same key is used for both encryption and decryption of data.
System Log- a direct access data set that stores messages and commands.
Tailgating- Form or method of skirting security by proximity. Physically or digitally.
Technology Asset- An item of value to achieve organizational mission/business objectives including computer systems, communication systems, software and hardware owned, used, or licensed by the company as licensee. An asset may be tangible (e.g., physical item such as hardware, software, firmware, computing platform, network device, or other technology components) or intangible (e.g., information, data, trademark, copyright, patent, intellectual property, image, or reputation).
Telnet- an unencrypted method to issue commands and perform functions on a remote device. SSH and SSHv2 are upgrades to Telnet in that both are encrypted in transmission.
Terms of Service- the legal terms that set forth the nature, scope, and limits of a service (such as one offered through a website or an app) and the rules that the service's users must agree to follow.
Test Restores- a process that is performed on a frequent basis to ensure the network backup system is working at the optimum level.
Threat- The potential for a threat source to exercise either accidentally trigger or intentionally exploit a specific vulnerability.
Threat Actor- a hostile party, regardless of if internal or external, that threatens the security of the company.
TLS (Transport Layer Security)- a cryptographic protocol designed to provide communications security over a computer network. The protocol is widely used in applications such as email, instant messaging, and voice over IP, but its use in securing HTTPS remains the most publicly visible.
TRUE- stands for "True" from typically a true or false question, standard value of 1 or an ASCII Value of "Y" for Yes. The opposite of TRUE would be FALSE with a value of 0.
Unauthorized Personnel- any individual or individuals not given specific authorization by the licensee or certified applicator to enter areas to which access is restricted by a given set of rules.
Unicode- The Unicode Standard is the universal character representation standard for text in computer processing.
Unintended Use- repurposing a device or system for use in another way, usually for a purpose unintended by the system or device owner or manufacturer.
Unrestricted Data- is public data information that may be disclosed to any person regardless of their affiliation with the company.
URL- stands for Uniform Resource Locator, typically on the internet, whereas URI means that it is not on the internet.
Virtual Private Network (VPN)/ Secure Sockets Layer (SSL)- is a virtual private network (VPN) created using the Secure Sockets Layer (SSL) protocol to create a secure and encrypted connection over a less-secure network, such as the Internet.
Visitor- is person or persons that has an appointment with a company employee or contractor, this does not include delivery personnel.
VLAN- Virtual Local Area Network
VNC (Virtual Network Computing)- A remote desktop sharing protocol that allows users to control another computer over a network connection. VNC transmits the keyboard and mouse input from the client device to the remote server and sends back the graphical display updates in real time. It is commonly used for remote support, administration, and access to systems across different platforms.
VoIP Phones- uses voice over IP technologies for placing and transmitting telephone calls over an IP network, such as the Internet. This contrasts with a standard phone which uses the traditional public switched telephone network (PSTN).
VPN- Virtual Private Network
Vulnerability- A weakness that could permit a threat to compromise the security of information assets.
Vulnerability Testing- the process of identifying, quantifying, and prioritizing (or ranking) the vulnerabilities in a system.
WAN- Wide Area Network
WAP- Wireless Access Point
Web Channel- a combination of various web services. One web channel can provide many services such as videos, news, and discussion.
WLAN- Wireless Local Area Network
Workstations- Includes laptops, desktops, tablets, phones, PDAs, computer-based equipment containing or accessing customer information and authorized home workstations accessing the corporate network.
Worm- a malicious, self-replicating program that can spread throughout a network without human assistance. Worms cause damage like viruses, exploiting holes in security software and potentially stealing sensitive information, corrupting files, and installing a back door for remote access to the system, among other issues. Worms often utilize copious amounts of memory and bandwidth, so affected servers, networks, and individual systems are often overloaded and stop responding.
WTL- Write to Log.
Xfree- Stands for remote desktop, though the software is open source and typically only works with Linux, or Linux like software with X desktop protocol.
No entries
No entries
Arrakis YouTube Channel
- https://www.youtube.com/@arrakisconsulting
Individual Videos
- Why Cybersecurity Reviews are Crucial in M&A
- Understanding Ransomware....protect your business!
- ISO27001 vs SOC2...which one is better?
- What Makes ISO 21502 Project Management Training So EFFECTIVE?
- How to protect your business without breaking the bank
- Why small businesses need cyber protection now!
- How ISO 42001 keeps AI security strong in 2025!
- Why skipping software updates could cost you big!
- Why cyber criminals want YOUR info!
- Could failing CMMC cost you big money?
- Why every project needs cybersecurity now!
- Shocking ways hackers get inside buildings!
- Understanding the ISO 27001 Audit Process
- Can vendor checks save your business?
- Travel smart - Navigating cybersecurity while on the road
- The true cost of cyberattacks - Protect your business with Arrakis Consulting!
- Can your business survive a huge fine?
- Is your business ready for the new digital rules? DORA!!!
- PADFA US Data Privacy Law 2024 changes everything
- Why GDPR compliance can save your company
- Mastering NIST800.53, a cybersecurity blueprint
- AI Security threats are getting smarter - Here's what you must know
- How will AI reshape digital security in 2025?
- Why government contractors MUST know about the False Claims Act!
- Is your business losing money from these compliance errors?
- Are your Employees secretly your biggest security risk?
- Small Companies are loosing MILLIONS to these Security Mistakes
- The Hidden Network Threats that Could DESTROY your Business
- Modern Cybersecurity Made Simiple - Protect your data NOW!
- Future Proofing Cybersecurity - What you need to know
- AI Regulation just changed forever and here's why
- Is your company ready for a MAJOR business disruption? Consider a BIA.
- Preparing for data breaches
- Beyond Compliance - Elevating your cybersecurity standards
- Phishing Unveiled - protecting your organization from cyber threats
- Risk Assessments - An unbiased view of compliance
- How our 3-phase system makes compliance easy
- SPAM, the hidden costs - protecting your business and productivity
- Safeguard your business - the power of continuity planning and how Arrakis Consulting can help
- Mastering GDPR Compliance: A guide for global businesses
- Short bio on Arrakis Consulting and some of the services we offer
- How does the 2025 DOJ Data Protection Law affect your privacy?
- Why penetration testing is essential
- Achieve 27001 certification with Arrakis Consulting
- Simplify your next audit with Arrakis Consulting
- Mastering SOC2 compliance with Arrakis Consulting
- Mastering 27001 - Your path to cybersecurity success
- Unlocking Audit Success with Arrakis Consulting
- Streamline Compliance with Arrakis Managed Services (MSP)
- Why vendor due diligence (VDD) is crucial for your business
- Achieving CMMC compliance with Arrakis Consulting
- How much money can non compliance REALLY cost your business?
- CMMC Compliance, a guide for defense contractors
- CMMC Compliance is vital for national security
- Terrifying truth behind insider threat
- CIOReview about Arrakis Consulting
- CMMC Podcast with Apptega
- Episode 29 - High level discussion about penetration testing
- Episode 28 - How to spot SCAMS and PHISHING emails
- Episode 27 - Cracking passwords
- Episode 26 - OSINT
- Episode 25 - Choosing a Cybersecurity Provider
- Episode 24 - DoD/TCPIP Model
- Episode 23 - OSI Model - Application Layer
- Episode 22 - OSI Model - Presentation Layer
- Episode 21 - OSI Model - Session Layer
- Episode 20 - OSI Model - Physical Layer
- Episode 19 - OSI Model - Transport Layer
- Episode 18 - OSI Model - Network Layer
- IP Addresses and how Routers Process them
- Episode 17 - OSI Model - Datalink Layer
- Episode 16 - OSI Model - High Level OSI Model Discussion
- Episode 15 - Subnetting
- Episode 14 - MSP and IT Company Liability
- Episode 13 - Binary to Decimal Conversion
- Episode 12 - Certifications in Greater Detail
- Episode 11 - Administrative Controls
- Episode 10 - Certifications
- Episode 9 - Cyberinsurance
- Episode 8 - Audits
- Episode 7 - Risk Management
- Episode 6 - High Level Discussion about Risk!!!
- Episode 5 - Privacy
- Episode 4 - BCDR
- Episode 1 - Arrakis Video Series
- Arrakis contributions to ISO27001:2022 whitepaper
- ISO27002 Webinar Recording
- Arrakis article on CMMC
- Penetration Testing Webinar
- Meeting Regulatory Requirements
- "Best Practice"
- Medical Device Online Article
- Lodging Magazine Article
- Cracking passwords with Hashcat