Vocabulary 1
Vocabulary 2
Random
Standards & Best Practices
CS Objectives
100

The collection of tools, policies, security concepts, security safeguards, guidelines, risk management approaches, actions, training, best practices, assurance and technologies that are used to protect the cyberspace environment and organization and user’s assets.

Cybersecurity

100

A set of rules and practices that specify or regulate how a system or organization provides security services to protect sensitive and critical system resources.

Security Policy

100

What are:

Identify, Protect, Detect, Respond, and Recover


Functions of the Cybersecurity Framework

100

This provides an understanding about cybersecurity and threats online in a way that people outside the technology field can understand.

5 Laws of Cybersecurity 

100

The property that data is not disclosed to system entities unless they have been authorized to know the data.

Confidentiality

200

A danger to organizations, employees, and consumers. They may be designed to access or destroy sensitive data or extort money. They can, in effect, destroy businesses and damage people’s financial and personal lives.

Cyber Attacks

200

Data contained in an information system; or a service provided by a system; or a system capability, such as processing power or communication bandwidth; or an item of system equipment; or a facility that houses system operations and equipment.

Asset

200

A repeating cycle; an ongoing proces that includes the steps below:  

1) Assess and Address the risk.  2) Implement the risk management decision.  3) Monitor, review, and communicate the risk.  4) Update and improve the controls



Cybersecurity Management Process

200

A business-focused guide to identifying and managing information security risks in organizations and their supply chains.  Organized into 3 activities

Standard of Good Practice for Information Security

200

The property that data has not been changed, destroyed, or lost in an unauthorized or accidental manner.

Integrity

300

Term used to describe the non-physical terrain created by computer systems. 

Cyberspace

300

A measure of the extent to which something is threatened by a potential circumstance or event or an examination of the impact that would arise if the circumstance or event occurs or the likelihood that the circumstance or event could happen.

Risk

300

What is listed below?

1. If There Is A Vulnerability, It Will Be Exploited  2. Everything Is Vulnerable In Some Way            3.  Humans Trust Even When They Shouldn’t       4. With Innovation Comes Opportunity For Exploitation.                                                      5. When In Doubt, See No. 1

The 5 Laws of Cybersecurity

300

Provide a globally recognized framework for best-practice information security management.  These security standards help organizations keep their information assets secure, such as their financial information, employee details and intellectual property.

ISO 27000 Suite of information Security Standards

300

The property of a system or a system resource being accessible or usable or operational upon demand, by an authorized system entity, according to performance specifications for the system.

Availabiltiy

400

A flaw or weakness in a system’s design, implementation, or operation and management that could be exploited to violate the system’s security policy.

Vulnerability

400

Preservation of confidentiality, integrity and availability of information.

Information Security

400

Assurance that the sender of information is provided with proof of delivery and the recipient is provided with proof of the sender’s identity, so neither can later deny having processed the information.

Non-repudiation

400

A nonprofit community of organizations and individuals seeking actionable security resources.

The Center for Internet Security (CIS)

400

The property of being genuine and being able to be verified and trusted.

Authenticity

500

An action, a device, a procedure, or a technique that reduces a threat, a vulnerability, or an attack by eliminating or preventing it, by minimizing the harm it can cause, or by discovering and reporting it so that corrective action can be taken.

Counter Measure

500

Protection of networks and their services from unauthorized modification, destruction, or disclosure and provision of assurance that the network performs its critical functions correctly and that there are not harmful side effects.

Network Security

500

What is listed below? 

Scale and complexity of cyberspace.  Nature of the threat.  User needs versus security implementation. Difficulty estimating costs and benefits

Cybersecurity Challenges

500

This document provides a policy framework of computer security guidance for how organizations in the United States can assess and improve their ability to prevent, detect, and respond to cyber attacks

 NIST Cybersecurity Framework

500

The property of a system or system resource ensuring that the actions of a system entity may be traced uniquely to that entity, which can then be held responsible for its actions.  

Accountability

M
e
n
u