The collection of tools, policies, security concepts, security safeguards, guidelines, risk management approaches, actions, training, best practices, assurance and technologies that are used to protect the cyberspace environment and organization and user’s assets.
Cybersecurity
A set of rules and practices that specify or regulate how a system or organization provides security services to protect sensitive and critical system resources.
Security Policy
What are:
Identify, Protect, Detect, Respond, and Recover
Functions of the Cybersecurity Framework
This provides an understanding about cybersecurity and threats online in a way that people outside the technology field can understand.
5 Laws of Cybersecurity
The property that data is not disclosed to system entities unless they have been authorized to know the data.
Confidentiality
A danger to organizations, employees, and consumers. They may be designed to access or destroy sensitive data or extort money. They can, in effect, destroy businesses and damage people’s financial and personal lives.
Cyber Attacks
Data contained in an information system; or a service provided by a system; or a system capability, such as processing power or communication bandwidth; or an item of system equipment; or a facility that houses system operations and equipment.
Asset
A repeating cycle; an ongoing proces that includes the steps below:
1) Assess and Address the risk. 2) Implement the risk management decision. 3) Monitor, review, and communicate the risk. 4) Update and improve the controls
Cybersecurity Management Process
A business-focused guide to identifying and managing information security risks in organizations and their supply chains. Organized into 3 activities
Standard of Good Practice for Information Security
The property that data has not been changed, destroyed, or lost in an unauthorized or accidental manner.
Integrity
Term used to describe the non-physical terrain created by computer systems.
Cyberspace
A measure of the extent to which something is threatened by a potential circumstance or event or an examination of the impact that would arise if the circumstance or event occurs or the likelihood that the circumstance or event could happen.
Risk
What is listed below?
1. If There Is A Vulnerability, It Will Be Exploited 2. Everything Is Vulnerable In Some Way 3. Humans Trust Even When They Shouldn’t 4. With Innovation Comes Opportunity For Exploitation. 5. When In Doubt, See No. 1
The 5 Laws of Cybersecurity
Provide a globally recognized framework for best-practice information security management. These security standards help organizations keep their information assets secure, such as their financial information, employee details and intellectual property.
ISO 27000 Suite of information Security Standards
The property of a system or a system resource being accessible or usable or operational upon demand, by an authorized system entity, according to performance specifications for the system.
Availabiltiy
A flaw or weakness in a system’s design, implementation, or operation and management that could be exploited to violate the system’s security policy.
Vulnerability
Preservation of confidentiality, integrity and availability of information.
Information Security
Assurance that the sender of information is provided with proof of delivery and the recipient is provided with proof of the sender’s identity, so neither can later deny having processed the information.
Non-repudiation
A nonprofit community of organizations and individuals seeking actionable security resources.
The Center for Internet Security (CIS)
The property of being genuine and being able to be verified and trusted.
Authenticity
An action, a device, a procedure, or a technique that reduces a threat, a vulnerability, or an attack by eliminating or preventing it, by minimizing the harm it can cause, or by discovering and reporting it so that corrective action can be taken.
Counter Measure
Protection of networks and their services from unauthorized modification, destruction, or disclosure and provision of assurance that the network performs its critical functions correctly and that there are not harmful side effects.
Network Security
What is listed below?
Scale and complexity of cyberspace. Nature of the threat. User needs versus security implementation. Difficulty estimating costs and benefitsCybersecurity Challenges
This document provides a policy framework of computer security guidance for how organizations in the United States can assess and improve their ability to prevent, detect, and respond to cyber attacks
NIST Cybersecurity Framework
The property of a system or system resource ensuring that the actions of a system entity may be traced uniquely to that entity, which can then be held responsible for its actions.
Accountability