An act or event that exploits a vulnerability seeking to cause a loss to an information asset.
bottom- up approach
An implementation approach that uses grass- roots effort in which systems administrators attempt to improve the security of their systems.
champion
"A member of the senior management of an organization who seeks to promote the successful outcome of a project or initiative by providing visibility
chief information officer (CIO)
The most senior manager or executive responsible for information technology and systems in an organization.
chief information security officer (CISO)
The most senior manager or executive responsible for information security in an organization.
chief security officer (CSO)
The most senior manager or executive responsible for physical and information security in an organization; sometimes misapplied to a functional CISO to follow industry trend.
controls
Those means undertaken to reduce the risk that information assets face from attacks by threats. Also known as safeguards.
data custodians
"Individuals who work directly with data owners and are responsible for the storage
data owners
"Individuals who control (and are therefore responsible for) the security and use of a particular set of information. Data owners may rely on custodians for the practical aspects of protecting their information
data users
"Systems users who work with the information to perform their daily jobs supporting the mission of the organization
ethical hackers
See white- hat hackers.
event- driven
"Refers to a corrective action that is in response to some event in the business community
"governance
risk management
joint application design (JAD)
"A process in which designers
managerial controls
"Processes or tools that define
methodology
A formal approach to solving a problem based on a structured sequence of procedures.
operational controls
"Processes or tools that deal with the operational functionality of security in the organization. They cover management functions and lower- level planning
penetration testing
A process in which security personnel simulate or perform specific and controlled attacks to compromise or disrupt systems by exploiting documented vulnerabilities.
plan-driven
Refers to a corrective action that is the result of a carefully developed planning strategy.
red teams
See white- hat hackers.
risk assessment
A process that assigns a comparative risk rating or score to each specific information asset. This enables the organization to gauge the relative risk introduced by each vulnerable information asset and allows comparative ratings later in the risk control process.
risk management
"A process that identifies vulnerabilities in an organization's information system and takes carefully reasoned steps to assure the confidentiality
safeguards
See controls.
security manager
A supervisory- level member of an organization accountable for some or all of the day- to-day operation of an InfoSec program.
security technician
"A technically qualified individual who may configure firewalls and IDPSs
stakeholder
"Those entities
strategic planning
"A process to lay out the long- term direction to be taken by an organization to guide organizational efforts and focus resources toward specific
structured review
"A process during which a project design team and its management- level reviewers decide whether a project should be continued
technical controls
Means by which technical approaches are used to implement security in the organization.
threat
An entity with the potential to damage or steal an organization's information or physical assets.
threat agent
A specific instance of a threat.
tiger teams
See white- hat hackers.
top- down approach
"A security approach in which upper- management directs actions and provides support and in which high- level managers provide resources; give direction; issue policies
vulnerability
An identified weakness of a controlled information asset resulting from absent or inadequate controls.
vulnerability assessment
A process of evaluating possible vulnerabilities in order to distinguish actual weaknesses from false reports.
white-hat hackers
"Persons given authority to engage in penetration testing in order to discover systems weakness that can be controlled to improve security. Also known as ethical hackers
Author
geggart
ID
258706
Card Set
ch02.csv
Description
BAKER ITS305 Management of Information Security Chap 2