Untitled Document
 
Friday, September 10, 2010
 You are here: Resources * Glossary and Definitions   Search
Glossary and Definitions

   Filters:  #   A   B   C   D   E   F   G   H   I   J   K   L   M   N   O   P   Q   R   S   T   U   V   W   X   Y   Z   All

Assets

Things, either tangible or not, that an attacker is likely to want to obtain

 

Attack surface

This is a representation of the amount of exposure that a system has. For example, if a system is on the Internet it has a larger attack surface then a system that is internal. This is because more entities have access to the system on the Internet than do internally.

 

Attack vector

This represents the combination of the method and access point that an attacker could use to attack the system.

 

Attacker

Entity who desires access to system resources or wishes to perform actions on a system that they are not authorized to do

 

Audit

The process of accumulating records of activities on a system. This typically includes the act of monitoring and responding to these activities. Auditing is never performed in real time and is considered a detective control.

 

Authentication

The process of asserting an identity

 

Authorization

The process of ensuring that an entity that has asserted its identity has the right to access the resource in question

 

Availability

This represents a systems ability to be online and ready to accept requests

 

    
Glossary Feedback

Contribute to the Glossary!

If you have any suggestions for additions to the glossary, please submit your suggestions below.

    





Cancel   Send
Now Available!
    
 
Premium Sponsors
    
Gold Sponsors
    
Advertise With Us
    
 
 
   Privacy Statement  |  Terms Of Use
Copyright (c) 2010 CISO/CSO Handbook