Wednesday, June 19, 2013 Register
 
Glossary Feedback

Contribute to the Glossary!

If you have any suggestions for additions to the glossary, please submit your suggestions below.

Glossary and Definitions

   Filters:  #   A   B   C   D   E   F   G   H   I   J   K   L   M   N   O   P   Q   R   S   T   U   V   W   X   Y   Z   All

Sarbanes-Oxley Act

The Sarbanes-Oxley Act of 2002, was signed into law by US President George W. Bush and became effective on July 30, 2002.The Act contains major changes for publicly traded securities, auditors, corporate board members, and lawyers. It focuses on identifying and then  punishing people who perform corporate fraud and corruption.

 

SASs 55/78

A set of processes, subsystems, and people that lead to effective & efficient operations, reliable financial reporting, and compliance with laws & regs.

 

Section 208: Privacy Compliance (EGOV) for Federal Agencies

In 2003, the OMB issued Guidance for implementing Section 208, the Privacy Provisions of the E-Government Act of 2002. This update deals with the posting of privacy policies, use of tracking technologies, and parental consent requirements. Agencies were to submit a report of their compliance plans annually.

 

Section 508: Accessibility Compliance for Federal Agencies

Section 508 of the Rehabilitation Act Amendments of 1998 requires all US federal agencies to make their information technology accessible to their employees and customers with disabilities.

 

Secure Data Handling

Formal, structure, and consistent procedures by which employees manage data during the performance of their daily tasks.

 

Secure Programming Standards

Tools and techniques for objectively and consistently applying security during the process of software development.

 

Secure Standard Builds

The documented repeatable process for building, deploying, updating, and decommissioning computer systems

 

Secure Storage

Tools that enforce the concept of “Least Privilege” for material that is housed in centralized, shared storage. 

 

Security Architect

The role of the security architect is to act as a conduit between related, yet different disciplines, while maintaining a focus on security. One or more individuals who possess the ability to accumulate and comprehend information, process it, formulate solutions that conform to the security policies of the organization, and communicate them to the target audience in an understandable manner.

 

Security Policies

Policies, procedures, and guidelines that represent the ideal security state of the organization. This is the basis for all security work within the project portfolio and the roles and responsibilities

 

Security Policy Compliance

An ability to measure conformance with documented security policies.

 

Security Program

The encapsulation of an organization's security strategy.

 

Security Project Portfolio

A prioritized listing of projects based on risk that a security office will undertake

 

Separation of Duties

A concept that no single individual has controls over two or more phases of a transaction or operation, so that a deliberate fraud or damage is more difficult to occur.

 

Software Quality Assurance Process

The structured process used to objectively measure the quality and security of software prior to deployment.

 

Spoofing

The act of assuming the identity of an entity that preferably has access to a wanted resource or can perform a requested action

 

Spyware

When a third party pries into a system and gathers knowledge without the system ever discovering them, all the while reporting back to the party and giving up you unique data.

 

Surveillance

Mechanisms to automate the process of monitoring and recording events that occur throughout the facilities of the organization.

 

System Log

A record of transactions that have be executed on a given system.

 

Systems Administration

Procedures for adding, changing, and deleting access to systems within the environment. 

 

Systems Auditability and Control (SAC)

A set of processes, subsystems, and people that lead to effective & efficient operations, reliable financial reporting, and compliance with laws & regs

 

Systems Dev Life Cycle (SDLC)

The existence of a documented SDLC that includes the inclusion of appropriate security controls such as checkpoints, secure code review, and developer training

 




Send

 
Premium Sponsor
Delphiis :: Control What You Can
CISOHandbook.com Founder Tweets
Buy Now on Amazon
                        
 


Stay Up To Date
xml.gif 
Gold Sponsors
GRC for Free!
Latus Free Checklist
Ostendo Group
Information Security Today
Computer Economics
Advertise with us?