Chief Financial Officer (CFO) - An executive position in an organization responsible for managing the financial actions of the company. This includes tracking cash flow, financial planning, analyzing the company's financial strengths and weaknesses, and proposing corrective actions.
Hardware disposal procedures - A set of guidelines and methods for disposing of computer hardware that is no longer needed or has reached the end of its useful life. Proper hardware disposal procedures ensure that sensitive data stored on the hardware is securely erased and that environmental regulations are followed.
Data retention policy - A policy that outlines how long different types of data must be kept, where it should be stored, and how it should be disposed of when it is no longer needed. A data retention policy is important for ensuring compliance with legal and regulatory requirements and for managing storage costs.
Random Access Memory (RAM) - A type of computer memory that allows data to be accessed quickly in random order. RAM is volatile memory, which means that it loses its contents when power is turned off.
OCTAVE - Operationally Critical Threat, Asset, and Vulnerability Evaluation: a risk management framework developed by the CERT Coordination Center at the Software Engineering Institute (SEI) at Carnegie Mellon University. OCTAVE is a self-directed risk management framework that helps organizations identify and prioritize risks and develop strategies for mitigating those risks.
PROM - Programmable Read-Only Memory: a type of memory that can be programmed once and then can only be read. PROM chips are often used for firmware or embedded system applications.
Flash memory - A type of non-volatile memory that can be electrically erased and reprogrammed. Flash memory is often used for portable devices like USB drives, digital cameras, and smartphones.
SSD - Solid-State Drive: a storage device that uses flash memory to store data. SSDs are faster and more reliable than traditional hard drives but are also more expensive.
Data in use - Refers to data that is currently being accessed or processed by a computer system. Protecting data in use requires implementing measures like clean desk policies, print policies, and password-protected screensavers.
Sensitivity labels - Used to indicate the level of sensitivity of data and how it should be handled. Factors that influence sensitivity labels include the value of the data, who will access it, and the potential impact of a disclosure.
Data owner: a person or group responsible for managing and making decisions about the security and use of a particular set of data.
Tailoring: the process of customizing a standard or framework to fit the specific needs and requirements of a particular organization.
Data at rest: refers to data that is stored and not actively being used or processed, such as data stored on disks, tapes, CDs/DVDs, or USB sticks.
Unclassified information: refers to information that is not sensitive and whose unauthorized disclosure will not cause harm to national security.
Certification: the process of verifying that a system meets the security requirements of the data owner, including evaluating the system and the security measures in place to protect it.
Data in Use - refers to the state of data when it is actively being used and cannot be encrypted.
Backup tapes - refers to a storage medium that is used to store backup copies of data.
SSD drives - Solid State Drives (SSD) are a type of data storage device that use NAND-based flash memory to store data.
Encryption - the process of converting data into a code to protect it from unauthorized access.
Tape backups - refers to the process of storing data on magnetic tape for backup and recovery purposes.
Data compromise - refers to the unauthorized access, use, disclosure, or destruction of sensitive data.
Data remanence - refers to the residual data that remains on storage devices even after they have been erased or formatted.
Wall or floor safe - refers to a secure storage device that is embedded in a wall or floor and is often used to store valuable or sensitive items.
Man-in-the-middle attack - refers to a type of cyber attack where the attacker intercepts communications between two parties to steal or modify information.
Read-Only Memory (ROM): a type of non-volatile memory that is used in computers and electronic devices to store permanent data that cannot be changed or modified after manufacture.
Programmable Read-Only Memory (PROM): a type of non-volatile memory that can be programmed only once and cannot be modified afterwards.
Erasable Programmable Read-Only Memory (EPROM): a type of non-volatile memory that can be erased and reprogrammed multiple times using ultraviolet light.