Board direction: The strategic guidance and direction provided by the governing board of an organization.
Data at rest: Refers to data that is stored in persistent storage, such as on a hard drive or in a database, and is not actively being transmitted over a network.
Encryption: The process of converting data into a coded language that can only be read by authorized parties.
SRAM: Static random-access memory is a type of computer memory that retains its contents as long as power is applied and is commonly used for CPU caches.
Mandatory Access Control: A security model that restricts access to resources based on the clearance level assigned to a subject, such as a user or process.
Data remanence: Refers to the residual representation of data that remains even after attempts have been made to remove or erase it.
Data disposal: The process of properly disposing of data storage devices to prevent unauthorized access to sensitive data.
Information lifecycle: The stages through which information passes, including acquisition, use, retention, and disposal.
Degaussing: The process of erasing data from a magnetic storage device, such as a hard drive, by applying a strong magnetic field to the device.
Data retention: The practice of keeping data for a specified period of time, either because it is still useful or because regulations require it.
Sensitivity labels: A system for classifying data based on its sensitivity and value to the organization.
EEPROM: Electrically Erasable Programmable Read Only Memory is a type of non-volatile memory that can be programmed and erased electrically, typically used in computers to store the BIOS.
Attack vector: A means by which an attacker can gain unauthorized access to a system or data.
Personally Identifiable Information (PII): Any information about an individual that can be used to distinguish or trace an individual's identity, such as name, social security number, date and place of birth, mother's maiden name, or biometric records, and any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information.
Formal Access Approval: A document from the data owner approving access to the data for the subject. The subject must understand all requirements for accessing the data and the liability involved if compromised, lost or destroyed. Appropriate Security Clearance is required as well as the Formal Access Approval.
Encryption: The process of converting information into a code to prevent unauthorized access. It involves the use of mathematical algorithms to convert data into a form that cannot be understood without a key.
Random Access Memory (RAM): A type of volatile memory that loses its contents after a power loss (or within a few minutes). It is used by a computer to temporarily store data that is being actively used.
e-Discovery: The process of producing all relevant documentation and data to a court or external attorneys in a legal proceeding. It involves searching for, collecting, and reviewing electronic documents and data that are relevant to a legal case.
Depository: A safe with slots or an opening where staff can add sensitive physical data. It is used to physically store sensitive data in a secure way.
Data Destruction: The process of permanently deleting or destroying data so that it cannot be recovered. It involves overwriting the data multiple times, degaussing (using a magnetic field to erase data from a hard drive), or physically destroying the storage media (e.g. disk crusher).
Role-Based Access Control (RBAC): A method of restricting access to computer resources based on the roles and responsibilities of individual users within an organization. Access is granted based on the user's job function and responsibilities, rather than their identity. Need-to-know policies may be added to further restrict access based on specific criteria or reasons.
Data retention policy: A document that outlines an organization's policy for retaining and storing data, including what data should be kept, for how long, and how it should be stored.
Disaster Recovery Plan (DRP): A plan for restoring an organization's critical IT infrastructure and operations in the event of a natural or man-made disaster, such as a fire, flood, or cyber attack.
Confidential information: Sensitive information that is protected by law, regulation, or policy, and if compromised, could cause damage to national security or an organization's reputation or finances.
Information lifecycle: The process of managing information from its creation to its disposal, including creation, use, storage, and destruction.
Personally Identifiable Information (PII): Any information that can be used to distinguish or trace an individual's identity, such as name, social security number, date and place of birth, mother's maiden name, or biometric records.