Appendix – Terms and Definitions

Serial Number

Term

Definition

1

Access control

Grading access to assets is restricted, based on business and security considerations on a need-to-know basis.

2

Analytical model

The algorithm or computation that combines several different decision criteria with a number of different base metrics.

3

Attack

An attempt to damage, expose, or change an asset in any way, steal it, or utilize it without authorization.

4

Attribute

A trait or feature of an object that may be quantified or qualitatively identified by human or automated means.

5

Audit

An objective procedure to review audit data and evaluate whether or not the audit criteria have been met through systematic, ...

Get Mastering Information Security Compliance Management now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.