<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Information Security on Sinetris's viewpoints</title><link>https://sinetris.info/glossary-contexts/information-security/</link><description>Recent content in Information Security on Sinetris's viewpoints</description><generator>Sine Die theme for Hugo</generator><language>en</language><webMaster>duilio@sinetris.info (Duilio Ruggiero)</webMaster><lastBuildDate>Sun, 07 Dec 2025 23:58:31 GMT</lastBuildDate><atom:link href="https://sinetris.info/glossary-contexts/information-security/index.rss.xml" rel="self" type="application/rss+xml"/><item><title>Risk Owner</title><link>https://sinetris.info/glossary/risk-owner/</link><pubDate>Sun, 07 Dec 2025 23:58:31 GMT</pubDate><guid>https://sinetris.info/glossary/risk-owner/</guid><description>Person directly responsible for identifying, assessing, monitoring, reporting,
responding to, and defining intervention strategies in relation to risks associated
with an &lt;a class="glossary-term" href="https://sinetris.info/glossary/information-technology-asset/"&gt;IT asset&lt;/a&gt;.</description></item><item><title>Information Technology Asset</title><link>https://sinetris.info/glossary/information-technology-asset/</link><pubDate>Sun, 07 Dec 2025 23:19:32 GMT</pubDate><guid>https://sinetris.info/glossary/information-technology-asset/</guid><description>Hardware and software (e.g., applications, systems, virtual resources, data) that
an organization uses to support its business objectives.</description></item><item><title>Responsive Controls</title><link>https://sinetris.info/glossary/responsive-controls/</link><pubDate>Sun, 07 Dec 2025 21:35:56 GMT</pubDate><guid>https://sinetris.info/glossary/responsive-controls/</guid><description>Measures designed to respond to and rectify security violations or incidents after they have been identified.</description></item><item><title>Detective Controls</title><link>https://sinetris.info/glossary/detective-controls/</link><pubDate>Sun, 07 Dec 2025 21:23:57 GMT</pubDate><guid>https://sinetris.info/glossary/detective-controls/</guid><description>Measures designed to identify, record, and report a security incident after it has occurred.</description></item><item><title>Entitlements</title><link>https://sinetris.info/glossary/entitlements/</link><pubDate>Mon, 01 Dec 2025 11:17:25 GMT</pubDate><guid>https://sinetris.info/glossary/entitlements/</guid><description>The access rights an account has on an asset.</description></item><item><title>Access Recertification Campaigns</title><link>https://sinetris.info/glossary/access-recertification-campaigns/</link><pubDate>Mon, 01 Dec 2025 10:25:02 GMT</pubDate><guid>https://sinetris.info/glossary/access-recertification-campaigns/</guid><description>Periodic review of user &lt;a class="glossary-term" href="https://sinetris.info/glossary/entitlements/"&gt;entitlements&lt;/a&gt;
to enforce the &lt;a class="glossary-term" href="https://sinetris.info/glossary/principle-of-least-privilege/"&gt;Principle of Least Privilege&lt;/a&gt;,
ensure &lt;a class="glossary-term" href="https://sinetris.info/glossary/orphaned-account/"&gt;orphaned accounts&lt;/a&gt; are removed,
and reduce internal threats and compliance violations.</description></item><item><title>Access Request</title><link>https://sinetris.info/glossary/access-request/</link><pubDate>Mon, 01 Dec 2025 10:22:15 GMT</pubDate><guid>https://sinetris.info/glossary/access-request/</guid><description>A user-initiated process to gain permission to access an &lt;a class="glossary-term" href="https://sinetris.info/glossary/information-technology-asset/"&gt;IT asset&lt;/a&gt; within an organization&amp;rsquo;s infrastructure.</description></item><item><title>Birthright Access</title><link>https://sinetris.info/glossary/birthright-access/</link><pubDate>Sat, 29 Nov 2025 15:32:02 GMT</pubDate><guid>https://sinetris.info/glossary/birthright-access/</guid><description>&lt;a class="glossary-term" href="https://sinetris.info/glossary/entitlements/"&gt;Entitlements&lt;/a&gt; automatically granted to a user when
they join an organization or change roles within it.</description></item><item><title>Orphaned Account</title><link>https://sinetris.info/glossary/orphaned-account/</link><pubDate>Sat, 29 Nov 2025 15:24:33 GMT</pubDate><guid>https://sinetris.info/glossary/orphaned-account/</guid><description>Account that retains access to an asset without an active owner.</description></item><item><title>Data Breach</title><link>https://sinetris.info/glossary/data-breach/</link><pubDate>Thu, 27 Nov 2025 22:08:23 GMT</pubDate><guid>https://sinetris.info/glossary/data-breach/</guid><description>Incident involving copying, transmitting, viewing, or processing sensitive,
protected, or confidential information by unauthorized individuals or for
unauthorized purposes.</description></item><item><title>Data Anonymization</title><link>https://sinetris.info/glossary/data-anonymization/</link><pubDate>Mon, 24 Nov 2025 14:47:49 GMT</pubDate><guid>https://sinetris.info/glossary/data-anonymization/</guid><description>The process of removing Personally Identifiable Information from a dataset in an irreversible and permanent manner.
This can serve as a mechanism of privacy protection. In the context of data governance,
anonymized data is no longer considered Personally Identifiable Information
according to the current regulatory interpretation.</description></item><item><title>Proactive Controls</title><link>https://sinetris.info/glossary/proactive-controls/</link><pubDate>Mon, 24 Nov 2025 12:56:03 GMT</pubDate><guid>https://sinetris.info/glossary/proactive-controls/</guid><description>&lt;p&gt;Proactive Controls are a strategy designed to prevent attacks and identify vulnerabilities
before they are exploited, focusing on prediction and prevention rather than simply
reacting, anticipating potential problems or targets and taking action to prepare
in advance, rather than waiting for them to occur.&lt;/p&gt;</description></item><item><title>Preventative Controls</title><link>https://sinetris.info/glossary/preventative-controls/</link><pubDate>Mon, 24 Nov 2025 11:42:20 GMT</pubDate><guid>https://sinetris.info/glossary/preventative-controls/</guid><description>Designed to prevent an event or an unauthorized action from occurring.</description></item><item><title>Security Controls</title><link>https://sinetris.info/glossary/security-controls/</link><pubDate>Mon, 24 Nov 2025 11:36:55 GMT</pubDate><guid>https://sinetris.info/glossary/security-controls/</guid><description>Safeguards and countermeasures that help protect an organization&amp;rsquo;s assets, systems,
and data from potential risks and threats.</description></item><item><title>Subject Matter Expert</title><link>https://sinetris.info/glossary/subject-matter-expert/</link><pubDate>Mon, 24 Nov 2025 07:28:53 GMT</pubDate><guid>https://sinetris.info/glossary/subject-matter-expert/</guid><description>A professional with in-depth, specialized knowledge in a particular field, process,
or technology who acts as a trusted advisor, guiding teams, validating information,
and solving complex problems to ensure accuracy, efficiency, and successful project
outcomes.</description></item><item><title>Asset Administrator</title><link>https://sinetris.info/glossary/asset-administrator/</link><pubDate>Mon, 24 Nov 2025 01:27:13 GMT</pubDate><guid>https://sinetris.info/glossary/asset-administrator/</guid><description>Manages user roles, account assignments, and performs access reviews and audits
for an &lt;a class="glossary-term" href="https://sinetris.info/glossary/information-technology-asset/"&gt;IT asset&lt;/a&gt;.</description></item><item><title>Authentication Assurance Level</title><link>https://sinetris.info/glossary/authentication-assurance-level/</link><pubDate>Sat, 22 Nov 2025 08:02:00 GMT</pubDate><guid>https://sinetris.info/glossary/authentication-assurance-level/</guid><description>NIST standard to assess the degree of confidence and reliability of an authentication
process.</description></item><item><title>Asset Owner</title><link>https://sinetris.info/glossary/asset-owner/</link><pubDate>Sat, 22 Nov 2025 08:01:09 GMT</pubDate><guid>https://sinetris.info/glossary/asset-owner/</guid><description>Person or group responsible for an &lt;a class="glossary-term" href="https://sinetris.info/glossary/information-technology-asset/"&gt;IT asset&lt;/a&gt;.</description></item><item><title>Account Lockout</title><link>https://sinetris.info/glossary/account-lockout/</link><pubDate>Sat, 22 Nov 2025 08:00:36 GMT</pubDate><guid>https://sinetris.info/glossary/account-lockout/</guid><description>A security feature typically used to prevent a &lt;a class="glossary-term" href="https://sinetris.info/glossary/brute-force-attack/"&gt;Brute-Force Attack&lt;/a&gt;
by temporarily disabling a user account after a set number of failed login attempts.</description></item><item><title>Web Authentication</title><link>https://sinetris.info/glossary/web-authentication/</link><pubDate>Mon, 10 Nov 2025 15:34:37 GMT</pubDate><guid>https://sinetris.info/glossary/web-authentication/</guid><description>Specification that defines an API enabling the creation and use of strong, attested,
scoped, public key-based credentials by web applications, for the purpose of strongly
authenticating users.</description></item><item><title>Client-to-Authenticator Protocols</title><link>https://sinetris.info/glossary/client-to-authenticator-protocols/</link><pubDate>Mon, 10 Nov 2025 15:29:40 GMT</pubDate><guid>https://sinetris.info/glossary/client-to-authenticator-protocols/</guid><description>Protocol developed by the FIDO Alliance and complementary to the &lt;a class="glossary-term" href="https://sinetris.info/glossary/web-authentication/"&gt;W3C&amp;#39;s WebAuthn specification&lt;/a&gt; that allows
a client (for example, an operating system, browser, or application) to communicate
with a device designed to authenticate the user.</description></item><item><title>FIDO Specifications</title><link>https://sinetris.info/glossary/fido-specifications/</link><pubDate>Mon, 10 Nov 2025 15:10:26 GMT</pubDate><guid>https://sinetris.info/glossary/fido-specifications/</guid><description>A set of open standards published by the 
&lt;a href="https://fidoalliance.org/" rel="external"&gt;FIDO Alliance&lt;/a&gt;
for stronger, simpler, and phishing-resistant user authentication.</description></item><item><title>Information Technology Asset Management</title><link>https://sinetris.info/glossary/information-technology-asset-management/</link><pubDate>Mon, 10 Nov 2025 14:55:30 GMT</pubDate><guid>https://sinetris.info/glossary/information-technology-asset-management/</guid><description>Systems to manage the lifecycle of &lt;a class="glossary-term" href="https://sinetris.info/glossary/information-technology-asset/"&gt;IT assets&lt;/a&gt;, including tracking, maintaining and disposing of hardware
and software.</description></item><item><title>Desired State</title><link>https://sinetris.info/glossary/desired-state/</link><pubDate>Mon, 10 Nov 2025 13:47:45 GMT</pubDate><guid>https://sinetris.info/glossary/desired-state/</guid><description>The planned state of a system, usually defined as data or code in a
&lt;a class="glossary-term" href="https://sinetris.info/glossary/single-source-of-truth/"&gt;&lt;abbr title="Single Source of Truth"&gt;SSOT&lt;/abbr&gt;&lt;/a&gt;.</description></item><item><title>Account Takeover</title><link>https://sinetris.info/glossary/account-take-overs/</link><pubDate>Wed, 25 Jun 2025 11:55:55 GMT</pubDate><guid>https://sinetris.info/glossary/account-take-overs/</guid><description>Gaining unauthorized access to a user account.</description></item><item><title>Information Assurance</title><link>https://sinetris.info/glossary/information-assurance/</link><pubDate>Mon, 17 Mar 2025 10:43:09 GMT</pubDate><guid>https://sinetris.info/glossary/information-assurance/</guid><description>&lt;p&gt;Information Assurance (IA) is the practice of assuring information quality and managing risks related to the use, processing, storage, and transmission of information.&lt;/p&gt;
&lt;p&gt;The 5 pillars of information assurance includes protection of the &lt;strong&gt;Confidentiality&lt;/strong&gt;, &lt;strong&gt;Integrity&lt;/strong&gt;, &lt;strong&gt;Availability&lt;/strong&gt;, &lt;strong&gt;Authenticity&lt;/strong&gt;, and &lt;strong&gt;Non-repudiation&lt;/strong&gt; of information.&lt;/p&gt;
&lt;p&gt;In IT systems, when possible, assets should be tagged/labeled with proper Information Assurance level.&lt;/p&gt;
&lt;h2 id="confidentiality"&gt;Confidentiality&lt;/h2&gt;
&lt;p&gt;The property that information is not made available or disclosed to unauthorized individuals, entities, or processes.&lt;/p&gt;
&lt;div&gt;[Truncated]&lt;/div&gt;</description></item><item><title>Principle of Least Privilege</title><link>https://sinetris.info/glossary/principle-of-least-privilege/</link><pubDate>Sun, 06 Aug 2023 10:10:15 GMT</pubDate><guid>https://sinetris.info/glossary/principle-of-least-privilege/</guid><description>Security concept whereby a user or service is granted the minimum levels of access
and authorization necessary to perform the requested task.</description></item></channel></rss>