- Data Classification
- A system that assigns sensitivity tiers β such as public, internal, confidential, and restricted β to data assets so that appropriate controls can be applied to each tier.
- Access Control
- Rules and technical mechanisms that restrict who can view, modify, or transmit specific data or systems, typically enforced through role-based permissions.
- Multi-Factor Authentication (MFA)
- A login method requiring two or more verification factors β such as a password plus a one-time code β to reduce the risk of unauthorized access from stolen credentials.
- Incident Response
- A documented set of steps an organization follows when a security event β breach, ransomware, phishing attack β is detected, from initial triage through containment and recovery.
- Acceptable Use Policy (AUP)
- A subset policy defining the permitted and prohibited ways employees may use company-owned devices, networks, and software.
- Least Privilege Principle
- A security design rule stating that users and systems should have only the minimum level of access necessary to perform their assigned function.
- Phishing
- A social engineering attack delivered via email or messaging that tricks recipients into revealing credentials, clicking malicious links, or transferring funds.
- Encryption
- The process of encoding data so that only authorized parties with the correct decryption key can read it, protecting information at rest and in transit.
- Patch Management
- The process of regularly applying security updates to operating systems, applications, and firmware to close known vulnerabilities before attackers can exploit them.
- Third-Party Risk
- The security exposure introduced when vendors, contractors, or partners have access to your systems or data and their own security practices are outside your direct control.
- Security Awareness Training
- Periodic instruction for employees covering how to identify threats such as phishing, how to handle sensitive data, and what to do when a security incident is suspected.
- Data Breach
- An incident in which sensitive, protected, or confidential data is accessed, disclosed, or stolen by an unauthorized party, triggering notification obligations in most jurisdictions.