- Authorized Use
- Access to or use of company systems, data, or networks that falls within the permissions expressly granted by the organization.
- Data Breach
- An incident in which confidential or protected information is accessed, disclosed, or exfiltrated without authorization.
- Personally Identifiable Information (PII)
- Any data that can be used to identify a specific individual, such as name, email address, Social Security number, or IP address.
- Least Privilege Principle
- A security concept requiring that users are granted only the minimum level of access needed to perform their job duties.
- Incident Reporting
- The formal obligation to notify a designated authority — typically an IT security team or CISO — when a suspected or confirmed security event occurs.
- Social Engineering
- Manipulation tactics — such as phishing, pretexting, or baiting — used to trick individuals into divulging credentials or sensitive information.
- Whistleblower Protection
- Legal safeguards that protect an employee from retaliation for reporting suspected unethical, illegal, or unsafe conduct in good faith.
- Chain of Custody
- The documented sequence of individuals who have accessed or handled specific data or digital evidence, used to maintain integrity in investigations.
- Multi-Factor Authentication (MFA)
- A login security mechanism requiring two or more verification methods — typically a password plus a code sent to a device or biometric confirmation.
- Zero-Day Vulnerability
- A previously unknown software flaw that attackers can exploit before the vendor has released a patch or mitigation.
- Confidential Information
- Non-public organizational data — including trade secrets, client data, financial records, and system architecture — that must be protected from unauthorized disclosure.