- Data Classification
- The process of categorizing data by sensitivity level β such as public, internal, confidential, or restricted β to determine appropriate handling and access rules.
- Access Control
- A set of rules and mechanisms that restrict who can view, edit, or share specific data based on their role or authorization level.
- Personally Identifiable Information (PII)
- Any data that can be used to identify a specific individual, including names, email addresses, social security numbers, and financial account details.
- Data Custodian
- The individual or team responsible for the day-to-day management and protection of a specific dataset, distinct from the data owner who sets policy.
- Least Privilege Principle
- A security concept requiring that users are granted only the minimum level of data access needed to perform their job functions.
- Incident Response
- A defined set of steps an organization follows to detect, contain, investigate, and recover from a data security incident or breach.
- Data Retention
- The policy governing how long different categories of data are kept before being securely deleted or archived.
- Encryption
- The process of converting data into an unreadable format using a cryptographic key so that only authorized parties can access the original content.
- Information Owner
- The business unit or senior individual accountable for determining the classification level and approved uses of a specific dataset.
- Acceptable Use Policy (AUP)
- A companion document that specifies how employees may and may not use company systems, devices, and data in their day-to-day work.
- Third-Party Risk
- The exposure an organization faces when vendors, contractors, or partners have access to its data and may not apply equivalent security controls.