- Acceptable Use Policy (AUP)
- A section or standalone document specifying permitted and prohibited uses of company-owned technology, networks, and internet access.
- Access Control
- The process of restricting access to systems, applications, and data to only the individuals who require it for their role.
- Data Classification
- A scheme for categorizing data by sensitivity β typically Public, Internal, Confidential, and Restricted β to determine appropriate handling and protection requirements.
- Multi-Factor Authentication (MFA)
- A login method that requires users to verify identity through two or more independent factors, such as a password and a one-time code sent to a mobile device.
- Incident Response
- The structured process for detecting, containing, investigating, and recovering from a security breach or cyberattack.
- Least Privilege
- A security principle that grants users only the minimum system access required to perform their job function, and no more.
- BYOD (Bring Your Own Device)
- A policy that governs whether and how employees may use personal smartphones, laptops, or tablets to access company systems and data.
- Phishing
- A social engineering attack in which a threat actor sends a deceptive email or message designed to trick the recipient into revealing credentials or installing malware.
- Patch Management
- The regular process of identifying, testing, and applying software updates and security fixes to operating systems and applications.
- SOC 2
- An auditing standard from the American Institute of CPAs that evaluates an organization's controls for security, availability, and data confidentiality β commonly required by enterprise SaaS customers.
- Encryption at Rest
- The practice of encrypting stored data β on hard drives, databases, or cloud storage β so it is unreadable if accessed without authorization.