Domain 1 Flash Cards
Acceptable risk
A suitable level of risk commensurate with the potential benefits of the organization’s operations as determined by senior management.
Audit/auditing
The tools, processes, and activities used to perform compliance reviews.
Availability
Ensuring timely and reliable access to and use of information by authorized users.
Business continuity (BC)
Actions, processes, and tools for ensuring an organization can continue critical operations during a contingency.
Business continuity and
disaster recovery (BC/DR)
A term used to jointly describe business continuity and disaster recovery efforts.
Business impact analysis
(BIA)
A list of the organization’s assets, annotated to reflect the criticality of each asset to the organization.
Compliance
For the IT professional, includes the activities that maintain and provide systematic proof of both adherence to internal policies and the external laws, guidelines, or regulations imposed upon the company.
Confidentiality
Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information.
Data custodian
The person/role within the organization who usually manages the data on a day-to-day basis on behalf of the data owner/controller.
Data owner/controller
The data controller determines the purposes for which and the manner in which personal data is processed. It can do this either on its own or jointly or in common with other organization. This means that the data controller exercises overall control over the ‘why’ and the ‘how’ of a data processing activity
Data subject
The individual human related to a set of personal data
Disaster recovery (DR)
Those tasks and activities required to bring an organization back from contingency operations and reinstate regular operations.
Due diligence
is a management process used to gather facts before making a decision.
Due Care
refers to the effort made by an ordinarily prudent or reasonable party to avoid harm to another, taking the circumstances into account. It refers to the level of judgment, care, prudence, determination, and activity that a person would reasonably be expected to do under particular circumstances.
Governance
The process of how an organization is managed; usually includes all aspects of how decisions are made for that organization, such as policies, roles, and procedures the organization uses to make
those decisions.
Governance committee
A formal body of personnel who determine how decisions will be made within the organization and the entity that can approve changes and exceptions to current relevant governance.
Guidelines
Suggested practices and expectations of activity to best accomplish tasks and attain goals.
Integrity
Guarding against improper information modification or destruction and includes ensuring information non-repudiation and authenticity.
Intellectual property
In general terms, intellectual property is any product of the human intellect that the law protects from unauthorized use by others. The ownership of intellectual property inherently creates a limited monopoly in the protected property. Intellectual property is traditionally comprised of four categories: patent, copyright, trademark, and trade secrets
Maximum allowable
downtime (MAD)
The measure of how long an organization can survive an interruption of critical functions.
[also known as maximum tolerable downtime (MTD)]