Termos de governança e risco
132 verbetes do glossário marcados como governança e risco, em ordem alfabética.
- ABNT (Associação Brasileira de Normas Técnicas)
- accounting
- ANATEL
- ANPD
- asset
- attestation
- audit
- audit trail
- authentication
- authorization
- braindump
- C5Cloud Computing Compliance Criteria Catalogue (BSI)
- CCPA / CPRA
- CERT (team)Computer Emergency Response Team
- CGI.br
- chain analysis
- chain of custody
- change management
- CIA triadConfidentiality, Integrity, Availability
- CISSPCertified Information Systems Security Professional ((ISC)2)
- Cloud Security AllianceCloud Security Alliance (CSA)
- COBITControl Objectives for Information and Related Technologies (ISACA)
- compliance
- compliance is not security
- Concentration risk (internet infrastructure)
- control framework
- coordinated disclosure
- cross-border data transfer
- crown jewels
- CSA STARCSA Security, Trust, Assurance and Risk registry
- CVECommon Vulnerabilities and Exposures
- CVSSCommon Vulnerability Scoring System
- CWECommon Weakness Enumeration
- Cyber EssentialsUK Cyber Essentials (NCSC scheme)
- data at rest
- data breach notification
- Data center tiersUptime Institute data center tiers (I-IV)
- data classification
- data minimization
- Data Privacy FrameworkEU-U.S. / Swiss-U.S. Data Privacy Framework (DPF)
- data processing agreement
- data residency
- data retention
- DCWF (DoD Cyber Workforce Framework)
- defense in depth
- deprovisioning
- DoD (United States Department of Defense)
- DPIA
- DPO
- ECMAEuropean Computer Manufacturers Association
- egress fee
- EOLend of life
- EPSSExploit Prediction Scoring System
- exit scam
- FedRAMPFederal Risk and Authorization Management Program
- FIPSFederal Information Processing Standards
- FIRST (org)Forum of Incident Response and Security Teams
- forensics
- Gary McKinnon
- GDPRGeneral Data Protection Regulation
- Goodhart's law
- GPL (GNU General Public License)
- HIPAAHealth Insurance Portability and Accountability Act
- ICANNInternet Corporation for Assigned Names and Numbers
- Inmetro
- Internet shutdown
- IoCindicator of compromise
- IRAPInformation Security Registered Assessors Program (Australia)
- ISC2ISC2 (formerly (ISC)², the International Information System Security Certification Consortium)
- ISO/IEC 27001ISO/IEC 27001 (Information Security Management System)
- ISO/IEC 27017ISO/IEC 27017 (cloud security controls)
- ISO/IEC 27018ISO/IEC 27018 (PII protection in the cloud)
- Jeitinho
- Katie Moussouris
- Key escrow
- key management
- least privilegeprinciple of least privilege (PoLP)
- Lei Carolina Dieckmann (Law 12.737/2012)
- LGPD
- MANRS (Mutually Agreed Norms for Routing Security)
- Marco Civil da Internet (Law 12.965/2014)
- Mind the SecMind the Sec
- NIC.br
- NICE Framework Work Role Categories
- NIS2Network and Information Security Directive 2 (EU)
- NISTNational Institute of Standards and Technology
- NIST CSF (Cybersecurity Framework)
- NIST CSRC (Computer Security Resource Center)
- NVDNational Vulnerability Database
- Operation Sundevil
- PAMPrivileged Access Management
- PCI DSSPayment Card Industry Data Security Standard
- PIIPersonally Identifiable Information
- Policy sprawl (and the exception register)
- Port-block allocation (deterministic NAT)
- RDAPRegistration Data Access Protocol
- responsible disclosure
- retention
- risk
- Room 641A
- RPO and RTO (recovery objectives)
- RTO and RPORecovery Time and Recovery Point Objectives
- Schrems II
- Security Leaders
- security theater
- shadow ITShadow IT
- shared responsibility
- shelfware
- SISBIN (Sistema Brasileiro de Inteligência)
- SOC 2System and Organization Controls 2
- standard contractual clauses
- Standards body
- supply-chain attack
- tabletop exercise
- the CentOS Stream change (2020)
- the Clipper chip
- the cobra effect
- the Crypto Wars
- the DNC hack (2016)
- the L0pht testimony
- the Sony Pictures hack (2014)
- the STJ ransomware attack (2020)
- the Swiss cheese model
- the Target breach (2013)
- Therac-25
- threat model
- trust, but verify
- TTPtactics, techniques, and procedures
- vulnerability
- WHOIS
- Y2Kthe Year 2000 problem
- you can't secure what you can't see