Cyberspace A global domain within the information environment consisting of the interdependent network of information systems infrastructures including the Internet, telecommunications networks, computer systems, and embedded processors and controllers. NIST Documented information The term documented information refers to information that must be controlled and maintained and its supporting medium. Documented information can be in any format and on any medium and can come from any source. ISO Documented information includes information about the management system and related processes. It also includes all the information that organizations need to operate and all the information that they use to document the results that they achieve (aka records). In short, the term documented information is just a new name for what used to be called documents and records. But this change is significant. In the past, documents and records were to be managed differently. Now the same set of requirements is to be applied to both documents and records. Information Security The purpose of information security is to protect and preserve the confidentiality, integrity, and availability of information. It may also involve protecting and preserving the authenticity and reliability of information and ensuring that entities can be held accountable. ISO Integrity Within the narrow context of information security, the term integrity means to protect the accuracy and completeness of information. The ability to quickly adapt and recover from any known or unknown changes to the environment through holistic implementation of risk management, contingency, and continuity planning. Also The ability to continue to: (i) operate under adverse conditions or stress, even if in a degraded or debilitated state, while maintaining essential operational capabilities; and (ii) recover to an effective operational posture in a time frame consistent with mission needs. ISO According to ISO 31000, risk is the “effect of uncertainty on objectives” and an effect is a positive or negative deviation from what is expected. (See ISO31000 for more on this.) ISO Resilience Risk Page 16 of 33 www.cto.int NIST

Select target paragraph3