Appendix 1 SAMPLE GLOSSARY
Note that in many cases there is no single, universally-accepted definition. This table provides those in common use,
drawing on internationally-recognised sources. Words that are underlined are themselves defined in this glossary.
Word
Availability
Definition
Availability is a property or characteristic. Something is available if it is accessible and
usable when an authorized entity demands access.
Source
ISO
Confidentiality
Confidentiality is a characteristic that applies to information. To protect and preserve
the confidentiality of information means to ensure that it is not made available or
disclosed to unauthorized entities. In this context, entities include both individuals and
processes.
ISO
Control
In the context of information security management, a control is any administrative,
managerial, technical, or legal method that is used to modify or manage information
security risk. Controls can include things like practices, processes, policies, procedures,
programs, tools, techniques, technologies, devices, and organizational structures. Controls
are sometimes also referred to as safeguards or countermeasures. (See ISO27000 for
more detail on this.)
The ability to protect or defend the use of cyberspace from cyber attacks
ISO
Cybersecurity is the collection of tools, policies, security concepts, security safeguards,
guidelines, risk management approaches, actions, training, best practices, assurance and
technologies that can be used to protect the cyber environment and organization and
user’s assets. Organization and user’s assets include connected computing devices,
personnel, infrastructure, applications, services, telecommunications systems, and the
totality of transmitted and/or stored information in the cyber environment. Cybersecurity
strives to ensure the attainment and maintenance of the security properties of the
organization and user’s assets against relevant security risks in the cyber environment
ITU
Cybersecurity
Page 15 of 33
www.cto.int
NIST