Cyberspace
A global domain within the information environment consisting of the interdependent
network of information systems infrastructures including the Internet, telecommunications
networks, computer systems, and embedded processors and controllers.
NIST
Documented
information
The term documented information refers to information that must be controlled and
maintained and its supporting medium. Documented information can be in any format and
on any medium and can come from any source.
ISO
Documented information includes information about the management system and related
processes. It also includes all the information that organizations need to operate and all
the information that they use to document the results that they achieve (aka records).
In short, the term documented information is just a new name for what used to be called
documents and records. But this change is significant. In the past, documents and
records were to be managed differently. Now the same set of requirements is to be applied
to both documents and records.
Information
Security
The purpose of information security is to protect and preserve the confidentiality, integrity,
and availability of information. It may also involve protecting and preserving the
authenticity and reliability of information and ensuring that entities can be held
accountable.
ISO
Integrity
Within the narrow context of information security, the term integrity means to protect the
accuracy and completeness of information.
The ability to quickly adapt and recover from any known or unknown changes to the
environment through holistic implementation of risk management, contingency, and
continuity planning.
Also
The ability to continue to: (i) operate under adverse conditions or stress, even if in a
degraded or debilitated state, while maintaining essential operational capabilities; and (ii)
recover to an effective operational posture in a time frame consistent with mission needs.
ISO
According to ISO 31000, risk is the “effect of uncertainty on objectives” and an effect is
a positive or negative deviation from what is expected. (See ISO31000 for more on this.)
ISO
Resilience
Risk
Page 16 of 33
www.cto.int
NIST