The Real Story: Security Definitions You Need to Know

Solutionary Blog and Bloggers

Solutionary is an information security company. What does that mean? Simply put, we help businesses protect their assets, remain fully secure and safe online, and maintain and adhere to compliance regulations and standards. Solutionary's blog is a place to learn about, and discuss, a wide variety of security and compliance topics.

For more information about Solutionary, click here.

To read the Solutionary blog comment policy and disclaimer, click here.

Solutionary Bloggers:

Brad Curtis, Compliance Manager              Jon Heimerl, Director of Strategic Security  Mike Hrabik, President and CTO             Don Gray, Chief Security Strategist       Court Little, Director of Strategic Security Joseph Blankenship, Director of Marketing 
Doug Picotte, Regional Technical Manager
Rob Kraus, Manager, Security Consulting Services    
Erik Barnett, Regional Technical Manager Jose Hernandez, Security Consultant
Vincent Ragosta, Information Security Engineer                                         Jozef Krakora, Sr Product Manager        

Subscribe to our blog

Your email:

Tags

Solutionary Minds - Your Information Security Blog Source

Current Articles | RSS Feed RSS Feed

The Real Story: Security Definitions You Need to Know

Posted by Jon Heimerl on Mon, Jul 12, 2010 @ 12:40 PM
  
  
  
  

describe the image

 

 

 

 

Security – Freedom from danger or risk, or actions taken to prevent or decrease danger or risk. The quest for information security is a form of perpetual motion.

Secure – Nothing.

Insecure – Everything.

Privacy – An illusion.

Backup – What you wish you had done before your system crashed.

Social Media – Alternate communications media that supports socialization and promotes communications. Does not normally fall under the same level of control as "official" communications media such as email because of rapid adoption rates, informal communication formats, and immature controls and policies.

ROI (Return on Investment) – The amount you need to project as hopeful future savings to justify spending money on a project now. Sometimes also known as Rationalization of Imagination.

RGE – The result of a crash in your main data center that wipes out half of your corporate information because your DR site had never really been tested and was not working the way you needed it to. Also known as a “Resume Generating Event”.

Incident Response – Unless accompanied with planning, usually involves screaming, hair pulling, sobbing, and cursing, immediately followed by accusations of blame for some unwitting party. Often results in an RGE.

Cookies – What you bring the auditor to help make sure you pass your audit, since you had not been doing the right logging, or the right reporting, and you know you weren't really ready for them.

Disaster Planning – Planned, measured steps taken to help limit the negative impacts of a foreseeable disaster or other significant event before the actual event. See also "What BP didn't do".

Security Policy – What someone who does not understand your operations wrote down so that you could claim you had one.

TANSTAAFL – There Ain’t No Such Thing As A Free Lunch. It’s just a matter of when you pay for it in the end. And you always pay for it. Always.

Synapticurse – When you enter the command to restore the backup image, and you tell your finger to press the “Enter” button, the synapticurse is the physiological and psychological reaction you get in that fraction of a second after you realize you have reversed the parameters and will destroy your only backup, but it is too late for your synapses to fire the impulse to tell your finger to stop from actually pressing the button.

Blended Threat – That strawberry daiquiri you should not have had before you logged onto your work system to promote code to production.

SSID Roulette – The act of just picking one, when faced with that chaos of wireless networks that shows up in public or hotels where you never know which is the hotel approved wireless or which ones are the hostile, fake, access points that are waiting for you to connect for evil purposes.

Silver Bullet – That one security fix, enhancement, or product that can heal/prevent all security woes. Or, a projectile made of a pure metal used to kill werewolves. I mean, each one is just as likely as the other, right?

 


describe the image

Tags: , , , ,

COMMENTS

Currently, there are no comments. Be the first to post one!
Post Comment
Name
 *
Email
 *
Website (optional)
Comment
 *

Allowed tags: <a> link, <b> bold, <i> italics