Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:Введение в информационную безопасность и защиту информации. Учебное пособие
.pdf
Твердая копия документа – полученная на устройствах вывода ЭВМ
надлежащим образом удостоверенная
форма внешнего представления электронного документа, выполненная на
бумажном носителе.
[ГОСТ 2.051-2006]
Тестирование – процесс испытания
одного или нескольких объектов проверки при определенных условиях,
который проводится для сравнения
реального поведения с ожидаемым.
Результаты используются для поддержки решения о наличии, эффективности, функциональных возможностях, правильности, полноте мер и
средств контроля и управления и возможности их совершенствования с
течением времени.
Р 56045-2014/ISO/IEC TR
[ГОСТ
27008:2011]
Hard copy of document – duly certified
form of external representation of electronic document, made on paper, obtained on the output devices of the computer.
Test – A type of assessment method that
is characterized by the process of exercising one or more assessment objects
under specified conditions to compare
actual with expected behavior, the results of which are used to support the
determination of security control effectiveness over time.
SOURCE: SP 800-53A
testing (1) Evaluation of a resource to
validate the achievement of objectives
and aims. See exercise.
[ASIS/BSI BCM.01-2010]
(2) Activities performed to evaluate the
effectiveness or capabilities of a plan
relative to specified objectives or measurement criteria. Testing usually involves exercises designed to keep teams
and employees effective in their duties
and to reveal weaknesses in the Business
Continuity Plan.
[ASIS GDL BC 01 2005]
(3) Activities performed to evaluate the
effectiveness or capabilities of a plan
relative to specified objectives or measurement criteria. Testing usually involves exercises designed to keep teams
and employees effective in their duties,
and to reveal weaknesses in the preparedness and response/continuity/recovery
plans.
[ASIS GDL BC 01 2005]
[ANSI/ASIS PAP.1-2012]
91

Тестирование функций СЗИ НСД
Техника защиты информации –
средства защиты информации, в том
числе средства физической защиты
информации, криптографические
средства защиты информации, средства контроля эффективности защиты
информации, средства и системы
управления, предназначенные для
обеспечения защиты информации.
ГОСТ Р 50922 2006
Трансграничная передача персональных данных – передача персо-
нальных данных оператором через
Государственную границу Российской Федерации органу власти иностранного государства, физическому
или юридическому лицу иностранного государства.
[Методические рекомендации по
обеспечению с помощью криптосредств безопасности персональных
данных при их обработке в информационных системах персональных
данных с использованием
средств
автоматизации]
Требование по защите информации – установленное правило или
норма, которая должна быть выполнена при организации и осуществлении защиты информации, или допустимое значение показателя эффективности защиты информации.
ГОСТ Р 50922 2006
Security Testing – Process to determine
that an information system protects data
and maintains functionality as intended.
SOURCE: CNSSI-4009
Information Security Program Plan –
Formal document that provides an overview of the security requirements for an
organization-wide information security
program and describes the program
management controls and common controls in place or planned for meeting
those requirements.
SOURCE: SP 800-37; SP 800-53; SP
800-53A
Cross-border transfer of personal
data – the transfer of personal data by
the operator through the state border of
the Russian Federation to the authority
of a foreign country, person or entity of
a foreign country.
Security Requirements – Requirements
levied on an information system that are
derived from applicable laws, Executive
Orders, directives, policies, standards,
instructions, regulations, or procedures,
or organizational mission/business case
needs to ensure the confidentiality, integrity, and availability of the information being processed, stored, or
transmitted.
SOURCE: FIPS 200; SP 800-53; SP
800-53A; SP 800-37; CNSSI-4009
92

Угроза (безопасности информации) – Совокупность условий и фак-
торов, создающих потенциальную
или реально существующую опасность нарушения безопасности информации.
ГОСТ Р 53114-2008
Угроза (безопасности информации):
Совокупность условий и факторов,
создающих потенциальную или реально существующую опасность
нарушения безопасности информации.
[ГОСТ Р 50922-2006, 2.6.1]
Инцидент информационной безопасности: Любое непредвиденное
или нежелательное событие, которое
Threat – Any circumstance or event
with the potential to adversely impact
organizational operations (including
mission, functions, image, or reputation), organizational assets, individuals,
other organizations, or the Nation
through an information system via unauthorized access, destruction, disclosure,
modification of information, and/or denial of service.
SOURCE: SP 800-53; SP 800-53A;
SP 800-27; SP 800-60; SP 800-37;
CNSSI-4009
Threat – The potential source of an adverse event.
SOURCE: SP 800-61
Threat – Any circumstance or event
with the potential to adversely impact
organizational operations (including
mission, functions, image, or reputation), organizational assets, or individuals through an information system via
unauthorized access, destruction, disclosure, modification of information, and/or
denial of service. Also, the potential for
a threat-source to successfully exploit a
particular information system vulnerability.
SOURCE: FIPS 200
Threat Any circumstance or event with
the potential to adversely impact agency
operations (including mission, functions,
image, or reputation), agency assets, or
individuals through an information system via unauthorized access, destruction,
disclosure, modification of information,
and/or Denial of Service (DOS). [Glossary TOC]
93

может нарушить деятельность или
информационную безопасность.
Примечание. Инцидентами информационной безопасности являются:
– утрата услуг, оборудования или
устройств;
– системные сбои или перегрузки;
– ошибки пользователей;
– несоблюдение политики или рекомендаций по ИБ;
– нарушение физических мер защиты;
– неконтролируемые изменения си-
стем;
– сбои программного обеспечения и
отказы технических средств;
– нарушение
правил доступа.
[ГОСТ Р ИСО/МЭК 27001-2006, статья 3.6]
Управление рисками: Координиро-
ванные действия по направлению и
контролю над деятельностью организации в связи с рисками.
[ГОСТ Р 53114-2008 3.2.16]
Risk Management – The process of
managing risks to organizational operations (including mission, functions, image, reputation), organizational assets,
individuals, other organizations, and the
Nation, resulting from the operation of
an information system, and includes: (i)
the conduct of a risk assessment; (ii) the
implementation of a risk mitigation
strategy; and (iii) employment of techniques and procedures for the continuous monitoring of the security state of
the information system.
SOURCE: SP 800-53; SP 800-53A; SP
800-37
Risk Management – The process of
managing risks to organizational operations (including mission, functions, image, or reputation), organizational assets,
or individuals resulting from the operation of an information system, and includes:
94

1) the conduct of a risk assessment;
2) the implementation of a risk mitigation strategy; and
3) employment of techniques and procedures for the continuous monitoring of
the security state of the information system.
SOURCE: FIPS 200
Risk Management – The process of
managing risks to agency operations
(including mission, functions, image, or
reputation), agency assets, or individuals
resulting from the operation of an information system. It includes risk assessment; cost-benefit analysis; the selection, implementation, and assessment of
security controls; and the formal authorization to operate the system. The process considers effectiveness, efficiency,
and constraints due to laws, directives,
policies, or regulations.
SOURCE: SP 800-82; SP 800-34
The process of managing risks to organ-
izational operations (including mission,
functions, image, or reputation), organizational assets, individuals, other organizations, or the nation resulting from the
operation or use of an information system, and includes: (1) the conduct of a
risk assessment; (2) the implementation
of a risk mitigation strategy; (3) employment of techniques and procedures
for the continuous monitoring of the
security state of the information system;
and (4) documenting the overall risk
management program.
SOURCE: CNSSI-4009
The program and supporting processes
to manage information security risk to
organizational operations (including
mission, functions, image, reputation),
95

Уровень:
– защиты информации;
– конфиденциальности;
– полномочий – cовокупность прав
доступа субъекта доступа. [Руководящий документ Защита от несанкционированного доступа к информации
Термины и определения, пункт 9]
Успешная атака – атака, достигшая
своей цели.
[Методические рекомендации по
обеспечению с помощью криптосредств безопасности персональных
данных при их обработке в информационных системах персональных
данных с использованием средств
автоматизации]
Устройства (Устройство – конструктивно законченный технический
элемент, имеющий определенное
функциональное назначение в информационной системе
[Методический документ. Меры защиты информации в государственных информационных системах.
Утвержден ФСТЭК России 11 февраля 2014 г.]):
organizational assets, individuals, other
organizations, and the Nation, and includes: (i) establishing the context for
risk-related activities; (ii) assessing risk;
(iii) responding to risk once determined;
and (iv) monitoring risk over time.
SOURCE: SP 800-39
Level:
– of information security;
– of confidentiality;
– of powers – the aggregate subject ac-
cess permissions..
Successful attack – attack, which has
reached its goal.
Devices
1) In general, a device is a machine designed for a purpose. In a general context, a computer can be considered a
device.
2) In the context of computer technology, a device is a unit of hardware, outside or inside the case or housing for the
essential computer (processor, memory,
and data paths) that is capable of providing input to the essential computer or of
receiving output or of both.
96

Утечка информации: Неконтролируемое распространение защищаемой
информации в результате ее разглашения, несанкционированного досту-
Data Loss – The exposure of proprietary, sensitive, or classified information
through either data theft or data leakage.
SOURCE: SP 800-137
па к информации и получения защищаемой информации иностранными
разведками.
[ГОСТ Р 53114-2008 3.3.10]
Учетные данные Credentials
Credential – An object or data structure
that authoritatively binds an identity
(and optionally, additional attributes) to
a token possessed and controlled by a
Subscriber.
SOURCE: SP 800-63
Credential – Evidence attesting to one’s
right to credit or authority.
SOURCE: FIPS 201
Credential – Evidence or testimonials
that support a claim of identity or assertion of an attribute and usually are intended to be used more than once.
SOURCE: CNSSI-4009
Уязвимость (информационной системы); брешь: Свойство информа-
ционной системы, обусловливающее
возможность реализации угроз безопасности обрабатываемой в ней информации.
[ГОСТ Р 50922-2006, 2.6.4]
Vulnerability – Weakness in an infor-
mation system, system security procedures, internal controls, or implementation that could be exploited or triggered
by a threat source. SOURCE: SP 80053; SP 800-53A; SP 800-37; SP 800-60;
SP 800- 115; FIPS 200
A weakness in a system, application, or
network that is subject to exploitation or
misuse. SOURCE: SP 800-61 Weakness
in an information system, system security procedures, internal controls, or implementation that could be exploited by
a threat source. SOURCE: CNSSI-4009
97

Фактор, воздействующий на защищаемую информацию: Явление, дей-
ствие или процесс, результатом которого могут быть утечка, искажение,
уничтожение защищаемой информации, блокирование доступа к ней.
[ГОСТ Р 50922-2006, 2.6.2]
Характеристика безопасности объекта – требование к объекту, или к
условиям его создания и существования, или к информации об объекте и
условиях его создания и существования, выполнение которого необходимо для обеспечения защищенности
жизненно важных интересов личности, общества или государства.
[Методические рекомендации по
обеспечению с помощью криптосредств
безопасности персональных
данных при их обработке в информационных системах персональных
данных с использованием средств
автоматизации]
Целостность информации – устой-
чивость информации к несанкционированному или случайному воздействию на нее в процессе обработки
техническими средствами, результатом которого может быть уничтожение и искажение информации.
СТРК-2001
Incident An assessed event of attempted
entry, unauthorized entry, and/or attack
against a facility, operation, or Automated Information System (AIS).
Security Requirements – Requirements – Requirements levied on an information system that are derived from
applicable laws, Executive Orders, directives, policies, standards, instructions,
regulations, or procedures, or organizational mission/business case needs to
ensure the confidentiality, integrity, and
availability of the information being
processed, stored, or transmitted.
SOURCE: FIPS 200; SP 800-53; SP
800-53A; SP 800-37; CNSSI- 4009
Integrity – Guarding against improper
information modification or destruction,
and includes ensuring information nonrepudiation and authenticity.
SOURCE: SP 800-53; SP 800-53A;
SP 800-18; SP 800-27; SP 800-37;
SP 800-60; FIPS 200; FIPS 199;
44 U.S.C., Sec. 3542
Integrity – The property that sensitive
data has not been modified or deleted in
an unauthorized and undetected manner.
SOURCE: FIPS 140-2
Integrity – The property whereby an
entity has not been modified in an unauthorized manner.
SOURCE: CNSSI-4009
98

Цель защиты информации: Заранее
намеченный результат защиты информации.
[ГОСТ Р 50922-2006, 2.4.2]
Target – a detailed performance re-
quirement applicable to the organization
(or parts thereof) that arises from the
objectives and that needs to be set and
met in order to achieve those objectives.
[ASIS SPC.1-2009] [ANSI/ASIS
PAP.1-2012]
[ANSI/ASIS PSC.1-2012]
Штамп.
Технологическая оснастка, посредством которой заготовка приобретает форму и (или) размеры, соответствующие поверхности или контуру
Stamp.
Industrial equipment, by means of which
the workpiece acquires the shape or size,
the corresponding surface or the contour
of the working elements of a stamp
рабочих элементов штампа
[ГОСТ 15830 84]
Эффективность защиты информации – степень соответствия результа-
тов защиты информации цели защиты
информации.
ГОСТ Р 50922 2006
Security Control Effectiveness – The
measure of correctness of implementation (i.e., how consistently the control
implementation complies with the security plan) and how well the security plan
meets organizational needs in accordance with current risk tolerance.
SOURCE: SP 800-137
НСД – несанкционированный доступ – unauthorized access
99

Компьютерная защита информации
Web-сервер – общедоступный в Сети
информационный сервер, использующий гипертекстовую технологию.
СТРК-2001
Автоматизированные системы
(АС) – автоматизированная система:
Система, состоящая из персонала и
комплекса средств автоматизации его
деятельности, реализующая информационную технологию выполнения
установленных функций.
[ГОСТ 34.003 90, пункт 1.1], [СТР-К,
2001, пункт 1.3]
– в которых работает один пользова-
тель;
– многопользовательские.
Администратор АС – лицо, ответственное за функционирование автоматизированной системы в установленном штатном режиме работы.
[СТР-К, 2001, пункт 1.4]
Администратор защиты информации (в АС) – это субъект доступа,
ответственный за защиту автоматизированной системы от несанкционированного доступа к информации. [Руководящий документ Защита от несанкционированного доступа к информации Термины и определения,
пункт 29], [СТР-К, 2001, пункт 1.5]
Web Server – A software process that
runs on a host computer connected to the
Internet to respond to HTTP requests for
documents from client web browsers.
Automated Information system
(AS)
A generic term applied to all electronic
computing systems. Automated Information Systems (AIS) collect, store,
process, create, disseminate, communicate, or control data or information.
AIS are composed of computer hardware (e.g., automated data processing
equipment and associated devices that
may include communication equipment),
firmware, an operating system (OS), and
other applicable software.
– single-user;
– multiuser.
System Administrator – A person who
manages the technical aspects of a system.
SOURCE: SP 800-40
Administrator of information security
(in AS) – it is the subject responsible for
protection of the automated system from
unauthorized access to information.
100
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
