Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:Введение в информационную безопасность и защиту информации. Учебное пособие
.pdf
Правовая защита информации:
Защита информации правовыми методами, включающая в себя разработку законодательных и нормативных
правовых документов (актов), регулирующих отношения субъектов по
защите информации, применение
этих документов (актов), а также
надзор и контроль за их исполнением.
[ГОСТ Р 50922-2006, 2.2.1]
Разглашение информации: Несанкционированное доведение защищаемой информации до лиц, не имеющих
права доступа к этой информации.
[ГОСТ Р 53114-2008 3.3.11]
Распространение персональных
данных – действия, направленные на
передачу персональных данных определенному кругу лиц (передача персональных данных) или на ознакомление
с персональными данными неограниченного круга лиц, в том числе обнародование персональных данных в
средствах массовой информации, размещение в информационно-телекоммуникационных сетях или предоставление доступа к
персональным
данным каким-либо иным способом.
[Методические рекомендации по
обеспечению с помощью криптосредств безопасности персональных
данных при их обработке в информационных системах персональных
данных с использованием средств
автоматизации]
Регистрация – регистрация – процедура, посредством которой какойлибо орган фиксирует соответствующие признаки продукции, процесса
Legal protection of information: data
protection of legal methods, including
the development of legislative and regulatory documents (acts) that regulate
subjects regarding the protection of information, using of these documents
(acts), as well as supervision and control
over their execution.
Inadvertent Disclosure – Type of incident involving accidental exposure of
information to an
individual not authorized access.
SOURCE: CNSSI-4009
Distribution of personal data – actions
aimed to the transfer of personal data
defined group of individuals (personal
data) or to become acquainted with the
personal data the general public, including disclosure of personal information in
the media, placement in the information
and telecommunications networks or the
provision of access to personal data in
any other way.
Registration – The process through
which a party applies to become a subscriber of a Credentials Service Provider
(CSP) and a Registration Authority
81

или услуги либо особенности органа
или лица в соответствующем общедоступном перечне;
[ГОСТ Р 1.12-99: Государственная система стандартизации Российской Федерации. Стандартизация и смежные виды деятельности.
Термины и определения] регистрация
– завершение идентификации и
аутентификации пользователя;
[ГОСТ Р ИСО/ТО 13569-2007: Финансовые услуги. Рекомендации по
информационной безопасности] регистрация
– начальный этап процесса
осуществления взаимодействия радиочастотной метки с устройством
считывания/опроса;
[ГОСТ Р ИСО/МЭК 19762-3-2011:
Информационные технологии. Технологии автоматической идентификации и сбора данных (АИСД). Гармонизированный словарь. Часть 3.
Радиочастотная идентификация
(РЧИ)] регистрация – процесс получения биометрического образца от
конечного пользователя;
[ГОСТ Р ИСО/МЭК 19794-102010: Автоматическая идентифика-
ция. Идентификациябиометрическая.
Форматы обмена биометрическими
данными. Часть 10. Данные геометрии контура кисти руки] регистрация – процесс предоставления личной
идентификационной информации
биометрической системе, сопоставления уникального идентификатора с
данной идентификационной информацией, сбор и запись соответствующей личной информации в систему.
validates the identity of that party on
behalf of the CSP. SOURCE: CNSSI4009 The process through which an Applicant applies to become a Subscriber
of a CSP and an RA validates the identity of the Applicant on behalf of the CSP.
SOURCE: SP 800-63
82

[ГОСТ Р ИСО/МЭК 24713-2-2011:
Информационные технологии. Биометрия. Биометрические профили
для взаимодействия и обмена данными. Часть 2. Контроль физического доступа сотрудников аэропортов]
Режим секретности – совокупность
определяемых органами власти и
управления правил, которыми ограничивается допуск лиц к секретным
материалам и работам, регламентируется порядок пользования секретных
материалов, соответствующим образом регулируется поведение людей,
имеющих отношение к секретам,
и предусматриваются другие меры.
Риск: Влияние неопределенностей на
процесс достижения поставленных
целей.
[ГОСТ Р 53114-2008 3.2.9]
Security Marking – Human-readable
information affixed to information system components, removable media, or
output indicating the distribution limitations, handling caveats, and applicable
security markings.
SOURCE: SP 800-53
Risk – The level of impact on organizational operations (including mission,
functions, image, or reputation), organizational assets, or individuals resulting
from the operation of an information
system given the potential impact of a
threat and the likelihood of that threat
occurring.
SOURCE: FIPS 200
The level of impact on organizational
operations (including mission, functions,
image, or reputation), organizational
assets, individuals, other organizations,
or the Nation resulting from the operation of an information system given the
potential impact of a threat and the likelihood of that threat occurring.
SOURCE: SP 800-60
A measure of the extent to which an entity is threatened by a potential circum-
stance or event, and typically a function
of: (i) the adverse impacts that would
arise if the circumstance or event occurs;
83

and (ii) the likelihood of occurrence.
Note: Information system-related security risks are those risks that arise from the
loss of confidentiality, integrity, or
availability of information or information systems and consider the adverse
impacts to organizational operations
(including mission, functions, image, or
reputation), organizational assets, individuals, other organizations, and the
Nation.
SOURCE: SP 800-53
A measure of the extent to which an
entity is threatened by a potential circumstance or event, and typically a
function of: (1) the adverse impacts that
would arise if the circumstance or event
occurs;
and (2) the likelihood of occurrence.
Note: Information system-related securi-
ty risks are those risks that arise
from the loss of confidentiality, integri-
ty, or availability of information or
information systems and reflect the po-
tential adverse impacts to organizational
operations (including mission, functions,
image, or reputation), organizational
assets, individuals, other organizations,
and the
Nation.
SOURCE: CNSSI-4009
A measure of the extent to which an
entity is threatened by a potential circumstance or event, and typically a
function of: (i) the adverse impacts that
would arise if the circumstance or event
occurs; and (ii) the likelihood of occurrence.
84

Сертификация на соответствие
требованиям по безопасности информации – форма осуществляемого
органом по сертификации подтверждения соответствия объектов оценки
требованиям по безопасности информации, установленным техническими
регламентами, стандартами или условиями договоров.
ГОСТ Р 50922 2006
[Note: Information system-related security risks are those risks that arise from
the loss of confidentiality, integrity, or
availability of information or information systems and reflect the potential
adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets,
individuals, other organizations, and the
Nation. Adverse impacts to the Nation
include, for example, compromises to
information systems that support critical
infrastructure applications or are paramount to government continuity of operations as defined by the Department of
Homeland Security.]
SOURCE: SP 800-37; SP 800-53A
Certification
A comprehensive assessment of the
management, operational, and technical
security controls in an information system, made in support of security accreditation, to determine the extent to which
the controls are implemented correctly,
operating as intended, and producing the
desired outcome with respect to meeting
the security requirements for the system.
SOURCE: FIPS 200
The process of verifying the correctness
of a statement or claim and issuing a
certificate as to its correctness.
SOURCE: FIPS 201
Comprehensive evaluation of the tech-
nical and nontechnical security safeguards of an information system to support the accreditation process that establishes the extent to which a particular
design and implementation meets a set
of specified security requirements.
SOURCE: CNSSI-4009
85

Сигнализация попыток нарушения
защиты.
Система:
– защиты информации (СЗИ) - комплекс организационных мер и программно-технических (в том числе
криптографических) средств обеспечения безопасности информации в
автоматизированных системах;
[Руководящий документ Защита от
несанкционированного доступа к информации Термины и определения,
пункт 34.]
– защиты информации от несанкционированного доступа (СЗИ
НСД) – комплекс организационных
и программно-технических (в том
мер
числе криптографических) средств
защиты от несанкционированного
доступа к информации в автоматизированных системах.
[Руководящий документ Защита от
несанкционированного доступа к информации Термины и определения,
пункт 35.]
Система защиты информации: Со-
вокупность органов и (или) исполнителей, используемой ими техники
защиты информации, а также объектов защиты информации, организованная и функционирующая по правилам и нормам, установленным соответствующими документами в области защиты информации.
[ГОСТ Р 50922-2006, 2.4.3]
Alarm of attacks.
Information Systems Security Product
– Item (chip, module, assembly, or
equipment), technique, or service that
performs or relates to information systems security. SOURCE: CNSSI-4009
Information Systems Security – (INFOSEC) Protection of information systems against unauthorized access to or
modification of information, whether in
storage, processing, or transit, and
against the denial of service to authorized users, including those measures
necessary to detect, document, and
counter such threats. SOURCE:
CNSSI-4009
Information Systems Security Product
– Item (chip, module, assembly, or
equipment), technique, or service that
performs or relates to information systems security. SOURCE: CNSSI-4009)
86

Система защиты информации от
НСД (СЗИ НСД) – комплекс органи-
зационных мер и программнотехнических (при необходимости
криптографических) средств защиты
от несанкционированного доступа к
информации (несанкционированных
действий с ней) в автоматизированной системе.
СТРК-2001
Служба безопасности информации
(служба защиты информации (в
АС)) – это самостоятельное подразделение предприятия, которое занимается решением проблем информационной безопасности данной организации.
System of protection of information
from unauthorized access - a set of
organizational measures and the software and hardware (if necessary cryptographic) means of protection against
unauthorized access to information (unauthorized actions with it) in an automated system.
Information Systems Security Manager (ISSM) – Individual responsible for
the information assurance of a program,
organization, system, or enclave.
SOURCE: CNSSI-4009
Information Systems Security Officer
(ISSO) – Individual assigned responsi-
bility for maintaining the appropriate
operational security posture for an information system or program. SOURCE:
CNSSI-4009
Senior Agency Information Security
Officer (SAISO) – Official responsible
for carrying out the Chief Information
Officer responsibilities under the Federal
Information Security Management
Act (FISMA) and serving as the Chief
Information Officer’s primary liaison to
the agency’s authorizing officials, information system owners, and information system security officers.
SP 800-53 Note: Organizations subordinate to federal agencies may use the
term Senior Information Security Officer
or Chief Information Security Officer to
denote individuals filling positions with
similar responsibilities to
Senior Agency Information Security
Officers.
87

Событие – факт, состоящий в том,
что нечто произошло или в проблемной области, или в среде, или в информационной системе.
[ГОСТ 34.320 96].
Специалист по защите
информации.
Специальная защита – комплекс
организационных и технических мероприятий, обеспечивающих защиту
информации от утечки по каналам
побочных излучений и наводок.
[Методические рекомендации по
обеспечению с помощью криптосредств безопасности персональных
данных при их обработке в информационных системах персональных
данных с использованием средств
автоматизации]
Специальная проверка - проверка
объекта информатизации в целях выявления и изъятия возможно внедренных закладочных устройств.
ГОСТ Р 50922 2006
Специальное исследование (объекта защиты информации) – Исследо-
вание, проводимое в целях выявления
технических каналов утечки защищаемой информации и оценки
SOURCE: SP 800-53; SP 800-53A; SP
800-37; SP 800-60; FIPS
200; CNSSI-4009; 44 U.S.C., Sec. 3544
Information Security Service = SSI-
SO+ISSM+ISSO
Event – Any observable occurrence in a
network or system. SOURCE: SP 80061 Any observable occurrence in a system and/or network. Events sometimes
provide indication that an incident is
occurring. SOURCE: CNSSI-4009
Information Systems Security Manager (ISSM) – Individual responsible for
the information assurance of a program,
organization, system, or enclave.
SOURCE: CNSSI-4009
Special protection – a complex of organizational and technical measures that
protect information from leaking
through the channels and spurious interference.
Security Inspection – Examination of
an information system to determine
compliance with security policy, procedures, and practices.
SOURCE: CNSSI-4009
Security Test & Evaluation (ST&E) –
Examination and analysis of the safeguards required to protect an information system, as they have been applied in an operational environment,
88

соответствия защиты информации
(на объекте защиты) требованиям
нормативных и правовых документов
to determine the security posture of that
system.
SOURCE: CNSSI-4009
в области безопасности информации.
ГОСТ Р 50922 2006
Специальный персонал. Special staff.
Способ защиты информации: Поря-
док и правила применения определенных принципов и средств защиты
Protective Measures Those actions,
procedures, or designs implemented to
safeguard protected information
информации.
[ГОСТ Р 50922-2006, 2.3.1]
Средства:
– защиты – техническое, программное, программно-техническое средство, вещество и (или) материал,
предназначенные или используемые
для защиты информации;
[ГОСТ 50922-2006, пункт 2.7.2]
– технические средства разведки;
– технические средства промышлен-
ного шпионажа;
– криптографической защиты - сред-
ство вычислительной техники, осуществляющее криптографическое
преобразование информации для
обеспечения ее безопасности;
[ГОСТ 50922-2006, пункт 2.7.5]:
– аттестованные (
лицензированные);
– сертифицированные;
– вычислительной техники (СВТ);
– восстановления (СЗИ НСД);
– технические средства охраны;
– оперативного контроля и воздействия на безопасность АС.
– периодического контроля за це-
лостностью программной и информа-
Means:
– of protection – is technical, software,
software and hardware, material and (or)
material designed or implemented to
protect information;
– technical means of intelligence;
– technical means of industrial espionage;
– cryptographic protection - the means
of ADP equipment which is realizing
cryptography information transform for
support of its safety;
– certified (licensed);
– certified;
– of computing;
– of recovery (SPI UA);
– technical means of protection;
– of operational control and impact on
the safety of the AS;
– of periodic control over the integrity of
the software and information complex
protection;
– of obtain registration information and
the possibility of unauthorized users
from reading it.
ционной части КСЗ.
89

– получения регистрационной ин-
формации и возможности санкционированного ознакомления с ней.
Средство защиты информации –
техническое, программное, программно-техническое средство, вещество
и (или) материал, предназначенные
или используемые для защиты информации.
ГОСТ Р 50922 2006
Средство контроля эффективности
защиты информации – средство
защиты информации, предназначенное или используемое для контроля
эффективности защиты информации.
ГОСТ Р 50922 2006
Статус объектов доступа – текущее
состояние объектов, к которым
предоставляется доступ.
Строгий пропускной режим.
Субъект доступа – это лицо или про-
цесс, действия которого регламентируются правилами разграничения
доступа.
[Руководящий документ Защита от
несанкционированного доступа к информации Термины и определения,
пункт 6.]
Protective Measures – Those actions,
procedures, or designs implemented to
safeguard protected information.
Information Security Continuous
Monitoring (ISCM) – Maintaining on-
going awareness of information security,
vulnerabilities, and threats to support
organizational risk management decisions.
The status of objects of access – a current status of objects to which access is
provided.
Access Control – The process of granting or denying specific requests to:
1) obtain and use information and related information processing services; and
2) enter specific physical facilities (e.g.,
federal buildings, military establishments, border crossing entrances).
SOURCE: FIPS 201; CNSSI-4009
Access Profile – Association of a user
with a list of protected objects the user
may access. SOURCE: CNSSI-4009
90
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
