DLP (data loss prevention)
DLP (data loss prevention) is the set of tools and rules that keeps sensitive information from leaving the company by email, USB drives, the cloud or messaging apps without authorization. It classifies data and spots leak attempts, then blocks or logs them.
How TecnetOne handles it: Microsoft 365
data loss prevention, data leak prevention, information leakage
Related terms
Penetration testing (pentest)
A penetration test, or pentest, is a controlled and authorized attack on a company's systems to find and prove its vulnerabilities before a real attacker does. It ends with a report of prioritized findings and how to fix them.
Risk model
A risk model is the method an organization uses to identify its assets, the threats that affect them, how likely they are and the impact they would have, so it can decide what to protect first and how much to invest. It's the starting point of standards such as ISO 27001 and of the risk assessment an ISMS requires.
Digital signature
A digital signature is a cryptographic mechanism that guarantees an electronic document was issued by whoever claims to have issued it and wasn't modified after it was signed. It's the basis of advanced electronic signatures, and in many jurisdictions it carries the same legal weight as a handwritten signature when it meets the applicable requirements.
Vulnerability, CVE and CVSS
A vulnerability is a flaw in software or configuration that an attacker can exploit. A CVE is the unique public identifier assigned to each known vulnerability. CVSS is the 0-to-10 scale that rates its severity and helps decide what to fix first.
Security patch
A security patch is an update a vendor releases to fix a vulnerability in its software. Applying it on time closes the gap before an exploit appears, and patch management is the process of doing that in an orderly way across every device.
CIA triad (confidentiality, integrity and availability)
The CIA triad is the model that sums up the three goals of information security: confidentiality (only the right people get access), integrity (information isn't altered without authorization) and availability (it's ready when needed). Every security control, from a backup to encryption, protects at least one of the three.
Ready to put this into practice in your operation?
Tell us what you need and a TecnetOne engineer will get back to you.
Talk to an engineerTalk to an engineer
Tell us what you need and we’ll reply the same business day.