EP3R 2013 – Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
EP3R 2013 – Position Paper
Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
December 2013
European Union Agency for Network and Information Security www.enisa.europa.eu
EP3R 2013 – Position Paper
About ENISA
The European Union Agency for Network and Information Security (ENISA) is a centre of network and information security expertise for the EU, its member states, the private sector and Europe’s citizens. ENISA works with these groups to develop advice and recommendations on good practice in information security. It assists EU member states in implementing relevant EU legislation and works to improve the resilience of Europe’s critical information infrastructure and networks. ENISA seeks to enhance existing expertise in EU member states by supporting the development of cross-border communities committed to improving network and information security throughout the EU. More information about ENISA and its work can be found at www.enisa.europa.eu.
Editors
Lionel Dupré, ENISA Rossella Mattioli, ENISA
Contact
For contacting the authors please use resilience@enisa.europa.eu. For media enquires about this paper, please use press@enisa.europa.eu.
Acknowledgements
The following EP3R Experts volunteered to participate in the task forces:
Terminology Definitions
- Athina Fragkouli RIPE NCC - Bastiaan Goslings AMS-IX - Christian Doerr University of Delft - Cornelia Kutterer Microsoft - John Michael Foley Danish Ministry of Defence / Project office for Cyber Security - Michele Minichino Enea - Octavia Frota High-Ads - Simona Cavallini Formit - Wim Degezelle CENTR
Assets Categorisation
- Athina Fragkouli RIPE NCC - Benjamin Lambrecht BSI - German Federal Office for Information Security - Chris Buckridge RIPE NCC - Genseric Cantournet Telecom Italia - Luis Ángel Fernández Escabías Bdigital - Octavia Frota High-Ads - Bastiaan Goslings AMS-IX - Patrick Palm Ericsson - Peter Biro Ministry of Finance of the Slovak Republic
Page ii
EP3R 2013 – Position Paper
- Uwe Jendricke BSI - German Federal Office for Information Security
Legal notice
Copyright Notice
Page iii
EP3R 2013 – Position Paper
Executive summary
Since 2011, the plenary sessions of EP3R addressed a number of topics ranging from Trusted Information Sharing, Incidents Preparedness and Management, Mutual Aid Assistance and the Protection of Critical Information Infrastructure. As EP3R discussions progressed, participants realised gradually that many concepts and terms were not clearly defined. During Summer 2012, the EP3R constituency devised a number of Work Objectives, and the initial Working Group 1 on Key Assets Categorisation led to the Creation of two Task Forces to issue a proposal for a methodology. The two topics addressed would be “Terminology Definitions” on one hand, and “Categorisation of Assets” on the other hand. Since a common terminology is the base of the characterisation of assets, it was later decided to use the latter to initiate the first. Both Task Forces were given 3 months to reach a conclusion on both topics. A few teleconferences and individual contributions helped to build this document. Together, the efforts of these two different task forces also represent the starting point for future efforts to secure and improve resilience in Europe’s cross-border and cross-organization context. Another important trait of these two task forces with the other EP3R position papers is the use of the Mutual Aid for Resilient Infrastructure In Europe (MARIE) ingredients in order to offer to all the interested stakeholders a comprehensive and articulated approach for cooperation and collaboration. The work produced by both Task Forces includes: - A list of commonly accepted Terminology sources; (see Annex A) - A proposal to categorise Terminology definitions according to their context; (Annex C) - An initial devise of key terms, those initially necessary to all Task Forces and further EP3R works; (Chapter 2.4) - An ontology for categorisation of assets and future development of Terminology Definitions; (Chapter 3.2)
As a common approach to subsequent activities (such as Risk Management, Business Continuity Management, etc). The Task Force recommends the pragmatic adoption of the 8 Ingredients devised in the M.A.R.I.E. (Mutual Aid for Resilient Infrastructure in Europe) as root Categories for Key ICT Assets. Should other sectors be later considered, a similar ontology could be developed where needed. Those recommendations were intended for EP3R, but however are valid for any Public-Private Partnership including EP3R’s successor, the NIS Platform.
Page iv
EP3R 2013 – Position Paper
Table of Contents
1 Introduction 1 2 Adoption of Terminology Sources 3 3 Assets Categorisation Principles 9 4 Conclusions 11
Page v
EP3R 2013 – Position Paper
1 Introduction
This Position Paper intends to establish the foundations of a commonly accepted and adopted methodology to define proper Terminology within EP3R, and later allow a concise Key Assets Categorisation. Such a Position Paper was intentionally kept small so it could be easily communicated and shared among EP3R participants to foster common understanding in a fast and effective way. The principle adopted within EP3R was that each Task Force would establish their own specific Terminology whenever required, and use this approach as a principle.
Goal
The purpose of inventorying Terminology sources was initially to ensure that all Participants could work on the same grounds, and allow discussions to be cleared from any misunderstanding.
Target audience
This Position Paper is addressed to all EP3R participants and the NIS Platform Working Groups. The methodology used in these task forces is similar to previous EP3R efforts. Several seasoned industry experts from different organization and backgrounds provided their expertise and advice in the definition of the contents. Following to on-site meetings and the desktop research, some individual feedback and recommendations where provided and used to integrate the materials collaboratively exchanged and produced via email and during the open teleconferences. The contents and participation to these task forces was renewed in two different occasions and cover a wide spectrum of expertise and different type of organizations and backgrounds. These initial efforts lasted two months during Spring 2013.
Terminology Definitions
During the early stages of work in the EP3R working groups, Participants have many times reported that several words were lacking a clear definition and also a common understanding. As a consequence, discussions were hanging on details to clarify, instead of allowing a seemless and fluid debate. The EP3R Working Group 1 on Key Assets therefore recommended that a Glossary is collegially adopted by EP3R constituency as a reference for further works. For these reasons the scope of the Task Force was focused on: - Taking stock of existing Terminology definitions available freely (to avoid licencing issues); - Identifying commonly used terms in the CIIP sector; - Providing or reuse (where possible) for each term a simple and effective definition, avoiding controversial definitions as much as possible. - Using free sources for such definitions where available to build up their recommendations, or get authorisation from relevant author(s).
The Deliverable of the TF was defined as follows in the EP3R Work Objectives: - A list of Terms commonly used in the CIIP Industry;
Page 1
EP3R 2013 – Position Paper
- A proposal of definition for each term, reusing where possible open and free dictionaries; - A list of commonly used Sources in the ICT Sector.
Assets Categorisation
A risk assessment of the protection level of Critical Information Infrastructures depends initially on a comprehensive inventory of all the components which constitute them. These are generally referred to as “assets” and comprise equally physical and technical assets, facilities, but also resources (e.g. supply chain), functions (i.e. Human operations), and regulatory environment (e.g. Policies, Standards, etc). A proper risk analysis approach would take into consideration any ingredient of the resulting service operated, and assess each asset category’s risk occurrence and likelihood. Since EP3R focuses on the proper operations of Critical Information Infrastructures (and unlike the Art.13a regulation *not* on the services), the actual operations of the CII are under the initial scope of reflection. The Task force was requested to undertake all necessary actions to define a proper and useful approach to the usage of CII stakeholders to ensure all Critical Assets supporting CIIs are encompassed in risk analysis, business continuity planning and disaster recovery exercises, hence ensuring proper preparedness and response capability for disasters or incidents. This requirement arose following the presentation during an EP3R Plenary Session (December 2011) of a major Telecom Operator’s Risk Management methodology.
Among the activities undertaken, the following have been considered:
- Taking stock on current practices in place in Member States for defining NCIs; - Taking stock on Industry’s Risk Identification and Risk Management good practices; - Evaluating the setup a reference framework and initiate a research activity on the methodology for the identification of ECIIs. “Functional” supply chains could be identified together with connections/ interconnections. - Convergence to a final, simple result.
The Deliverable of the TF was defined as follows in the EP3R Work Objectives: - A taxonomy of typical components which constitute a Critical Information Infrastructure. - From the various methodologies proposed, select the parts relevant to Critical Information Infrastructures Protection, and establish a formal recommendation for a set of criteria allowing “Key Assets Identification”.
Page 2
EP3R 2013 – Position Paper
2 Adoption of Terminology Sources 2.1 Key Terminology
During the discussions of the Task force it was decided to start addressing the issue using a taxonomy approach. Due the short timeframe and the voluntary basis involvement it was considered difficult to produce a comprehensive glossary covering all the possible terms. Therefore the TF decided to give a clear and unique definition only of the most important concepts that represent the foundations of all EP3R efforts. ICANN The result is close to 160 definitions gathered • Bylaws for Internet Corporation for Assigned Names and Numbers from free access sources, properly referenced, IETF and some definitions developed by the TF • Internet Engineering Task Force - RFC 4949 members themselves when the existing ones ISACA were not satisfactory. • Control Objectives for Information and Related Technology (COBIT) ISO/IEC For the broader glossary it was preferred to • 27000 series - Information technology — Security techniques — Information security define a first list of most common term and for management systems — Overview and vocabulary. ITGI those not covered use taxonomy to • IT Control Objectives for Sarbanes-Oxley characterize the most important clusters and NATO bound them with the most relevant references • AAP-6, NATO Glossary of terms and definitions present in literature. IARU The following definitions were identified, • The Tampere Convention adopted by the Task Force, and used as United Kingdom's Cabinet Office foundation for all discussions relating to • Information Technology Infrastructure Library (ITIL) Critical Information Infrastructures. European Commission • Council directive 2008/114/EC on the identification and designation of European Critical Infrastructures and the assessment of the need to improve their protection • Green paper on a European programme for critical infrastructure protection -
2.2 Terminology Sources COM/2005/0576 Final
Page 3
EP3R 2013 – Position Paper
2.3 Categorising Terminology
A given term may take different meanings Environment depending of the context of use, and •space in a strategically located data centre therefore the use of categorisation will allow to overcome controversy in the Power adoption of terms. •diesel generator The process of organising the terminology Hardware required an initial assumption, and more specifically to avoid reinventing the wheel. •cell on wheels (COW) It was suggested to use the 8 ingredients 1 Software mentioned in the MARIE report in order to •program on hardware provided (above) align this output with previous works and to provide continuity both in scope and Network terminology. •spare critical ingress or egress capacity The full list of Categorised Terminology is attached in Annex C. Payload •creating, processing, storing or transporting data The definition of an agreed common terminology definition not only poses the Human baseline for Categorization of assets, but •cable splicer fosters also a the definition of mutual efforts between cross-industry and cross- ASPR border communities. Basing the •Agreements, Standards, Policy and Regulation terminology cluster reference on the Mutual Aid for Resilient Infrastructure In Europe (MARIE) eight ingredients provides a mutual starting point but also maximize the convergence of the task forces outputs, starting with the establishment of proper Terminology in each Category.
Rauscher, K.F., Krock, R.E. & Runyon, J.P., 2006. Eight ingredients of communications infrastructure: A systematic and comprehensive framework for enhancing network reliability and security A. P. Macwan, K. K. Mutha, & R. S. Hanmer, eds. Bell Labs Technical Journal, 11(3), pp.73–81.
Page 4
EP3R 2013 – Position Paper
2.4 Adopted Terms
The table below includes a (short) version of the definitions proposed by the Task Force Participants. We have selected initially terms extract from sources which do not originate from the ENISA Risk Management glossary.
A list of approximately 160 terms and their source and categorisation, please refer to the list attached in Annex C:
Term Categorization Definition Source
Backbone Network The central core of a network EP3R TF-TDCA aroudn which the remainder is built.
Component Hardware, An item of electronic EP3R TF-TDCA Network communications equipment that forms part or all of a node.
Critical Information Network Information infrastructure (like EP3R TF-TDCA Infrastructure networks, hardware, software, etc.) that is critical to the functioning of a nation or country, like IT that supports health- or energy-sectors.
Critical Infrastructure Hardware, an asset, system or part „COUNCIL DIRECTIVE Network thereof located in Member 2008/114/EC on the States that is essential for the identification and maintenance of vital societal designation of functions, health, safety, European critical security, economic or social infrastructures and well-being of people, and the the assessment of the disruption or destruction of need to improve their which would have a significant protection“ impact on a Member State as a result of the failure to maintain those functions. Disaster ASPR means a serious disruption The Tampere of the functioning of society, Convention posing a significant, widespread threat to human life, health, property or the environment, whether caused by accident, nature or human activity, and whether developing suddenly or as the result of complex, long-
Page 5
EP3R 2013 – Position Paper
Term Categorization Definition Source
term processes.
Disaster mitigation ASPR measures designed to The Tampere prevent, predict, prepare for, Convention respond to, monitor and/or mitigate the impact of, disaster 12. Relief operations means those activities designed to reduce loss of life, human suffering and damage to property and/or the environment caused by a disaster. Fixed network Network A network in which service EP3R TF-TDCA delivery to the customer is primarly over the physical communication links (e.g. copper or fiber potic cables). The end-user's connection into the network does not move.
Gateway Network A point of connection between EP3R TF-TDCA two dissimilar networks (e.g. between a fixed and mobile network)
Incident ASPR Any circumstance or event Proposal for a having an actual adverse effect DIRECTIVE OF THE on security. EUROPEAN PARLIAMENT AND OF THE COUNCIL concerning measures to ensure a high common level of network and information security across the Union
Interconnection Network The connection between two EP3R TF-TDCA similar networks (e.g. a link between to CSPs and ISPs as a means of passing traffic between them. ISP Network, An Internet Service Provider - EP3R TF-TDCA Human normally not providing fixed or
Page 6
EP3R 2013 – Position Paper
Term Categorization Definition Source
mobile voice services.
Likelihood ASPR The chance of something EP3R TF-TDCA happening. Location Environment The physical presence of a EP3R TF-TDCA node. Mobile Network Network A network in which service EP3R TF-TDCA delivery to the customer is primarly over virtual communication links (e.g. radio). The end-user's connection into the network does may move, and the network will maintain the connection. Network Network A network is a system of EP3R TF-TDCA interconnected nodes, each of which is able to deliver a function or service local to that node, but which may be a component in delivering services more widely.
Node Network, A node is a single point of EP3R TF-TDCA Hardware connection. At a high level, nodes interconnect with one another to form a network.At a low level, nodes are used to connect customers into the network. Protection Security EP3R TF-TDCA
Resilience Network ISO Guide 73
Risk Security The effect of uncertainity on EP3R TF-TDCA objectives. Telecommunication ASPR the provision of The Tampere assistance telecommunication resources Convention or other resources or support intended to facilitate the use of telecommunication resources.
Telecommunication Network, personnel, equipment, The Tampere resources Hardware materials, information, Convention training, radio-frequency spectrum, network or
Page 7
EP3R 2013 – Position Paper
Term Categorization Definition Source
transmission capacity or other resources necessary to telecommunications.
Telecommunications Network, any transmission, emission, Tampere Convention Hardware or reception of signs, signals, writing, images, sounds or intelligence of any nature, by wire, radio, optical fibre or other electromagnetic system. Traffic Network The actual voice or data EP3R TF-TDCA communication sent and received between two nodes.
Traffic shaping Network When traffic through packed EP3R TF-TDCA based networks becomes slow, and latency increases, traffic shaping is the action of controlling the volume of packets sent into the network (sometimes referred as bandhwidth throttling)or the rate at which they are sent (rate limiting).
Vulnerability Security The intrinsic properties of EP3R TF-TDCA something resulting in susceptibility to a risk source that can lead to an event with a consequence.
Page 8
EP3R 2013 – Position Paper
3 Assets Categorisation Principles 3.1 Introduction
Since the beginnings of EP3R, the Assets Categorization Task Force has discussed several approaches on how to address the most important issues and which best practises to consider. During the teleconferences several methods have been discussed in order to create an initial risk mapping ontology in order to follow the path traced by existing literature regarding CI. Existing experiences 3 4 like the one in Finland and UK were cited as possible examples to refer to. The initial idea was to focus on public networks and align the work with the Art 13a content, which is the obligation for the Telecom Operators to report incidents. Therefore it was decided to proceed initially with definitions of Critical Infrastructure / Critical Information Infrastructure / European Critical Infrastructure. Moreover the different business models that can be applied in the Telco sector (fixed/mobile/connectivity provider) were emphasised and also the consequent different definitions of criticality.
3.2 Initial Ontology
During the initial open teleconferences the task force decided to tackle the problem starting from the differences between Internet Exchanges points (IXs) and manufacturers methodologies: IXs are more focused on the physical and supply chain and the data/control plane repercussions, while Manufacturers will concentrate on the meta-classification of specific assets. Moreover the different business models that can be applied in the Telco sector (fixed/mobile/connectivity provider) were emphasised and also the consequent different definitions of criticality.
In the course of the proceedings and discussions with the experts it was decided to use primarily the Mutual Aid for Resilient Infrastructure in Europe (MARIE) eight ingredients to align the output with the other task forces.
This effort helps to draw a red line between the different goals and have a more holistic approach. In the presented table the effort of the TF are sketched in order to give the an overview of the possible different aspects that must be addressed. The following ontology should therefore be viewed as a means of gaining a foothold in an extensive, dynamic subject rather than as a statement of universally accepted fact.
Page 9
EP3R 2013 – Position Paper
In the presented table the effort of the TF are sketched in order to give the an overview of the possible different aspects that must be addressed
The idea was to identify generic high level critical component that can be, once the ontology is released, tailored due to the specific business model and size of the organization.
Thus by using the Mutual Aid for Resilient Infrastructure In Europe (MARIE) eight ingredients this could be also connected with all the related literature and efforts and allow the interested parties to foster collaboration based on the same terminology baseline. For this reason also the terminology definition approach that follows makes use of the same categorisation.
The figure below shows a initial proposal classification of activities, assets and paves the way for Terminology categorisation and development as well.
Page 10
EP3R 2013 – Position Paper
4 Conclusion
This work was intended to be a very first step within EP3R that could be a foundation for later developments. The Task Forces ran for two months, just before the EP3R was subsumed to the NIS Platform. This was actually the first attempt within the European Public Private Partnership for Resilience to reach convergence points in Participants’ understanding, and allow to prevent many misunderstandings as they used to happen in the past. The Task Force acknowledges that this iteration solely addresses the Telecom Sector, and suggests that it should be expanded to Sectors which depend on ICT, such as Health, Finance, Transports, Energy. But also, such definitions might be also needed for the specifics of CyberSecurity areas: Botnets, Cyber Police, etc. The process for each Sector should be similar, i.e. the identification of Terminology Sources relevant to the Sector considered, submitting a consolidated listing of terms to a panel of Experts, and their formal adoption of one definition per term. Among the important uses of Terminology Definitions, the Task Force felt that Mutual Aid Assistance was probably the most crucial, since all participants in the Agreement need to speak the same language. Some specifics of Mutual Aid Assistance should therefore be explored and a proper list of defined terms adopted. In the Working Groups meeting of the NIS Platform, a few participants raised the need for starting a similar initiative. EP3R therefore hands over its initial conclusions so their starting point is already more advanced than for EP3R, 4 years ago.
Page 11
EP3R 2013 – Position Paper
Annex A: Glossary and Terminology Sources
- ISO/IEC 27000 series - Information technology — Security techniques — Information security management systems — Overview and vocabulary. http://standards.iso.org/ittf/PubliclyAvailableStandards/c056891_ISO_IEC_27000_2012(E).zi p - United Kingdom's Cabinet Office - Information Technology Infrastructure Library (ITIL) http://www.itil-officialsite.com/home/home.aspx - ISACA - Control Objectives for Information and Related Technology (COBIT) http://www.isaca.org/knowledge-center/cobit/Pages/Overview.aspx - ITGI - IT Control Objectives for Sarbanes-Oxley 2nd Edition http://www.isaca.org/Knowledge-Center/Research/ResearchDeliverables/Pages/IT-Control- Objectives-for-Sarbanes-Oxley-2nd-Edition.aspx - MERIDIAN PROCESS resources http://meridianprocess.org - NATO - AAP-6, NATO Glossary of terms and definitions http://nsa.nato.int/nsa/zPublic/ap/aap6/AAP-6.pdf - ENISA Risk Management - Glossary http://www.enisa.europa.eu/activities/riskmanagement/current-risk/risk-management-inventory/glossary - NIST - Glossary of Key Information Security Terms http://nvlpubs.nist.gov/nistpubs/ir/2013/NIST.IR.7298r2.pdf - CIIP Handbook 2004 - section A1 Key Terms http://www.emsec.rub.de/media/crypto/attachments/files/2011/03/ciip_handbook_2004_ ethz.pdf - CRS Report for Congress - Critical Infrastructure and Key Assets: Definition and Identification http://www.fas.org/sgp/crs/RL32631.pdf - European Commission - Council Directive 2008/114/EC of 8 December 2008 on the identification and designation of European critical infrastructures and the assessment of the need to improve their protection. http://europa.eu/legislation_summaries/justice_freedom_security/fight_against_terrorism/ jl0013_en.htm - Final Report to European Commission - Study on Risk Governance of European Critical Infrastructures in the ICT and Energy Sector http://ec.europa.eu/energy/infrastructure/studies/doc/2009_10_risk_governance_report.p df - ITU - List of security-related terms, acronyms and definitions http://www.itu.int/ITU- T/studygroups/com17/def005.doc - ITU - Technical and Procedural Measures for Cybersecurity http://www.itu.int/osg/csd/cybersecurity/gca/docs/global_strategic_report.pdf#page=76 - DHS - Infrastructure Data Taxonomy: Common Terminology for Describing Critical Infrastructure http://www.dhs.gov/infrastructure-taxonomy
Page 12
EP3R 2013 – Position Paper
Annex B: Assets Categorisation References
- X.805 – Security architecture for systems providing end-to-end communications http://www.itu.int/rec/T-REC-X.805-200310-I/en - ISO/IEC 27011 Information technology — Security techniques — Information security management guidelines for telecommunications organizations based on ISO/IEC 27002 http://webstore.iec.ch/preview/info_isoiec27011%7Bed1.0%7Den.pdf - The European Perspective of Telecommunications as a Critical Infrastructure http://link.springer.com/content/pdf/10.1007%2F978-3-642-35764-0_1.pdf - Critical infrastructure and key assets: definition and identification http://www.fas.org/sgp/crs/RL32631.pdf - Rauscher, K.F., Krock, R.E. & Runyon, J.P., 2006. Eight ingredients of communications infrastructure: A systematic and comprehensive framework for enhancing network reliability and security A. P. Macwan, K. K. Mutha, & R. S. Hanmer, eds. Bell Labs Technical Journal, 11(3), pp.73–81.
Page 13
EP3R 2013 – Position Paper
Annex C: Full list of Adopted Terms, and their proposed Categorisation
Term Categorization Definition Source Link
Acceptable Risk ASPR The level of residual risk that has been determined to be a reasonable NIST SP 800-16 http://csrc.nist.gov/publications/nist level of potential loss/disruption for a specific system. Information Technology pubs/800-16/AppendixA-D.pdf Security Training Requirements - Appendix A
Access control Security Means to ensure that access to assets is authorized and restricted based ISO/IEC 27000 2.1 on business and security requirements.
Accountability Security The property that ensures that the actions of an entity may be traced ISO/IEC PDTR 13335-1 / http://www.enisa.europa.eu/activiti uniquely to the entity. (ISO/IEC PDTR 13335-1).This may cover non ENISA Risk Assessment es/risk-management/currentrepudiation, deterrence, fault isolation, intrusion detection and Glossary risk/risk-managementprevention, and after-action recovery and legal action. inventory/glossary
Accountability Security The property of a system (including all of its system resources) that IETF Internet http://www.ietf.org/rfc/rfc2828.txt ensures that the actions of a system entity may be traced uniquely to Engineering Task Force that entity, which can be held responsible for its actions. RFC 2828 Accountability Security Responsibility of an entity for its actions and decisions. ISO/IEC 27000 2.2
Asset Hardware, Anything that has value to the organization ISO/IEC 27000:2012 http://www.iso.org/iso/catalogue_d Software Information technology - etail?csnumber=56891 - Security techniques -- Information security management systems -- Overview and vocabulary
Page 1
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Asset Hardware, Anything that has value to the organization, its business operations and ISO/IEC PDTR 13335-1 / http://www.enisa.europa.eu/activiti Software their continuity, including Information resources that support the ENISA Risk Assessment es/risk-management/currentorganization's mission. Glossary risk/risk-managementinventory/glossary Asset Hardware, Anything that has value to the organization. NOTE There are many types ISO/IEC 27000 2.3 Software of assets, including: a) information; b) software, such as a computer program; c) physical, such as computer; d) services; e) people, and their qualifications, skills, and experience; and f) intangibles, such as reputation and image.
Attack Security Attempt to destroy, expose, alter, disable, steal or gain unauthorized ISO/IEC 27000 2.4 access to or make unauthorized use of an asset.
Authentication Security The provision of assurance that a claimed characteristic of an entity is ISO/IEC 27000:2012 http://www.iso.org/iso/catalogue_d correct Information technology - etail?csnumber=56891 - Security techniques -- Information security management systems -- Overview and vocabulary
Authenticity Security Property that an entity is what it claims to be Control (ISO/IEC 27000 ISO/IEC 27000 2.6 2.10): means of managing risk, including policies, procedure, guidelines, practices or organizational structures, which can be administrative, technical, management, or legal in nature. NOTE Control is also used as a synonym for safeguard or countermeasure. Availability Security Proprety of being accessible and usable upon demand by an authorized ISO/IEC 27000:2012 http://www.iso.org/iso/catalogue_d entity. Information technology - etail?csnumber=56891 - Security techniques -- Information security
Page 2
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
management systems -- Overview and vocabulary
Backbone Network The central core of a network aroudn which the remainder is built. EP3R TF-TDCA
Bot Security A malicious or potentially malicious bot (derived from the word "robot", IETF Internet http://www.ietf.org/rfc/rfc6561.txt hereafter simply referred to as a "bot") refers to a program that is Engineering Task Force installed on a system in order to enable that system to automatically (or RFC6561 semi-automatically) perform a task or set of tasks typically under the command and control of a remote administrator, or "bot master". Bots are also known as "zombies". Such bots may have been installed surreptitiously, without the user's full understanding of what the bot will do once installed, unknowingly as part of another software installation, under false pretenses, and/or in a variety of other possible ways.
Botnet Security A "bot network", or "botnet", is defined as a concerted network of bots IETF Internet http://www.ietf.org/rfc/rfc6561.txt capable of acting on instructions generated remotely. Engineering Task Force - The malicious activities are either focused on the information on the RFC6561 local machine or acting to provide services for remote machines. Bots are highly customizable so they can be programmed to do many things. The major malicious activities include but are not limited to identity theft, spam, spim (spam over Instant Messaging (IM)), spit (spam over Internet telephony), email address harvesting, distributed denial-ofservice (DDoS) attacks, key-logging, fraudulent DNS pharming (redirection), hosting proxy services, fast flux hosting, hosting of illegal content, use in man-in-the-middle attacks, and click fraud.
Page 3
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Business ASPR The capability of the organization to continue delivery of products and ISO 22301:2012 Societal http://www.iso.org/iso/catalogue_d Continuity services at acceptable predefined levels following a disruptive incident. security -- Business etail?csnumber=50038 continuity management systems --- Requirements Business ASPR Processes and/or procedures for ensuring continued business ISO/IEC 27000 2.8 continuity operations. BusinessImpact ASPR The process of analyzing activities and the effect that a business ISO 22301:2012 Societal http://www.iso.org/iso/catalogue_d Analysis distruption might have upon them. security -- Business etail?csnumber=50038 continuity management systems --- Requirements
Component Hardware, An item of electronic communications equipment that forms part or all EP3R TF-TDCA Network of a node. Confidentiality Security Property that information is not made available or disclosed to ISO/IEC 27000:2012 http://www.iso.org/iso/catalogue_d unauthorized individuals, entities and processes. Information technology - etail?csnumber=56891 - Security techniques -- Information security management systems -- Overview and vocabulary
Connection Hardware, A communication channel between two or more end-points (e.g. 3GPP TR 21.905 V8.5.0 http://www.quintillion.co.jp/3GPP/S Network terminal, server etc.). (2008-06) 3rd pecs/21905-850.pdf Generation Partnership Project;Technical Specification Group Services and System
Page 4
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Aspects; Vocabulary for 3GPP Specifications
Consequence Security Outcome of an event. There can be more than one consequence from ISO/IEC Guide 73 / http://www.enisa.europa.eu/activiti one event. Consequences can range from positive to negative. ENISA Risk Assessment es/risk-management/current- Consequences can be expressed qualitatively or quantitatively Glossary risk/risk-managementinventory/glossary Contingency ASPR A plan for emergency response, backup operations, and post-disaster IETF Internet http://www.enisa.europa.eu/activiti Plan recovery in a system as part of a security program to ensure availability Engineering Task Force - es/risk-management/currentof critical system resources and facilitate continuity of operations in a RFC 4949 risk/risk-managementcrisis. inventory/glossary Control ASPR ENISA Risk Assessment http://www.enisa.europa.eu/activiti Glossary es/risk-management/currentrisk/risk-managementinventory/glossary Control ASPR Statement describing what is to be achieved as a result of implementing ISO/IEC 27000 2.11 objective controls. Corrective ASPR Action to eliminate the cause of a detected nonconformity or other ISO/IEC 27000 2.12 action undesirable situation. Crisis ASPR ISO 22300 Societal security — Terminology Critical Network Information infrastructure (like networks, hardware, software, etc.) that EP3R TF-TDCA Information is critical to the functioning of a nation or country, like IT that supports Infrastructure health- or energy-sectors.
Page 5
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Critical Hardware, an asset, system or part thereof located in Member States that is „COUNCIL DIRECTIVE Infrastructure Network essential for the maintenance of vital societal functions, health, safety, 2008/114/EC on the security, economic or social well-being of people, and the disruption or identification and destruction of which would have a significant impact on a Member State designation of European as a result of the failure to maintain those functions. critical infrastructures and the assessment of the need to improve their protection“
CSP Communication Service Provider - normally providing either a fixed or Technical Specification mobile voice and data service, which may include Internet access. Group Services and System Aspects;
Customer An individual or organization paying for a service from a CISP or a ISP. Vocabulary for 3GPP Specifications
Data Security The fact that data is accessible and services are operational. ENISA Risk Assessment http://www.enisa.europa.eu/activiti Availability Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Data Security The protection of communications or stored data against interception ENISA Risk Assessment http://www.enisa.europa.eu/activiti Confidentiality and reading by unauthorized persons. (ENISA). The property that Glossary es/risk-management/currentinformation is not made available or disclosed to unauthorized risk/risk-managementindividuals, entities, or processes. (ISO/IEC PDTR 13335-1) inventory/glossary
Data Integrity Security The confirmation that data which has been sent, received, or stored are ENISA Risk Assessment http://www.enisa.europa.eu/activiti complete and unchanged. (ENISA) The property that data has not been Glossary es/risk-management/currentaltered or destroyed in an unauthorized manner. (ISO/IEC PDTR 13335-1) risk/risk-managementinventory/glossary
Page 6
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Definition of Security Process for the establishment of global parameters for the performance ENISA Risk Assessment http://www.enisa.europa.eu/activiti Scope of Risk Management within an organization. Within the definition of Glossary es/risk-management/currentscope for Risk Management internal and external factors have to be risk/risk-managementtaken into account. (ENISA) inventory/glossary Disaster ASPR means a serious disruption of the functioning of society, posing a The Tampere http://www.itu.int/ITUsignificant, widespread threat to human life, health, property or the Convention D/emergencytelecoms/Tampere_co environment, whether caused by accident, nature or human activity, nvention.pdf and whether developing suddenly or as the result of complex, longterm processes.
Disaster ASPR ISO 22300 Societal security — Terminology
Disaster ASPR measures designed to prevent, predict, prepare for, respond to, The Tampere http://www.itu.int/ITUmitigation monitor and/or mitigate the impact of, disaster 12. Relief operations Convention D/emergencytelecoms/Tampere_co means those activities designed to reduce loss of life, human suffering nvention.pdf and damage to property and/or the environment caused by a disaster.
Disaster ASPR A coordinated activity to enable the recovery of telecom/IT/business ETSI TR 102 445 V1.1.1 http://www.etsi.org/deliver/etsi_tr/ Recovery systems to a disruption. (2006-10)3 Emergency 102400_102499/102445/01.01.01_6 Communications 0/tr_102445v010101p.pdf (EMTEL); Overview of Emergency Communications Network Resilience and Preparedness
Disaster ASPR The process of restoring a system to full operation after an interruption ENISA Risk Assessment http://www.enisa.europa.eu/activiti Recovery in service, including equipment repair / replacement, file recovery / Glossary es/risk-management/currentrestoration. (ENISA) risk/risk-managementinventory/glossary
Page 7
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Diversity Network The ability to use,select or switch between different circuits to avoid ETSI TR 102 445 V1.1.1 http://www.etsi.org/deliver/etsi_tr/ congestion and network failure. (2006-10)3 Emergency 102400_102499/102445/01.01.01_6 Communications 0/tr_102445v010101p.pdf (EMTEL); Overview of Emergency Communications Network Resilience and Preparedness
Effectiveness ASPR Extent to which planned activities are realized and planned results ISO/IEC 27000 2.11 achieved [ISO 9000:2005]
Efficiency ASPR Relationship between the results achieved and how well the resources (ISO/IEC 27000 2.14 have been used.
Event Security Occurrence of a particular set of circumstances. The event can be certain ENISA Risk Assessment http://www.enisa.europa.eu/activiti or uncertain. The event can be a single occurrence or a series of Glossary es/risk-management/currentoccurrences. (ISO/IEC Guide 73) risk/risk-managementinventory/glossary
Event Security Occurrence of a particular set of circumstances [ISO/IEC Guide 73:2002]. ISO/IEC 27000 2.15 Evidence Security Information that either by itself or when used in conjunction with other ENISA Risk Assessment http://www.enisa.europa.eu/activiti information is used to establish proof about an event or action. Evidence Glossary es/risk-management/currentdoes not necessarily prove truth or existence of something but risk/risk-managementcontributes to establish proof. (ENISA) inventory/glossary Exposure Security The potential loss to an area due to the occurrence of an adverse event. ENISA Risk Assessment http://www.enisa.europa.eu/activiti (ISACA) Generally, in the Risk Management process a risk does not Glossary es/risk-management/currentalways represent a loss or a negative consequence but can also be an risk/risk-managementopportunity or a result of a positive event. (ENISA) inventory/glossary
Page 8
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Fault tolerance Hardware, Devices that are designed and built to correctly operate even in the ETSI TR 102 445 V1.1.1 http://www.etsi.org/deliver/etsi_tr/ Software presence of a software error or failed components. (2006-10)3 Emergency 102400_102499/102445/01.01.01_6 Communications 0/tr_102445v010101p.pdf (EMTEL); Overview of Emergency Communications Network Resilience and Preparedness
Fixed network Network A network in which service delivery to the customer is primarly over the EP3R TF-TDCA physical communication links (e.g. copper or fiber potic cables). The end-user's connection into the network does not move.
Gap Analysis ASPR A comparison that identifies the difference between the actual and the ENISA Risk Assessment http://www.enisa.europa.eu/activiti expected / specified system status. Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Gateway Network A point of connection between two dissimilar networks (e.g. between a EP3R TF-TDCA fixed and mobile network)
Guideline ASPR Recommendation of what is expected to be done to achieve an ISO/IEC 27000 2.16 objective.
Impact Security The result of an unwanted incident . (ISO/IEC PDTR 13335-1) ENISA Risk Assessment http://www.enisa.europa.eu/activiti Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Impact Security Adverse change to the level of business objectives achieved. ISO/IEC 27000 2.17
Page 9
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Impact Analysis Security The identification of critical business processes, and the potential ENISA Risk Assessment http://www.enisa.europa.eu/activiti damage or loss that may be caused to the organization resulting from a Glossary es/risk-management/currentdisruption to those processes. Business impact analysis identifies: the risk/risk-managementform the loss or damage will take; how that degree of damage or loss is inventory/glossary likely to escalate with time following an incident; the minimum staffing, facilities and services needed to enable business processes to continue to operate at a minimum acceptable level; the time for full recovery of the business processes (ENISA)
Impact or Security The outcome of an event affecting objectives. ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d consequence management -- etail?csnumber=44651 Vocabulary
incident ASPR any circumstance or event having an actual adverse effect on security. Proposal for a DIRECTIVE http://ec.europa.eu/information_so OF THE EUROPEAN ciety/newsroom/cf/dae/document.c PARLIAMENT AND OF fm?doc_id=1666 THE COUNCIL concerning measures to ensure a high common level of network and information security across the Union
Incident ASPR An event that has been assessed as having an actual or potentially ENISA Risk Assessment http://www.enisa.europa.eu/activiti adverse effect on the security or performance of a system. (ENISA) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Page 10
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Information Hardware, Knowledge or data that has value to the organization. ISO/IEC 27000 2.18 asset Software, Security, Network
Information Security Preservation of confidentiality , integrity and availability of information. ISO/IEC 27000 2.19 security NOTE In addition, other properties, such as authenticity , accountability , non-repudiation ), and reliability can also be involved.
Information Security Identified occurrence of a system, service or network state indicating a ISO/IEC 27000 2.20 security event possible breach of information security policy or failure of controls, or a previously unknown situation that may be security relevant.
Information Security Single or a series of unwanted or unexpected information security events ISO/IEC 27000 2.21 security that have a significant probability of compromising business operations incident and threatening information security.
information Security Processes for detecting, reporting, assessing, responding to, dealing ISO/IEC 27000 2.22 security with, and learning from information security incidents.
incident management
Information Security Part of the overall management system), based on a business risk ISO/IEC 27000 2.23 security approach, to establish, implement, operate, monitor, review, maintain management and improve information security.
system ISMS
Information Security Potential that a threat will exploit a vulnerability of an asset or group of ISO/IEC 27000 2.24 security risk assets and thereby cause harm to the organization.
Integrity Security Property of protecting the accuracy and completeness of assets. ISO/IEC 27000:2012 http://www.iso.org/iso/catalogue_d Information technology - etail?csnumber=56891 - Security techniques --
Page 11
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Information security management systems -- Overview and vocabulary Interconnection Network The connection between two similar networks (e.g. a link between to EP3R TF-TDCA CSPs and ISPs as a means of passing traffic between them. Interested Party Human Person or group having an interest in the performance or success of an ENISA Risk Assessment http://www.enisa.europa.eu/activiti organization’s mission or objectives. (ISO/IEC Guide 73) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary Internet Network The Internet is the single, interconnected, worldwide system of IETF Internet http://tools.ietf.org/html/rfc4949 commercial, governmental, educational, and other computer networks Engineering Task Force that share (a) the protocol suite specified by the IAB (RFC 2026) and (b) RFC 4949 the name and address spaces managed by the ICANN. ISP Network, An Internet Service Provider - normally not providing fixed or mobile EP3R TF-TDCA Human voice services. Likelihood ASPR The chance of something happening. EP3R TF-TDCA Location Environment The physical presence of a node. EP3R TF-TDCA Management Software Framework of policies, procedures, guidelines and associated resources ISO/IEC 27000 2.26 system to achieve the objectives of the organization Mitigation ASPR Limitation of any negative consequence of a particular event . (ISO/IEC ENISA Risk Assessment http://www.enisa.europa.eu/activiti Guide 73) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Page 12
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Mobile Network Network A network in which service delivery to the customer is primarly over EP3R TF-TDCA virtual communication links (e.g. radio). The end-user's connection into the network does may move, and the network will maintain the connection. Monitor and Network, A process for measuring the efficiency and effectiveness of the ENISA Risk Assessment http://www.enisa.europa.eu/activiti Review Human, organization’s Risk Management processes is the establishment of an Glossary es/risk-management/current- Software, ongoing monitor and review process. This process makes sure that the risk/risk-management- Hardware, ASPR specified management action plans remain relevant and updated. This inventory/glossary process also implements control activities including re-evaluation of the scope and compliance with decisions. (ENISA)
Mutual Aid ASPR ISO 22300 Societal Agreement security — Terminology
Network Network A network is a system of interconnected nodes, each of which is able to EP3R TF-TDCA deliver a function or service local to that node, but which may be a component in delivering services more widely. Node Network, A node is a single point of connection. At a high level, nodes interconnect EP3R TF-TDCA Hardware with one another to form a network.At a low level, nodes are used to connect customers into the network. Non Security The ability to prove the occurrence of a claimed event or action and its ISO/IEC 27000:2012 http://www.iso.org/iso/catalogue_d Repudiation originating entities, in order to resolve disputes about the occurrence or Information technology - etail?csnumber=56891 non-occurrence of the event or action and involvement of entities in the - Security techniques -event. Information security management systems -- Overview and vocabulary
Patnership ASPR ISO 22300 Societal
Page 13
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
security — Terminology
Policy ASPR Overall intention and direction as formally expressed by management. ISO/IEC 27000 2.28
Preventive ASPR Action to eliminate the cause of a potential nonconformity or other ISO/IEC 27000 2.29 action undesirable potential situation. [ISO 9000:2005]
Priority Network Sequence in which an incident or problem needs to be resolved, based ENISA Risk Assessment http://www.enisa.europa.eu/activiti on impact and urgency. (ENISA) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Probability Security The measure of the chance of occurrence expressed as a number ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d between 0 and 1, where 0 is impossibility and 1 is absolute certainity. management -- etail?csnumber=44651 Vocabulary
Probability Security Extent to which an event is likely to occur.(ENISA) ENISA Risk Assessment http://www.enisa.europa.eu/activiti Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Procedure ASPR A written description of a course of action to be taken to perform a given ENISA Risk Assessment http://www.enisa.europa.eu/activiti task. (ENISA) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Procedure ASPR ISO/IEC 27000 2.29
Process ASPR An organized set of activities which uses resources to transform inputs ENISA Risk Assessment http://www.enisa.europa.eu/activiti to outputs. (ENISA) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Page 14
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Process ASPR Set of interrelated or interacting activities which transforms inputs into ISO/IEC 27000 2.31 outputs [ISO 9000:2005] Process Owner ASPR An individual held accountable and responsible for the workings and ENISA Risk Assessment http://www.enisa.europa.eu/activiti improvement of one of the organization's defined processes and its Glossary es/risk-management/currentrelated sub-processes. (ENISA) risk/risk-managementinventory/glossary Protection Security EP3R TF-TDCA Record Payload Document stating results achieved or providing evidence of activities ISO/IEC 27000 2.32 performed. [ISO 9000:2005] Redundancy Network The inclusion of extra components, which are not strictly necessary to The Oxford English http://www.oed.com/ functioning, in case of failure in other components. Dictionary Reliability Network, Property of consistent intended behaviour and results. ISO/IEC 27000 2.33 Hardware, Software Residual Risk Security Risk emaining after risk treatment. (ISO/IEC Guide 73) ENISA Risk Assessment http://www.enisa.europa.eu/activiti Glossary es/risk-management/currentrisk/risk-managementinventory/glossary Resilience Network ISO Guide 73 Resilience Network The resilience of an organization to resist to being affected by ISO/IEC 27031:2011 http://www.iso.org/iso/catalogue_d disruption. Information technology - etail?csnumber=44374 - Security techniques -- Guidelines for information and communication
Page 15
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
technology readiness for business continuity
Risk Security The effect of uncertainity on objectives. EP3R TF-TDCA http://www.iso.org/iso/catalogue_d etail?csnumber=44651 Risk Security The potential that a given threat will exploit vulnerabilities of an asset or ENISA Risk Assessment http://www.enisa.europa.eu/activiti group of assets and thereby cause harm to the organization. (ISO/IEC Glossary es/risk-management/current- PDTR 13335-1) risk/risk-managementinventory/glossary Risk Security Combination of the probability of an event and its consequence. [ISO/IEC ISO/IEC 27000 2.34 Guide 73:2002] Risk acceptance Security Informed decision of taking a particular risk . Information technology - http://www.iso.org/iso/catalogue_d - Security techniques -- etail?csnumber=44651 Guidelines for information and communication technology readiness for business continuity Risk Acceptance Security The potential that a given threat will exploit vulnerabilities of an asset or ENISA Risk Assessment http://www.enisa.europa.eu/activiti group of assets and thereby cause harm to the organization. (ISO/IEC Glossary es/risk-management/current- PDTR 13335-1) Risk acceptance depends on risk criteria defined within risk/risk-managementthe process Definition of Scope. (Definition adopted from ISO/IEC Guide inventory/glossary 73 with some modification by ENISA) Risk acceptance Security Risk acceptance (ISO/IEC 27000 2.35): decision to accept a risk (2.34) ISO/IEC 27000 2.35 [ISO/IEC Guide]
Page 16
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Risk Analysis Security Systematic use of information to identify sources and to estimate the ENISA Risk Assessment http://www.enisa.europa.eu/activiti risk. Risk analysis provides a basis for risk evaluation , risk treatment and Glossary es/risk-management/currentrisk acceptance. ISO/IEC Guide 73 risk/risk-managementinventory/glossary Risk analysis Security systematic use of information to identify sources and to estimate risk ISO/IEC 27000 2.36 [ISO/IEC Guide 73:2002] NOTE Risk analysis provides a basis for risk evaluation , risk treatment and risk acceptance . Risk assessment Security The overall process of risk identification, risk analysis and risk evaluation. ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d management -- etail?csnumber=44651 Vocabulary Risk Assessment Security A scientific and technologically based process consisting of three steps, ENISA Risk Assessment http://www.enisa.europa.eu/activiti risk identification, risk analysis and risk evaluation . (ENISA) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary Risk assessment Security Overall process of risk analysis and risk evaluation [ISO/IEC Guide ISO/IEC 27000 2.37 73:2002] Risk avoidance Security Informed decision not to be involved in, or to withdraw from, an activity ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d in order not to be exposed to a particular risk. management -- etail?csnumber=44651 Vocabulary Risk Avoidance Security Decision not to become involved in, or action to withdraw from, a risk ENISA Risk Assessment http://www.enisa.europa.eu/activiti situation. (ISO/IEC Guide 73) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Page 17
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Risk ASPR A process to exchange or share information about risk between the ENISA Risk Assessment http://www.enisa.europa.eu/activiti Communication decision-maker and other stakeholders. The information can relate to Glossary es/risk-management/currentthe existence, nature, form, probability, severity, acceptability, risk/risk-managementtreatment or other aspects of risk. (ISO/IEC Guide 73) inventory/glossary
Risk ASPR Exchange or sharing of information about risk between the decision- ISO/IEC 27000 2.38 communication maker and other stakeholders. [ISO/IEC Guide 73:2002]
Risk Control Security Actions implementing risk management decisions. Risk control may ENISA Risk Assessment involve monitoring, re-evaluation, and compliance with decisions. Glossary (ISO/IEC Guide 73)
Risk Criteria Security Terms of reference by which the significance or risk is assessed. Risk ENISA Risk Assessment http://www.enisa.europa.eu/activiti criteria can include associated cost and benefits, legal and statutory Glossary es/risk-management/currentrequirements, socio-economic aspects, the concerns of stakeholders , risk/risk-managementpriorities and other inputs to the assessment. (ISO/IEC Guide 73) inventory/glossary
Risk criteria Security Terms of reference by which the significance of risk is assessed [ISO/IEC ISO/IEC 27000 2.39 Guide 73:2002]
Risk Estimation Security Process of comparing the estimated risk against given risk criteria to ENISA Risk Assessment http://www.enisa.europa.eu/activiti determine the significance of risk. (ISO/IEC Guide 73) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Risk estimation Security Activity to assign values to the probability and consequences of a ISO/IEC 27000 2.40 risk.[ISO/IEC Guide 73:2002]
Risk Evaluation Security Process of comparing the estimated risk against given risk criteria to ENISA Risk Assessment http://www.enisa.europa.eu/activiti determine the significance of risk. (ISO/IEC Guide 73) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Page 18
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Risk evaluation Security Process of comparing the estimated risk against given risk criteria o ISO/IEC 27000 2.41 determine the significance of the risk. [ISO/IEC Guide 73:2002] Risk Financing ASPR, Security Provision of funds to meet the cost of implementing risk treatment and ENISA Risk Assessment http://www.enisa.europa.eu/activiti related costs. (ISO/IEC Guide 73) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Risk Security Process to find, list and characterize elements of risk ]. (ISO/IEC Guide ENISA Risk Assessment http://www.enisa.europa.eu/activiti Identification 73) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary Risk ASPR, Security The process , distinct from risk assessment , of weighing policy ENISA Risk Assessment http://www.enisa.europa.eu/activiti Management alternatives in consultation with interested parties , considering risk Glossary es/risk-management/currentassessment and other legitimate factors, and selecting appropriate risk/risk-managementprevention and control options. (ENISA) inventory/glossary Risk Security Coordinated activities to direct and control an organization with regard ISO/IEC 27000 2.42 management to risk [ISO/IEC Guide 73:2002] NOTE Risk management generally includes risk assessment , risk treatment ), risk acceptance , risk communication (2.38), risk monitoring and risk review.
Risk Security A process to modify risk ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d modification management -- etail?csnumber=44651 Vocabulary
Risk Security Process [G.24], related to a risk [G.27] to minimize the negative and to ENISA Risk Assessment http://www.enisa.europa.eu/activiti Optimization maximize the positive consequences [G.4] and their respective Glossary es/risk-management/currentprobabilities [G.22]. Risk optimization depends upon risk criteria [G.34], risk/risk-managementincluding costs and legal requirements. (ISO/IEC Guide 73) inventory/glossary
Page 19
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Risk Perception Security Way in which a stakeholder [G.50] views a risk [G.27], based on a set of ENISA Risk Assessment http://www.enisa.europa.eu/activiti values or concerns. Risk perception depends on the stakeholder’s needs, Glossary es/risk-management/currentissues and knowledge. Risk perception can differ from objective data. risk/risk-management- (ISO/IEC Guide 73) inventory/glossary Risk reduction Security A process to modify risk. ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d management -- etail?csnumber=44651 Vocabulary Risk Reduction Security Actions taken to lessen the probability , negative consequences or both, ENISA Risk Assessment http://www.enisa.europa.eu/activiti associated with a risk . (ISO/IEC Guide 73) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Risk Retention Security Acceptance of the burden of loss, or benefit of gain, from a particular risk ENISA Risk Assessment http://www.enisa.europa.eu/activiti Risk retention includes the acceptance of risks that have not been Glossary es/risk-management/currentidentified. Risk retention does not include treatments involving risk/risk-managementinsurance, or transfer by other means. (ISO/IEC Guide 73) inventory/glossary
Risk sharing Security Form of risk treatment involving the agreed distribution of risk with ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d other parties. management -- etail?csnumber=44651 Vocabulary
Risk Security Informed decision not to be involved in, or to withdraw from, an activity ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d termination in order not to be exposed to a particular risk. management -- etail?csnumber=44651 Vocabulary
Risk tolerance Security Informed decision to take a particul risk. ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d management -- etail?csnumber=44651 Vocabulary
Risk transfer ASPR Form of risk treatment involving the agreed distribution of risk with ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d other parties. management – etail?csnumber=44651
Page 20
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Vocabulary
Risk Transfer ASPR Sharing with another party the burden of loss or benefit of gain, for a ENISA Risk Assessment http://www.enisa.europa.eu/activiti risk. Legal or statutory requirements can limit, prohibit or mandate the Glossary es/risk-management/currenttransfer of certain risk. Risk transfer can be carried out through risk/risk-managementinsurance or other agreements. Risk transfer can create new risks or inventory/glossary modify existing risk. (ISO/IEC Guide 73)
Risk Treatment ASPR, Security Process of selection and implementation of measures to modify risk.Risk ENISA Risk Assessment http://www.enisa.europa.eu/activiti treatment measures can include avoiding, optimizing, transferring or Glossary es/risk-management/currentretaining risk (ISO/IEC Guide 73) risk/risk-managementinventory/glossary
Risk treatment ASPR, Security Process of selection and implementation of measures to modify ISO/IEC 27000 2.43 risk.[ISO/IEC Guide 73:2002] Safeguards Security Practices, procedures or mechanisms that reduce risk. The term ENISA Risk Assessment http://www.enisa.europa.eu/activiti 'safeguard' is normally considered to be synonymous with the term Glossary es/risk-management/current- 'control'. (ISO/IEC PDTR 13335-1) risk/risk-managementinventory/glossary
Security Security All aspects related to defining, achieving, and maintaining data ENISA Risk Assessment http://www.enisa.europa.eu/activiti confidentiality, integrity, availability, accountability, authenticity, and Glossary es/risk-management/currentreliability. A product, system, or service is considered to be secure to the risk/risk-managementextent that its users can rely that it functions (or will function) in the inventory/glossary intended way. (ISO/IEC WD 15443-1)
Separacy Network A more reliable means of ensuring that specified circuits are not ETSI TR 102 445 V1.1.1 http://www.etsi.org/deliver/etsi_tr/ rerouted over the same cables, equipment or transmission systems and (2006-10)3 Emergency 102400_102499/102445/01.01.01_6 also there are no common physical sites within the circuits rerouting. Communications 0/tr_102445v010101p.pdf (EMTEL); Overview of Emergency Communications
Page 21
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Network Resilience and Preparedness
Service Software A component of a portfolio of choices offered by service providers to a 3GPP TR 21.905 V8.5.0 http://www.quintillion.co.jp/3GPP/S user, functionality offered to a user. (2008-06) 3rd pecs/21905-850.pdf Generation Partnership Project;Technical Specification Group Services and System Aspects; Vocabulary for 3GPP Specifications
Signalling Network The exchange of information specifically concerned with the 3GPP TR 21.905 V8.5.0 http://www.quintillion.co.jp/3GPP/S establishment and control of connections, and with management, in the (2008-06) 3rd pecs/21905-850.pdf telecommunications network. Generation Partnership Project;Technical Specification Group Services and System Aspects; Vocabulary for 3GPP Specifications
Source Security Item or activity having a potential for a consequence. (ISO/IEC Guide 73) ENISA Risk Assessment http://www.enisa.europa.eu/activiti Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Source Security Process to find, list and characterize sources. (ISO/IEC Guide 73) ENISA Risk Assessment http://www.enisa.europa.eu/activiti Identification specified way to carry out an activity or a process.[ISO 9000:2005] Glossary es/risk-management/currentrisk/risk-managementinventory/glossary
Page 22
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Stakeholder ASPR Any individual, group or organization that can affect, be affected by, or ENISA Risk Assessment http://www.enisa.europa.eu/activiti perceive itself to be affected by, a risk. (ISO/IEC Guide 73) Glossary es/risk-management/currentrisk/risk-managementinventory/glossary Statement of Security Documented statement describing the control objectives and controls ISO/IEC 27000 2.34 applicability that are relevant and applicable to the organization's ISMS (2.23)
Telecommunica ASPR the provision of telecommunication resources or other resources or The Tampere tion assistance support intended to facilitate the use of telecommunication resources. Convention
Telecommunica Network, personnel, equipment, materials, information, training, radio- The Tampere tion resources Hardware frequency spectrum, network or transmission capacity or other Convention resources necessary to telecommunications.
Telecommunica Network, any transmission, emission, or reception of signs, signals, writing, Tampere Convention tions Hardware images, sounds or intelligence of any nature, by wire, radio, optical fibre or other electromagnetic system.
Threat Security Any circumstance or event with the potential to adversely impact an ENISA Risk Assessment http://www.enisa.europa.eu/activiti asset through unauthorized access, destruction, disclosure, modification Glossary es/risk-management/currentof data, and/or denial of service. (ENISA) risk/risk-managementinventory/glossary
Threat Security Potential cause of an unwanted incident, which may result in harm to a ISO/IEC 27000 2.45 system or organization.
Threat or Security A source of potential harm, an element, which alone or in combination ISO Guide 73:2009 Risk http://www.iso.org/iso/catalogue_d hazard has the intrinsic potential to give rise to risk. management -- etail?csnumber=44651 Vocabulary
Traffic Network The actual voice or data communication sent and received between two EP3R TF-TDCA nodes.
Page 23
EP3R 2013 – Position Paper
Term Categorization Definition Source Link
Traffic shaping Network When traffic through packed based networks becomes slow, and latency EP3R TF-TDCA increases, traffic shaping is the action of controlling the volume of packets sent into the network (sometimes referred as bandhwidth throttling)or the rate at which they are sent (rate limiting). Vulnerability Security The intrinsic properties of something resulting in susceptibility to a risk EP3R TF-TDCA source that can lead to an event with a consequence. Vulnerability Security ISO 22300 Societal security — Terminology Vulnerability Security The existence of a weakness, design, or implementation error that can ENISA Risk Assessment http://www.enisa.europa.eu/activiti lead to an unexpected, undesirable event compromising the security of Glossary es/risk-management/currentthe computer system, network, application, or protocol involved. (ITSEC) risk/risk-managementinventory/glossary Vulnerability Security Weakness of an asset or control that can be exploited by a threat. ISO/IEC 27000 2.46
Page 24
EP3R 2013 – Position Paper
ENISA
European Union Agency for Network and Information Security Science and Technology Park of Crete (ITE) Vassilika Vouton, 700 13, Heraklion, Greece
Athens Office
1 Vass. Sofias & Meg. Alexandrou Marousi 151 24, Athens, Greece
PO Box 1309, 710 01 Heraklion, Greece Tel: +30 28 14 40 9710 info@enisa.europa.eu Page 1 www.enisa.europa.eu
Fotnoter
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA) December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA) December 2013
- Notice must be taken that this publication represents the views and interpretations of the authors and editors, unless stated otherwise. This publication should not be construed to be a legal action of ENISA or the ENISA bodies unless adopted pursuant to the Regulation (EU) No 526/2013. This publication does not necessarily represent state-of the-art and ENISA may update it from time to time. Third-party sources are quoted as appropriate. ENISA is not responsible for the content of the external sources including external websites referenced in this publication. This publication is intended for information purposes only. It must be accessible free of charge. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication.
- © European Union Agency for Network and Information Security (ENISA), 2013 Reproduction is authorised provided the source is acknowledged.
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA) December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA) December 2013
- 2.1 Key Terminology 3
- 2.2 Terminology Sources 3
- 2.3 Categorising Terminology 4
- 2.4 Adopted Terms 5
- 3.1 Introduction 9
- 3.2 Initial Ontology 9
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA) December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA) December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- ENISA While discussing the allocation, it was possible • Risk Management - Glossary to pinpoint the following list of references • Inter‐X: Resilience of the Internet Interconnection Ecosystem from authoritative resources for each cluster. The present list does not cover all the possible references but can allow the creation of a common baseline in defining typical components which constitute a Critical Information Infrastructure.
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- 2 JRC-IPSC, ’’Risk assessment methodologies for Critical Infrastructure Protection. Part I: A state of the art’’ http://ec.europa.eu/home-affairs/doc_centre/terrorism/docs/RA-ver2.pdf Ministry of Transport and Communications , ‘’Communications Market Act’’ , Finland http://www.finlex.fi/en/laki/kaannokset/2003/en20030393.pdf Ofcom, The UK Communications Infrastructure Report, United Kingdom http://stakeholders.ofcom.org.uk/market-data-research/other/telecoms-research/broadbandspeeds/infrastructure-report-2012/ 5 Official Journal of the European Union, DIRECTIVE 2009/140/EC OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL, Art 13a http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2009:337:0037:0069:EN:PDF
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- ASPR Standards (Agreements, Standards, Policies, Policies Regulations)
- Software Regulations
- Monitoring Network Management
- Location National Critical European Critical Information Environment Infrastructures Infrastructures Hosting
- Power Suppliers Coaxial Servers Optical Fibre Hardware Cables 3G, 4G, TDM, WIFI, Wireless WLAN, WIMAX ... ATM, BWA, DOCSIS, CDMA, GSM, IN, IP, IMS, Wire line MPLS, SIP, C7, SS7, Payload Data SONET, SDH,
- Human Security
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA) December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA) December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013
- Task Forces on Terminology Definitions and Categorisation of Assets (TF-TDCA)
- December 2013