Keystroke logger
Software or hardware designed to capture a user’s keystrokes on a compromised system. The keystrokes are stored or transmitted so that they may be used to collect valued information.
Least privilege
The principle of giving an individual only the set of privileges that are essential to performing authorized tasks. This principle limits the damage that can result from the accidental, incorrect, or unauthorized use of an information system.
Malware
Malicious software designed to infiltrate or damage a computer system, without the owner’s consent. Common forms of malware include computer viruses, worms, Trojans, spyware, and adware.
Management security control
A security control that focuses on the management of IT security and IT security risks.
Multi-factor authentication
A tactic that can add an additional layer of security to your devices and account. Multi-factor authentication requires additional verification (like a PIN or fingerprint) to access your devices or accounts. Two-factor authentication is a type of multi-factor authentication.
Overwrite
To write or copy new data over existing data. The data that was overwritten cannot be retrieved.
Perimeter
The boundary between two network security zones through which traffic is routed.
Phishing
An attempt by a third party to solicit confidential information from an individual, group, or organization by mimicking or spoofing a specific, usually well-known brand, usually for financial gain. Phishers attempt to trick users into disclosing personal data, such as credit card numbers, online banking credentials, and other sensitive information, which they may then use to commit fraudulent acts.
Plaintext
Unencrypted information.
Privacy Officer
The privacy administrator is responsible for safeguarding patient confidentiality at a clinic or hospital. Under regulations of applicable privacy laws and/or college guidelines, the privacy officer oversees institutional privacy policies, procedures, and rules.
