Glossary

Terms you may encounter in some of our cybersecurity training programs.

Quantum computing

A quantum computer can process a vast number of calculations simultaneously. Whereas a classical computer works with ones and zeros, a quantum computer will have the advantage of using ones, zeros and “superpositions” of ones and zeros. Certain difficult tasks that have long been thought impossible for classical computers will be achieved quickly and efficiently by a quantum computer.

Ransomware

A type of malware that denies a user’s access to a system or data until a sum of money is paid.

Redaction

A form of data sanitization (making unreadable) for selected data-file elements (not to be confused with media sanitization, which addresses all data on media).

Remote exploitation

Exploitation of a victim computer by sending specially crafted commands from a remote network to a service running on that computer to manipulate it for the purpose of gaining access or information.

Risk level

The degree of risk (e.g. high, medium, low).

Sanitize

Sanitization is a process through which data is irreversibly removed from media. The storage media is left in a re-usable condition in accordance with IT security policy, but the data that was previously on it cannot be recovered or accessed.

Secure destruction

The destruction of information assets through one or more approved methods, carried out alone or in combination with erasing, to ensure that information cannot be retrieved.

Secure erasure

A digital sanitization process that uses tools and industry-standard commands (e.g. ATA security erase) to erase all accessible memory locations of a data storage device.

Security control

A management, operational, or technical high-level security requirement needed for an information system to protect the confidentiality, integrity, and availability of its IT assets. Security controls can be applied by using a variety of security solutions that can include security products, security policies, security practices, and security procedures.

Security Officer (Information Security Officer)

The information security officer (data protection officer) is responsible for safeguarding patient data and systems at a clinic or hospital. Under regulations of applicable privacy laws and/or college guidelines, the privacy officer oversees institutional privacy policies, procedures, and rules.