Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proposed update to Security Automation #82

Open
adammontville opened this issue Dec 10, 2017 · 6 comments
Open

Proposed update to Security Automation #82

adammontville opened this issue Dec 10, 2017 · 6 comments

Comments

@adammontville
Copy link
Contributor

The present definition is:

The process of which security alerts can be automated through the use of different components to monitor, analyze and assess endpoints and network traffic for the purposes of detecting misconfigurations, misbehaviors or threats.

I propose (changes emphasized):

The process by which security programs can be automated through the use of different components to monitor, analyze and assess endpoints and network traffic for the purposes of detecting misconfigurations, misbehaviors or threats.

@davidkazuhiro
Copy link

What does "security program" mean?

@adammontville
Copy link
Contributor Author

That's a fair question. In trying to find a standard definition for "security program", I realized that I should probably have said "information security program" which seems to have some fairly well-understood boundaries (see these Google search results).

If you, or someone else, has a better way to describe this, please let me know.

@davidkazuhiro
Copy link

Ah OK I think I was confused by the definition of program. I thought you meant

a series of coded software instructions to control the operation of a computer or other machine.

But apparently you meant

a set of related measures or activities with a particular long-term aim.

But yes, Information Security is more specific than security.

In any case, I think usage of such a term would require a new entry in the terminology section.

@adammontville
Copy link
Contributor Author

We could add another term. How about this definition for information security program:

A documented approach for organizing and directing all activities undertaken to ensure the confidentiality, integrity, and availability of the information held by the organization.

That's taken from ISO 704:2009.

@davidkazuhiro
Copy link

davidkazuhiro commented Dec 15, 2017

That would do it 😄

@henkbirkholz
Copy link
Member

👍 for adding the term "Information Security Program" defined in ISO 704:2009 in order to be used in the definition of Security Automation proposed by Adam.

adammontville added a commit that referenced this issue Jul 18, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants