Computer Security Concepts (Inglés) (Artículo) Autor Zainab Abdullah Jasim
Computer Security Concepts (Inglés) (Artículo) Autor Zainab Abdullah Jasim
=====================================================
COMPUTER SECURITY CONCEPTS
A Definition of Computer Security
The NIST Computer Security Handbook [NIST95] defines the term computer
security as follows:
This definition introduces three key objectives that are at the heart of computer
security:
• Confidentiality سرية: This term covers two related concepts:
— Data confidentiality: Assures that private or confidential information
is not made available or disclosed to unauthorized individuals.
— Privacy خصوصية: Assures that individuals control or influence what
information related to them may be collected and stored and by whom and to
whom that information may be disclosed.
• Integrity سالمة: This term covers two related concepts:
— Data integrity: Assures that information and programs are changed only
in a specified and authorized manner.
— System integrity : Assures that a system performs its intended function
in an unaffected manner , free from deliberate االعتماديةor unauthorized
manipulation معالجةof the system.
• Availability توفر: Assures that systems work immediately and service is
not denied to authorized users.
These three concepts form what is often referred to as the CIA triad
( Figure 1.1 ). The three concepts embody the fundamental security objectives
for both data and for information and computing services. For example, the
NIST
A flaw or weakness in a system’s design, implementation, or operation and management that could be
exploited to violate انتهاكthe system’s security policy.