Terms & Glossary
Note on Terminology:
“Werte” ≙ “Assets”
“Informationsverbund” ≙ “Scope” (BSI terminology).
Core values/security objectives: Confidentiality, Integrity, Availability.
User (End User):
A person who uses IT services in daily work (not the same as a customer).
Example: EU Paying Agency BW = processing offices using specialized procedures.
Application (App/Software):
IT support for processes; combines IT resources for a specific purpose.
Work Instruction:
Detailed description for the repeatable, quality-compliant execution of activities.
Assets:
Valuable target objects of an institution (e.g., information, systems, rooms).
Authentication:
Proof of identity (e.g., password, smart card, biometric feature).
Authenticity:
The property of truly matching the authenticated identity.
Authorization:
Validation/approval of access rights to resources.
Availability Management (ITIL):
Ensuring agreed service availability, including planning, measurement, and improvement.
Basic Security Check (BSC):
Interview-based target/actual comparison of IT baseline protection implementation (older BSI 100-x standards).
Module (IT Baseline Protection):
Modular content with short description, threat scenario, recommended measures.
Threat:
Condition/event that may cause harm to C, I, A via vulnerabilities.
User Account (Username/Login):
Identification feature of a user towards an IT system.
Best Practices:
Proven practices.
Biometrics:
IT-supported identification based on physical/behavioral features (e.g., fingerprint, iris).
Bugfix / Hotfix / Patch / Update / Upgrade:
Error correction or functional enhancement.
- Hotfix = urgent patch
- Update = usually minor
- Upgrade = major
Federal Office for Information Security (BSI):
German authority for IT security; publisher of IT Baseline Protection; certification body.
Federal Data Protection Act (BDSG):
German federal law on personal data protection (supplements GDPR, state laws).
Business Impact Analysis (BIA):
Assessment of potential impacts of failures on business processes.
Capacity Management (ITIL):
Ensuring sufficient capacity/performance (business, service, component levels).
Change Management (ITIL):
Managing changes to IT operations with minimized risk.
Configuration Item (CI):
An asset or IT component.
Configuration Management (ITIL):
Managing/verifying information about CIs.
CMDB (Configuration Management Database):
Database mapping and linking CIs including lifecycle data.
Data Protection:
Protection of personal data (fundamental right; GDPR/BDSG).
Data Security:
Technical goal to protect data of any type from loss/manipulation.
Backup:
Full/incremental/differential; ensures C, I, consistency.
Demilitarized Zone (DMZ):
Network zone between different security levels.
Digital Signature:
Verifies authorship and integrity of data.
Effectiveness:
Achieving objectives (regardless of effort).
Efficiency:
Economy (effort-benefit ratio).
Supplementary Security Analysis:
Identifies where risk analyses beyond IT Baseline Protection are needed (higher protection needs, special cases, atypical scenarios).
EU Paying Agency Baden-Württemberg:
Administrative units for EGFL/ELER funds (approval, control, payment, accounting).
Specialized Application:
Software for specific requirements/industries.
Specialized Task:
Government tasks for planning/operating the EU Paying Agency.
Operational Responsibility (Specialized):
Data administration, user support, responsibility for specialized applications.
Specialized Procedure:
IT support for administrative services; consists of one or more applications.
Financial Management (ITSM):
Budgeting, cost allocation, and service charging.
Firewall (Security Gateway):
Secure network interconnection, filtering allowed connections.
Hazard:
Umbrella term; threat = specific hazard (e.g., defective storage medium).
Threat:
A hazard exploiting a vulnerability and causing harm.
Core Value/Security Objective:
Confidentiality, Integrity, Availability.
GSTOOL:
Former BSI software for security concepts (discontinued, support until 2016).
(—)
Incident Management (ITIL):
Minimizing disruptions, restoring service; prioritization by impact/urgency.
Information Security:
Protecting analog/digital information; absence of unacceptable risks.
CISO / ISB:
Chief Information Security Officer / Information Security Officer; develops/facilitates policies; manages ISMS.
Information Security Event:
An event that may impair security.
Information Security Incident:
(Series of) events with risks for business operations/information security.
ISMS (Information Security Management System):
Rules, processes, measures to manage information security (continuous, PDCA).
IT (Information Technology):
Means for processing/transmitting information.
Scope (Information Network):
All objects (infrastructure, organizational, personnel, technical) in an application area.
Infrastructure (Baseline Protection):
Buildings, rooms, power, climate, cabling (without IT systems).
Institutions:
Companies, authorities, other organizations.
Integrity:
Absence of unauthorized modifications to systems/data.
Internal Audits:
Regular ISMS effectiveness/conformity checks; basis for improvements.
Internal Control System (ICS):
Principles/measures to ensure effectiveness, compliance, and legality.
ISO 27000 Family (ISO27k):
International information security standards.
- ISO 27001: ISMS requirements (certifiable).
- ISO 27002: Implementation guide for controls (non-certifiable).
Partial IS Revision:
Review of specific processes using baseline modules.
ITIL (IT Infrastructure Library):
Best practices for IT service management (ITSM).
IT Security:
Protection of electronically processed information (subset of InfoSec).
Critical Infrastructure (KRITIS):
Facilities vital for supply/safety.
Accumulation Effect:
Higher protection needs from cumulative damages/dependencies.
Customer:
Buyer/contract partner of an IT service provider; SLA addressee.
Information Security Policy:
Strategic document defining goals, means, structures, and desired security level.
Maximum Principle:
Highest potential damage determines protection needs.
Modeling (Baseline Protection):
Assigning modules to structure elements; basis for target/actual comparison.
Traceability:
Complete recording of actions (who/what/when).
Evidence Documents:
Process results (e.g., plans, logs, audits, reviews).
Network Diagram:
Clean overview of elements and connections.
Non-repudiation:
Data origin/receipt cannot be denied.
Penetration Test:
Non-destructive test of security measures.
Prioritization:
Resource control by impact/urgency (incident mgmt).
Problem Management (ITIL):
Eliminating/preventing incident root causes.
Proxy:
Intermediary node for data forwarding/filtering.
Process:
Structured activities transforming inputs into outputs.
Release Management (ITIL):
Planned, disruption-minimized rollouts of approved components.
Residual Risk:
Remaining risk after treatment.
Audit/Revision:
Independent review of suitability/compliance.
Risk:
Combination of threat + vulnerability; evaluated by probability × impact.
Risk Acceptance:
Deliberate decision to accept risk (temporary/permanent).
Risk Analysis/Assessment/Evaluation/Management:
Identification, analysis, evaluation, treatment, monitoring of risks.
Malware (Virus, Worm, Trojan, Rootkit, Spyware):
Software with harmful functions.
Protection Needs/Definition/Assessment:
Classification as normal/high/very high per object; inheritance rules.
Security Objectives:
Confidentiality, Integrity, Availability.
Vulnerability:
Weakness enabling exploitation by threats.
Server:
System providing services to clients.
SLA (Service Level Agreement):
Agreement on service objectives/responsibilities.
Service Level Management (ITIL):
Negotiating/monitoring SLAs; reviews/improvements.
Security Gateway (Firewall):
Network interconnection per policy.
Security Concept:
Plans/documents to achieve security objectives.
Security Measure:
Organizational, personnel, technical, or infrastructural action.
Security Policy:
Official document with security objectives and general measures.
Single Point of Failure (SPOF):
Component whose failure disrupts the entire system.
Structural Analysis:
Recording objects/relationships in the scope.
Structure Elements:
Applications, IT systems, networks, rooms, buildings, connections.
Support (Helpdesk/IT Support):
1st/2nd/3rd level support.
Technical Operation:
Facilities, infrastructure, hardware, system software, databases.
Underpinning Contracts (UC):
Contracts with external providers supporting services.
Availability:
Provision of information/services as required.
Encryption:
Transforming plaintext into ciphertext via keys.
Distribution Effect:
Reduced inherited protection needs by spreading across systems.
Confidentiality:
Protection against unauthorized access.
VLAN (Virtual LANs):
Logical network segmentation.
VPN (Virtual Private Network):
Logically separated, authenticated, encrypted network.
Directive Documents:
Binding rules with mandatory implementation.
Assets:
Anything valuable to an institution (assets, knowledge, health, objects).
Asset Owner:
Responsible for assessing, protecting, and securing an asset.
Asset Register:
Inventory of relevant asset information supporting security concepts.
WLAN (Wi-Fi):
Wireless networks (IEEE 802.11).
Certification Scope:
Subset of the ISMS scope under certification.
Target Object:
Element within the scope assigned modules.
Access/Entry/Use:
System use / data knowledge / physical entry.
Terms in the fuentis Suite (DE/EN, compact)
Section titled “Terms in the fuentis Suite (DE/EN, compact)”| Term (DE) | Term (EN) | Definition |
|---|---|---|
| Anforderung | Requirement | Describes what must be done; fulfilled by matching security measures. |
| Assets | Assets | Valuable objects for achieving goals/value (Baseline Protection context). |
| Audit | Audit | Review for compliance, identifying gaps, basis for improvement (internal/external). |
| Basis-Absicherung | Basic protection | Broad initial protection across all processes/procedures. |
| Bausteine | Block | Modular content (threats, requirements, notes) in Baseline Protection. |
| Fragebogen | Questionnaire | Standardized protection needs assessment. |
| Gefährdungen | Threats | Threats acting through vulnerabilities. |
| Geltungsbereich | Scope | All relevant components of an application domain. |
| Geschäfts-/Kernprozesse | Business/Core processes | Processes directly creating value. |
| Katalog | Catalog | Central publication of security standards (e.g., BSI compendium). |
| Kern-Absicherung | Core protection | Focus on particularly vulnerable processes/assets. |
| Kumulationseffekt | Accumulation effect | Raised protection needs due to cumulative damages/multiple processing. |
| Maßnahme | Security measure | Actions for risk control (organizational, personnel, technical, infrastructural). |
| Maximumprinzip | Maximum principle | Highest potential damage sets protection needs. |
| Modellierung | Modeling | Assigning modules to objects (with scope/requirements). |
| Risiken | Risks | Typically frequency × impact (a form of uncertainty). |
| Risikoanalyse | Risk analysis | German usage: overall process of risk assessment + treatment. |
| Schutzbedarfsanalyse | Protection needs analysis | Determining protection needs “normal/high/very high” incl. consequences. |
| Schwachstelle | Vulnerability | Weakness enabling a risk. |
| Sicherheitskonzept | Security concept | Planned approach to achieving objectives; key document. |
| Standard-Absicherung | Standard protection | Classical approach (BSI 100-2): broad and deep coverage. |
| Steuerungsprozesse | Management process | Set goals and track progress (requirements/evidence). |
| Strukturanalyse | Structural analysis | Capturing processes/apps/IT/networks/rooms/buildings/connections. |
| Unterstützungsprozess | Support process | Provides resources for business/management processes. |
| Vererbung | Propagation | Protection need inheritance (max principle, dependencies, accumulation, distribution). |
| Zielobjekt | Target object | Object within the scope assigned modules. |
| Top-Down-Prinzip | Top-Down principle | Strategies from leadership; implemented along hierarchy. |
| Verwaltung | Governance | Rules/practices for control, compliance, transparency. |
| CISO/ISB | CISO/ISB | Chief Information Security Officer / Information Security Officer. |
| Risk Owner | Risk Owner | Responsible for identifying, assessing, managing, and reporting a risk. |
| RACI-Matrix | RACI matrix | Role clarification: Responsible, Accountable, Consulted, Informed. |
| Governance-Gruppe | Governance group | Committee for strategy, policies, compliance, risk management. |
| Informationssicherheitsziele | Information Security Objectives | Concrete objectives protecting CIA. |
| ISO-Konformität | ISO compliance | Adherence to relevant ISO standards (esp. ISO 27001/27002). |