The principle of restricting access to only the data required to fulfil an authorised role or function.
The principle of restricting access to only the data required to fulfil an authorised role or function.
Two or more network devices linked together (see Network infrastructure).
Security policies used to control access to a network and actions on a network. This can include authentication checks and authorisation controls.
IT equipment designed to facilitate the communication of data. For example, routers, switches and wireless access points.
The infrastructure used to carry data between workstations and servers or other network devices.
Network traffic generated over a network to manage or control workstations, servers and network devices. This includes standard management protocols and other network traffic that contains data relating to the management of the network.
Partitioning a network into smaller networks; compare with network segregation.
Developing and enforcing a rule set for controlling the communications between specific hosts and services; compare with network segmentation.
The linking of computers to allow them to operate interactively.
Network-based Intrusion Detection System
Network-based Intrusion Prevention System
National Institute of Standards and Technology
A contract by which one or more parties agree not to disclose confidential information that they have shared with each other as a necessary part of doing business together.
A non-human actor, such as a service, application, workload or AI agent, that is authorised to access a system and its resources.
Authentication that does not involve direct interaction by a human user.
Providing proof that an action was performed by a particular user such that the origin of the action cannot subsequently be repudiated.
A specific type of electrically erasable programmable read-only memory.
A type of media which retains its data when power is removed.