Backup
A protected copy of data or a system that can be used to restore information after deletion, corruption, failure, or an incident.
Use this reference while reviewing proposals, service descriptions, security plans, and contracts.
A protected copy of data or a system that can be used to restore information after deletion, corruption, failure, or an incident.
An agreement defining responsibilities in a relationship subject to HIPAA business associate requirements. Applicability depends on the actual service and data; consult the responsible adviser.
The plans and capabilities that keep critical business processes operating during a disruption, not merely the restoration of technology.
A model in which internal IT and an external provider divide clearly defined operational responsibilities.
Access policies that evaluate signals such as identity, device, and context before allowing access. The exact features depend on the platform and configuration.
Domain Name System: the records that direct domain names to services such as websites and email. Keep ownership and administrator access documented.
Endpoint detection and response: software and operations used to detect, investigate, and contain suspicious activity on devices.
The intake, communication, troubleshooting, and escalation function for employee technology questions and incidents.
A backup copy designed so it cannot be altered or deleted during a defined retention period.
The coordinated technical and business process for investigating, containing, communicating, and recovering from a security incident.
Granting only the permissions needed for an approved task or role, with review and removal when the need ends.
Mobile device management: administration of supported device settings, applications, and policies through a management service.
Managed detection and response: an operated security service that monitors, investigates, and responds to threats.
Multifactor authentication: verifying identity with more than one type of factor, such as something you know and something you possess.
Managed service provider: a company that operates defined technology services under an ongoing agreement.
Network operations center: a team or function that monitors and supports infrastructure and availability.
Permissions that can make significant administrative changes. Document who holds them, what they cover, and how use and removal are controlled.
Remote monitoring and management: tools used to observe and administer systems remotely. Tool access requires clear authorization and oversight.
Recovery point objective: the acceptable data-loss window measured in time for a system or process.
Recovery time objective: the target time for restoring a system or process after disruption.
A documented operational procedure describing prerequisites, steps, owners, and validation for a recurring task or recovery activity.
A broader support function that manages requests, incidents, communication, knowledge, and service processes.
Service-level agreement: documented service commitments such as coverage, priority, response, escalation, and reporting.
Security operations center: the people, process, and technology used to monitor, investigate, and respond to security events.
Single sign-on: using an identity service to access connected applications. Application scope and access removal still need verification.
An organization’s logical environment within a cloud service. Record its identifier, business owner, and administrator access.
The system record used to track a request, incident, communication, ownership, timing, and resolution.
Virtual chief information officer: an external role intended to connect technology planning, risk, budget, and business priorities.
A security approach that continuously verifies access based on identity, device, context, and least privilege rather than assuming internal traffic is trusted.
A newly discovered vulnerability for which defenders may have little warning or no broadly available patch.
Ask who owns the work, what triggers action, how performance is reported, and where the commitment appears in the agreement.
Explore the service library →Scope, service levels, security roles, pricing, access, and transition obligations should be explicit before signing.
Read the contract guide →