<rss version="2.0">
<channel>
<title>Information Security Glossary</title>
<link>http://www.rsasecurity.com/glossary/</link>
<description>An authoritative resource from RSA Security where you can find clear definitions of Information Security terms.</description>
<copyright>Copyright 2005, RSA Security</copyright>
 <image>
  <title>Information Security Glossary, from RSA Security</title> 
  <url>http://www.rsasecurity.com/blog/images/small_blog_logo.gif</url> 
  <link>http://www.rsasecurity.com/glossary/</link> 
  <width>144</width> 
  <height>36</height> 
  </image>
<item>
<guid>http://www.rsa.com/glossary/default.asp?id=1119&amp;modified=7%2F3%2F2008</guid>
<pubDate>Thu, 3 Jul 2008 00:00:00 EDT</pubDate>
<title>ISO27002</title>
<link>http://www.rsa.com/glossary/default.asp?id=1119</link>
<description>New name for &lt;a href="/glossary/default.asp?id=1028"&gt;ISO17799&lt;/a&gt;.</description>
</item>
<item>
<guid>http://www.rsa.com/glossary/default.asp?id=1113&amp;modified=9%2F4%2F2007</guid>
<pubDate>Tue, 4 Sep 2007 00:00:00 EDT</pubDate>
<title>Knowledge Based Authentication (KBA)</title>
<link>http://www.rsa.com/glossary/default.asp?id=1113</link>
<description>A method to authenticate an individual based on knowledge of personal information, substantiated by a real-time interactive question and answer process.</description>
</item>
<item>
<guid>http://www.rsa.com/glossary/default.asp?id=1114&amp;modified=9%2F4%2F2007</guid>
<pubDate>Tue, 4 Sep 2007 00:00:00 EDT</pubDate>
<title>Intelligent Questioning</title>
<link>http://www.rsa.com/glossary/default.asp?id=1114</link>
<description>During a Knowledge Based Authentication session, the process of logically developing correct and incorrect answers using actual consumer data in order to diminish a person's ability to guess the correct responses. Intelligent Questioning compensates for minor input errors and name variations and accounts for errors in public data in order to identify meaningful facts for question development. The result is robust questions unique to the individual being authenticated </description>
</item>
<item>
<guid>http://www.rsa.com/glossary/default.asp?id=1115&amp;modified=9%2F4%2F2007</guid>
<pubDate>Tue, 4 Sep 2007 00:00:00 EDT</pubDate>
<title>sequential questions</title>
<link>http://www.rsa.com/glossary/default.asp?id=1115</link>
<description>During a Knowledge Based Authentication session, the ability to present and score one question at a time, which can reduce the number of questions presented to the customer, thereby improving the efficiency of the authentication process.</description>
</item>
<item>
<guid>http://www.rsa.com/glossary/default.asp?id=1116&amp;modified=9%2F4%2F2007</guid>
<pubDate>Tue, 4 Sep 2007 00:00:00 EDT</pubDate>
<title>call center</title>
<link>http://www.rsa.com/glossary/default.asp?id=1116</link>
<description>A venue where an agent will access the Knowledge Based Authentication system and the customer will be authenticated via telephone.</description>
</item>
<item>
<guid>http://www.rsa.com/glossary/default.asp?id=1117&amp;modified=9%2F4%2F2007</guid>
<pubDate>Tue, 4 Sep 2007 00:00:00 EDT</pubDate>
<title>call center assist</title>
<link>http://www.rsa.com/glossary/default.asp?id=1117</link>
<description>Real-time scripts which guide the call center agent through the authentication process, prompting the agent to correct missing or inaccurate customer information (address, SSN, name spellings) when appropriate.</description>
</item>
<item>
<guid>http://www.rsa.com/glossary/default.asp?id=1118&amp;modified=9%2F4%2F2007</guid>
<pubDate>Tue, 4 Sep 2007 00:00:00 EDT</pubDate>
<title>verification</title>
<link>http://www.rsa.com/glossary/default.asp?id=1118</link>
<description>During a Knowledge Based Authentication session, the process that ensures that the data provided for an individual exists and matches (name, address, social security number, date of birth, driver’s license).</description>
</item>
<item>
<guid>http://www.rsa.com/glossary/default.asp?id=1111&amp;modified=8%2F23%2F2007</guid>
<pubDate>Thu, 23 Aug 2007 00:00:00 EDT</pubDate>
<title>key management</title>
<link>http://www.rsa.com/glossary/default.asp?id=1111</link>
<description>A collection of procedures involved with the generation, exchange, storage, safeguarding, use, vetting, and replacement of encryption keys.  Key management is essential to the secure ongoing operation of any cryptosystem.
</description>
</item>
<item>
<guid>http://www.rsa.com/glossary/default.asp?id=1112&amp;modified=8%2F23%2F2007</guid>
<pubDate>Thu, 23 Aug 2007 00:00:00 EDT</pubDate>
<title>CVV</title>
<link>http://www.rsa.com/glossary/default.asp?id=1112</link>
<description>&lt;img src="http://www.rsa.com/blog/bimgs/070822/ccard.png" width="250" height="165" align="left" vspace="3" hspace="3"&gt;The CVV (Card Verification Value) is a part of the of the magnetic track data in the credit card itself. CVV2/CVC2/CID information is the 3 or 4 digit code on the back of the signature strip of a credit or debit card (or on the front of American Express cards).</description>
</item>
<item>
<guid>http://www.rsa.com/glossary/default.asp?id=1100&amp;modified=2%2F15%2F2007</guid>
<pubDate>Thu, 15 Feb 2007 00:00:00 EDT</pubDate>
<title>Alerting, alerts</title>
<link>http://www.rsa.com/glossary/default.asp?id=1100</link>
<description>A robust network-security monitoring application should include an alerting service.  When an event that requires attention occurs, this service will send a notice by e-mail, page, instant messaging or other urgent method to a security expert.  

The administrator may configure this service for pre-determined events or baselining may be used.  When baselining is used, a threshold value is configured.  When the value exceeds the threshold for a particular kind of event, an alert is issued.

For example, a number of failed attempts to log into an administrative account on a server may indicate that an attacker is trying to gain control of the server.  The network team decides that up to ten tries is reasonable for someone who has just temporarily forgotten the password, so they set a threshold of ten failed attempts for this kind of event.  At the eleventh attempt, an alert is sent so that an expert can investigate for other symptoms that would indicate an attack.</description>
</item>

</channel>
</rss>