Concept | Documentation |
System Of Interest | An abstract element representing a SOI. Base class for specific kinds of SOIs. |
General Context | Specifies a General Context. |
General Context Element | Specifies a General Context Element. |
General Context Element Role | Specifies the fact that a General Context Element exists in a given General Context. |
| specifies the fact, that a system of interest exists in a security context. |
Security Context Element Role | |
Security Context | The Security Context describes all internal and external elements, boundaries, interconnections and assumptions that referes to the security of a system or an asset. DIN ISO 31000:2018-10 defines: "The context of the risk management process should be derived from an understanding of the external and internal environment in which the organisation operates and should reflect the specific environment of the activity to which the risk management process is applied." |
Asset | Asset Definition in ISO 27005, Chapter „Identifying and describing information security risks“ [§7.2.1] (Page 17): „An asset is anything that has value to the organization and therefore requires protection.“ Asset Definition NIST SP 800-160v1r1 „The Concept of Assets“ [§3.4] Page 16: „An asset is an item of value. There are many different types of assets. Assets are broadly categorized as either tangible or intangible. Tangible assets include physical items, such as hardware, computing platforms, other technology components, and humans. Intangible assets include humans, firmware, software, capabilities, functions, services, trademarks, intellectual property, data, copyrights, patents, image, or reputation.“ |
Adversary | Adversary definition from NIST Special Publication 800-30, Glossary [APPENDIX B]: “Individual, group, organization, or government that conducts or has the intent to conduct detrimental activities.” |
Assumption | |
Security Context Element | An abstract element representing a Security Context Element. Base class for specific kinds of Security Context Elements. |