{
  "id": "http://connectivity-hub.com/terms/450e4dd3-6189-4b7d-97a7-a1672a60d061",
  "type": "Concept",
  "prefLabel": {
    "en": "Misconfiguration of Software and Hardware"
  },
  "definition": {
    "en": "Misconfiguration of software and hardware is the incorrect or suboptimal configuration of an information system or system component that may lead to vulnerabilities (NIST, no date). <br /> <p>NIST, no date. <a href=\"https://csrc.nist.gov/glossary/term/misconfiguration\">Misconfiguration. Glossary: Computer Security Resource Center. National Institute of Standards and Technology (NIST) Information Technology Laboratory</a>. Accessed 9 November 2020.</p>"
  },
  "editorialNote": {
    "en": [
      "source:UNDRR HIPS"
    ]
  },
  "scopeNote": {
    "en": [
      "Security configuration includes security rules configured in the cloud platform, network, virtual machines and various application components. It is different to a high-level security policy, which sets out the organisation’s approach to achieve its information security objectives (ITU, 2016). Misconfiguration implies an incorrect or suboptimal system component that may lead to vulnerabilities in the cloud platform, network, virtual machines and various application components (NIST, no date). Cloud service providers (CSPs) should execute the integrated security configuration management to provide efficient implementation and fast deployment of the security configuration (ITU, 2016). In security configuration management, it is suggested that CSPs set security policy configuration templates and security configuration policy baselines. Furthermore, CSPs should take measures to ensure the consistency and efficiency of security configuration when the cloud environment changes and to isolate the security configuration between Cloud service customers (CSCs) in a multi-tenancy environment (ITU, 2016). Security configuration templates include the main templates of security configuration that the current cloud computing environment needs, such as account management, authentication, access control policies, audit policies, dynamic response policies, application and software update policies, and backup and recovery policies (ITU, 2016). Security configuration baselines provide a criterion for the security configuration requirements of the entire cloud computing environment, which can help CSPs evaluate whether the current security configuration meets the fundamental security level or not, and further provide detailed guidance to reinforcement. The categories of security configuration baselines should include but are not limited to the following: operating system (OS) security configuration baselines, database security configuration baselines, firewall security configuration baselines, switch security configuration baselines, and router security configuration baselines, etc. Security configuration management involves the following measures (ITU, 2016):"
    ]
  },
  "broader": {
    "id": "http://connectivity-hub.com/terms/09b9e15e-4ed2-4cbf-975a-96086dfb65a5",
    "prefLabel": {
      "en": "Cyber Hazard"
    }
  },
  "inScheme": [
    {
      "id": "http://connectivity-hub.com/terms/",
      "title": {
        "en": "Climate Connectivity Taxonomy"
      }
    }
  ],
  "inSchemeAll": [
    {
      "id": "http://connectivity-hub.com/terms/"
    }
  ],
  "@context": {
    "@version": 1.1,
    "id": "@id",
    "type": "@type",
    "@vocab": "http://www.w3.org/2004/02/skos/core#",
    "xsd": "http://www.w3.org/2001/XMLSchema#",
    "dct": "http://purl.org/dc/terms/",
    "dc": "http://purl.org/dc/elements/1.1/",
    "schema": "https://schema.org/",
    "vann": "http://purl.org/vocab/vann/",
    "ldp": "http://www.w3.org/ns/ldp#",
    "owl": "http://www.w3.org/2002/07/owl#",
    "title": {
      "@id": "dct:title",
      "@container": "@language"
    },
    "dc:title": {
      "@id": "dc:title",
      "@container": "@language"
    },
    "dc:description": {
      "@id": "dc:description",
      "@container": "@language"
    },
    "description": {
      "@id": "dct:description",
      "@container": "@language"
    },
    "license": {
      "@id": "dct:license",
      "@container": "@language"
    },
    "issued": {
      "@id": "dct:issued",
      "@type": "xsd:date"
    },
    "created": {
      "@id": "dct:created",
      "@type": "xsd:date"
    },
    "modified": {
      "@id": "dct:modified",
      "@type": "xsd:date"
    },
    "creator": "dct:creator",
    "publisher": "dct:publisher",
    "preferredNamespacePrefix": "vann:preferredNamespacePrefix",
    "preferredNamespaceUri": "vann:preferredNamespaceUri",
    "isBasedOn": "schema:isBasedOn",
    "source": "dct:source",
    "prefLabel": {
      "@container": "@language"
    },
    "altLabel": {
      "@container": [
        "@language",
        "@set"
      ]
    },
    "hiddenLabel": {
      "@container": [
        "@language",
        "@set"
      ]
    },
    "definition": {
      "@container": "@language"
    },
    "note": {
      "@container": [
        "@language",
        "@set"
      ]
    },
    "changeNote": {
      "@container": [
        "@language",
        "@set"
      ]
    },
    "editorialNote": {
      "@container": [
        "@language",
        "@set"
      ]
    },
    "historyNote": {
      "@container": [
        "@language",
        "@set"
      ]
    },
    "scopeNote": {
      "@container": [
        "@language",
        "@set"
      ]
    },
    "notation": {
      "@container": "@set"
    },
    "example": {
      "@container": "@language"
    },
    "narrower": {
      "@container": "@set"
    },
    "related": {
      "@container": "@set"
    },
    "relatedMatch": {
      "@container": "@set"
    },
    "narrowerTransitive": {
      "@container": "@set"
    },
    "broaderTransitive": {
      "@container": "@set"
    },
    "broadMatch": {
      "@container": "@set"
    },
    "narrowMatch": {
      "@container": "@set"
    },
    "closeMatch": {
      "@container": "@set"
    },
    "exactMatch": {
      "@container": "@set"
    },
    "hasTopConcept": {
      "@container": "@set"
    },
    "inScheme": {
      "@container": "@set"
    },
    "topConceptOf": {
      "@container": "@set"
    },
    "deprecated": {
      "@id": "owl:deprecated",
      "@type": "xsd:boolean"
    },
    "isReplacedBy": {
      "@id": "dct:isReplacedBy",
      "@container": "@set"
    }
  }
}