Glossary
A
The process of restricting access to networks, systems, or resources based on predetermined criteria to protect sensitive information.
A prolonged and targeted cyberattack designed to steal data or gain access to networks, often carried out by well-funded and organized threat actors.
Software designed to detect, prevent, and remove malicious software (malware) from computer systems.
B
The process of creating copies of data to ensure it is recoverable in case of data loss or system failure.
A decentralized, distributed ledger technology used to securely record transactions across multiple computers.
A policy that allows employees to use their personal devices, such as smartphones or laptops, for work-related tasks.
C
The delivery of computing services over the internet, including storage, processing, and software, enabling on-demand access to resources.
The measures and technologies employed to protect data, applications, and services hosted in cloud environments.
Adherence to laws, regulations, and standards to ensure the protection of data and maintain privacy and security.
The practice of securing communication and data through encoding and decoding techniques to protect confidentiality.
The practice of protecting systems, networks, and data from digital attacks, breaches, and unauthorized access.
D
The process of converting data into a coded form to prevent unauthorized access during transmission or storage.
The accuracy, consistency, and reliability of data throughout its lifecycle, from creation to storage and retrieval.
The protection of personal and sensitive data from unauthorized access or misuse, ensuring individuals’ rights are upheld.
The process of retrieving lost, corrupted, or damaged data from backup systems or other recovery methods.
The practice of storing copies of data across multiple locations or systems to ensure data availability in case of failure.
The process and strategies used to restore IT systems and data after a catastrophic event, such as a natural disaster or cyberattack.
Security measures designed to prevent unauthorized access, leakage, or loss of sensitive data.
E
Protection for individual devices (endpoints) connected to a network, including computers, mobile devices, and IoT devices.
F
Security systems designed to monitor and control incoming and outgoing network traffic based on predetermined security rules.
G
A European Union regulation that governs the protection of personal data and privacy for individuals within the EU and the European Economic Area.
H
A U.S. regulation that sets standards for the protection of health-related data and ensures privacy and security in healthcare environments.
I
The process of identifying, managing, and mitigating security incidents to minimize their impact on business operations.
A system designed to detect unauthorized access or anomalies within a network, alerting administrators to potential security threats.
A system designed to actively block or prevent security threats or intrusions in real time based on pre-established rules.
A unique numerical label assigned to each device connected to a network, used for identification and communication.
An international standard for information security management, outlining requirements for establishing, implementing, and maintaining an information security management system (ISMS).
M
Malicious software designed to harm, exploit, or gain unauthorized access to computer systems and networks.
A security system that requires two or more forms of authentication from different categories (e.g., something you know, something you have, something you are) to access a system.
A set of tools and processes used to secure, monitor, and manage mobile devices within an organization.
N
The practice of protecting a computer network from unauthorized access, misuse, and threats, ensuring the integrity and confidentiality of data.
P
The practice of simulating cyberattacks on a system to identify vulnerabilities and weaknesses before malicious actors can exploit them.
A cyberattack where attackers impersonate legitimate entities to trick individuals into revealing sensitive information, such as passwords or credit card details.
R
A type of malicious software that locks or encrypts a user's data and demands payment (ransom) to restore access to the data.
The duplication of critical components, systems, or data to ensure availability and continuity of operations in case of failure.
The process of identifying, assessing, and mitigating risks to minimize their impact on an organization’s operations, assets, and reputation.
S
A cloud computing model that delivers software applications over the internet, typically on a subscription basis, without the need for on-premise installations.
A security solution that provides real-time monitoring, detection, and analysis of security events and incidents within an organization's IT infrastructure.
A centralized unit within an organization responsible for monitoring, detecting, and responding to cybersecurity incidents and threats.
A set of standards for managing data based on five trust service principles: security, availability, processing integrity, confidentiality, and privacy.
Unsolicited or irrelevant messages, typically sent in bulk, often for the purpose of advertising or phishing.
A tool or algorithm used to identify and block unsolicited or malicious emails (spam) from reaching an inbox.
Cryptographic protocols used to secure communications over a network, such as encrypting data sent between web servers and browsers.
T
Information and analysis about potential or current cybersecurity threats, used to help organizations prevent or respond to attacks.
A security measure that requires two separate forms of verification to access an account, typically a password and a code sent to a mobile device.
U
The amount of time a system, service, or network is operational and available for use, typically expressed as a percentage.
V
A technology that creates a secure, encrypted connection over a public network, such as the internet, allowing users to protect their privacy and data.
A weakness in a system or application that could be exploited by a threat actor to gain unauthorized access or cause damage.
W
A large-scale network that connects multiple local area networks (LANs), typically covering a broad geographical area.
A security system designed to monitor and filter HTTP traffic to protect web applications from attacks such as SQL injection or cross-site scripting (XSS).
The practice of protecting websites and web applications from cyberattacks, ensuring confidentiality, integrity, and availability of online resources.
Z
Grease fitting for lubrication access
A security model that assumes no entity, either inside or outside the network, should be trusted by default, requiring strict verification for access to any resources.
A cyberattack that exploits a previously unknown vulnerability in software or hardware, before the vendor can patch it.
A type of cyberattack that takes advantage of a software vulnerability that is not yet known to the vendor or public, making it difficult to defend against.
A security flaw in software or hardware that is unknown to the vendor, and potentially exploited by cybercriminals before it is addressed with a patch.