1/327
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
CAR
Corrective Action Report:CAR is a document that outlines actions taken to correct identified non-conformities or deficiencies in a process or system.
AAA
Authentication, Authorization, and Accounting:AAA refers to a security framework that encompasses Authentication, Authorization, and Accounting, commonly used in computer systems and networks to control access and monitor activities.
ALE
Annualized Loss Expectancy:ALE is a risk management metric that represents the expected financial loss from a security incident in a year.
APT
Advanced Persistent Threat:APT is a type of cyber attack where an unauthorized user gains access to a network and remains undetected for an extended period, often with the goal of stealing sensitive data.
ATT&CK
Adversarial Tactics, Techniques, and Common Knowledge:ATT&CK is a framework for understanding the actions and behaviors of cyber adversaries, providing valuable insights for threat intelligence and defense strategies.
BPA
Business Partners Agreement:BPA is a formal agreement between business partners that outlines the terms and conditions of their collaboration.
CA
Certificate Authority:CA is a trusted entity that issues digital certificates, verifying the identities of individuals, organizations, or devices.
CAPTCHA
Completely Automated Public Turing Test to Tell Computers and Humans Apart:CAPTCHA is a security measure used to distinguish between human and automated access to websites by presenting challenges that are easy for humans but difficult for machines to solve.
CERT
Computer Emergency Response Team:CERT is a group of information security experts responsible for protecting an organization from cyber threats and responding to incidents.
DBA
Database Administrator:DBA is a professional responsible for managing and maintaining a database system.
DKIM
DomainKeys Identified Mail:DKIM is an email authentication method that allows the sender to digitally sign an email, verifying its authenticity.
DMARC
Domain Message Authentication Reporting and Conformance:DMARC is an email authentication protocol that helps prevent email spoofing and phishing attacks.
DNS
Domain Name System:DNS is a system that translates domain names into IP addresses, facilitating the routing of data on the internet.
ERP
Enterprise Resource Planning:ERP is a software solution that integrates core business processes, such as finance, human resources, and inventory management, into a unified system.
FTPS
Secured File Transfer Protocol:FTPS is an extension of FTP that adds support for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.
HSM
Hardware Security Module:HSM is a physical or logical device that provides secure key storage and cryptographic operations, often used to safeguard sensitive data.
IaaS
Infrastructure as a Service:IaaS is a cloud computing service model that provides virtualized computing resources over the internet.
IEEE
Institute of Electrical and Electronics Engineers:IEEE is a professional association that develops standards for the electronics and electrical industries.
IRC
Internet Relay Chat:IRC is a real-time text messaging protocol that allows users to communicate in channels or private messages.
IRP
Incident Response Plan:IRP is a documented set of procedures and guidelines to follow in the event of a cybersecurity incident.
ISO
International Standards Organization:ISO is an international standard-setting body that develops and publishes standards for various industries.
ISSO
Information Systems Security Officer:ISSO is an individual responsible for the information security of an organization's information systems.
LAN
Local Area Network:LAN is a network that connects computers and devices within a limited geographic area, such as a home, office, or campus.
MAC (Message)
Message Authentication Code:MAC is a short piece of information used to authenticate a message and to provide integrity and authenticity.
MFD
Multifunction Device:MFD is a device that combines various office functionalities into one machine, such as printing, scanning, and copying.
MTBF
Mean Time Between Failures:MTBF is a measure of the expected time between the failures of a system or component.
MTTR
Mean Time to Recover:MTTR is the average time required to repair a failed system or component and restore it to normal operation.
MTU
Maximum Transmission Unit:MTU is the size of the largest data packet that can be transmitted over a network.
NIDS
Network-based Intrusion Detection System:NIDS is an intrusion detection system that monitors and analyzes network traffic for signs of malicious activity.
OSINT
Open-source Intelligence:OSINT is the collection and analysis of information that is gathered from public, open sources.
P2P
Peer to Peer:P2P is a decentralized communication model where each party has the same capabilities and responsibilities.
PAP
Password Authentication Protocol:PAP is a simple authentication protocol that uses a plaintext password.
PCI DSS
Payment Card Industry Data Security Standard:PCI DSS is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment.
PIV
Personal Identity Verification:PIV is a U.S. government standard for secure and reliable forms of identification issued by the federal government to its employees and contractors.
PUP
Potentially Unwanted Program:PUP is software that may be unwanted on a computer and is often installed without the user's consent.
RA (Recovery)
Recovery Agent:RA is an individual or entity authorized to decrypt data in case of data recovery or system access needs.
RA (Registration)
Registration Authority:RA is an entity responsible for authenticating users and devices in a public key infrastructure (PKI).
RTP
Real-time Transport Protocol:RTP is a network protocol used to deliver audio and video over IP networks.
SAML
Security Assertions Markup Language:SAML is an XML-based standard for exchanging authentication and authorization data between parties.
SED
Self-encrypting Drives:SED are hard drives that automatically and continuously encrypt the data on the drive without user intervention.
SOW
Statement of Work:SOW is a document that defines project-specific activities, deliverables, and timelines for a vendor providing services to a client.
TPM
Trusted Platform Module:TPM is a hardware-based security feature that stores cryptographic keys, passwords, or certificates.
TSIG
Transaction Signature:TSIG is a protocol extension to DNS (Domain Name System) that allows for transaction-level authentication using shared secrets.
UTP
Unshielded Twisted Pair:UTP is a type of cable that consists of pairs of twisted copper wires and is widely used for network cabling.
VBA
Visual Basic:VBA is a programming language developed by Microsoft to automate tasks in Microsoft Office applications.
VLAN
Virtual Local Area Network:VLAN is a network of computers that behave as if they are connected to the same wire, regardless of their physical location.
VoIP
Voice over IP:VoIP is a technology that enables voice communication and multimedia sessions over the internet.
VTC
Video Teleconferencing:VTC is a technology that allows users in different locations to hold face-to-face meetings without having to move to a single location physically.
WO
Work Order:WO is a document containing instructions to perform work, usually within an organization or business context.
XML
Extensible Markup Language:XML is a markup language that defines rules for encoding documents in a format that is both human-readable and machine-readable.
XOR
Exclusive Or:XOR is a logical operation that outputs true or 1 only when the number of true inputs is odd.
ACL
Access Control List:ACL is a list of rules specifying which users or system processes are granted access to objects, as well as what operations are allowed on given objects.
AES
Advanced Encryption Standard:AES is a widely used encryption algorithm that ensures secure communication by protecting sensitive data through advanced cryptographic techniques.
AES-256
Advanced Encryption Standards 256-bit:AES-256 is a specific implementation of the Advanced Encryption Standard using a 256-bit key size, providing a high level of security.
AH
Authentication Header:AH is a protocol used in IP networking to provide connectionless integrity and data origin authentication for IP datagrams.
AI
Artificial Intelligence:AI refers to the development of computer systems that can perform tasks that typically require human intelligence, such as visual perception, speech recognition, and decision-making.
AIS
Automated Indicator Sharing:AIS is a system that enables the automated exchange of cyber threat indicators and defensive measures among organizations.
AP
Access Point:An Access Point is a device that allows wireless communication devices to connect to a wired network using Wi-Fi or related standards.
API
Application Programming Interface:API is a set of rules and tools for building software applications, allowing different software systems to communicate with each other.
ARO
Annualized Rate of Occurrence:ARO is a risk management metric representing the estimated frequency of a specific threat occurring in a year.
ARP
Address Resolution Protocol:ARP is a protocol used to map an IP address to a physical machine address (MAC address) on a local network.
ASLR
Address Space Layout Randomization:ASLR is a security technique that randomizes the memory addresses used by system components, making it harder for attackers to predict target locations.
AUP
Acceptable Use Policy:AUP is a set of rules and guidelines outlining the acceptable ways individuals may use computing and network resources within an organization.
AV
Antivirus:Antivirus refers to software designed to detect, prevent, and remove malicious software (malware) from computer systems.
BASH
Bourne Again Shell:BASH is a Unix shell and command language, commonly used as the default shell on many Linux distributions.
BCP
Business Continuity Planning:BCP is a process that outlines the necessary steps an organization must take to ensure its critical functions continue during and after a disaster.
BGP
Border Gateway Protocol:BGP is a standardized exterior gateway protocol used to exchange routing and reachability information among autonomous systems on the internet.
BIA
Business Impact Analysis:BIA is a process that identifies and evaluates the potential impact of disruptions to critical business operations.
BIOS
Basic Input/Output System:BIOS is a firmware used to perform hardware initialization during the booting process and provide runtime services for operating systems.
BPDU
Bridge Protocol Data Unit:BPDU is a frame exchanged between bridges (network switches) to detect loops in a network topology using the spanning tree protocol.
BYOD
Bring Your Own Device:BYOD is a policy that allows employees to use their personal devices (laptops, smartphones) for work purposes, creating challenges for IT security.
CASB
Cloud Access Security Broker:CASB is a security solution that helps organizations extend their security policies to the cloud, providing visibility and control over data in cloud applications.
CBC
Cipher Block Chaining:CBC is a mode of operation for block ciphers, where each block of plaintext is XORed with the previous ciphertext block before encryption.
CCMP
Counter Mode/CBC-MAC Protocol:CCMP is an encryption protocol used in Wi-Fi networks, providing confidentiality and integrity using the Counter mode with CBC-MAC.
CCTV
Closed-circuit Television:CCTV is a system where video cameras transmit signals to a specific set of monitors, used for surveillance and security purposes.
CFB
Cipher Feedback:CFB is a mode of operation for block ciphers, where each ciphertext block is fed back into the encryption algorithm to encrypt the next block of plaintext.
CHAP
Challenge Handshake Authentication Protocol:CHAP is a security protocol used in Point-to-Point Protocol (PPP) for authenticating users.
CIA
Confidentiality, Integrity, Availability:CIA is a security model that represents the core principles of information security: Confidentiality, Integrity, and Availability.
CIO
Chief Information Officer:CIO is a senior executive responsible for the information technology and computer systems that support enterprise goals.
CIRT
Computer Incident Response Team:CIRT is a team of professionals responsible for responding to and mitigating the impact of cybersecurity incidents.
CMS
Content Management System:CMS is a software application that allows users to create, edit, and manage digital content on websites without the need for specialized technical knowledge.
COOP
Continuity of Operation Planning:COOP is a process that ensures essential functions continue during and after a disaster or emergency situation.
COPE
Corporate Owned, Personally Enabled:COPE is a mobile device management strategy where organizations provide and control devices used by employees for both work and personal purposes.
CP
Contingency Planning:CP involves developing plans and procedures to ensure an organization's critical functions continue during and after disruptive events.
CRC
Cyclical Redundancy Check:CRC is an error-checking technique used in data communication to detect errors in transmitted data.
CRL
Certificate Revocation List:CRL is a list of digital certificates that have been revoked by the certificate authority before their scheduled expiration date.
CSO
Chief Security Officer:CSO is a senior executive responsible for the overall security posture of an organization, including physical and information security.
CSP
Cloud Service Provider:CSP is a company that offers cloud computing services, providing infrastructure, platforms, or software over the internet.
CSR
Certificate Signing Request:CSR is a request sent to a Certificate Authority to apply for a digital certificate.
CSRF
Cross-site Request Forgery:CSRF is an attack where an attacker tricks a user's browser into making an unintentional request to a web application on which the user is authenticated.
CSU
Channel Service Unit:CSU is a device used in telecommunications to connect a digital communication line to a customer's equipment.
CTM
Counter Mode:CTM is a mode of operation for block ciphers, where each block of plaintext is encrypted separately using a unique counter value.
CTO
Chief Technology Officer:CTO is a senior executive responsible for the technological direction of an organization, overseeing research, development, and implementation.
CVE
Common Vulnerability Enumeration:CVE is a standardized identifier for vulnerabilities and exposures in software and hardware.
CVSS
Common Vulnerability Scoring System:CVSS is a framework for assessing the severity of software vulnerabilities, providing a numerical score to prioritize remediation efforts.
CYOD
Choose Your Own Device:CYOD is a mobile device management strategy that allows employees to choose from a list of approved devices for work purposes.
DAC
Discretionary Access Control:DAC is a security model where access rights are determined by the owner of the resource, allowing users to control access to their own resources.
DDoS
Distributed Denial of Service:DDoS is a cyber attack where multiple compromised computers are used to flood a target system with traffic, causing a denial of service.
DEP
Data Execution Prevention:DEP is a security feature that prevents code execution from certain regions of memory, reducing the risk of buffer overflow attacks.
DES
Digital Encryption Standard:DES is a symmetric key algorithm used for encrypting and decrypting data, widely used in the past but now considered insecure.