Ethical Hacking, Penetration Testing and IT-Forensics -Alphabet soup, Abbreviations and Definitions

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/18

flashcard set

Earn XP

Description and Tags

Vocabulary terms and definitions covering Security Operations Centers (SOC), incident classification levels, the Incident Response Team (CSIRT) structure, and incident response planning.

Last updated 4:35 PM on 5/14/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

19 Terms

1
New cards

ISOC (or SOC)

Information Security Operations Center; a physical place and group of people manning equipment 24/724/7 to monitor networks and services for abnormal activity.

2
New cards

NOC

Network Operations Center; a center that often cooperates and shares sites, people, and equipment with a SOC.

3
New cards

Security event

Anything security-related that does not affect any operations, such as a blocked SQL injection or a network scan for open ports.

4
New cards

Security incident

An adverse event that threatens, affects, or disrupts operations and may trigger an incident response.

5
New cards

IRT / CSIRT

Incident Response Team / Computer Security Incident Response Team; the group responsible for declaring and handling security incidents.

6
New cards

High level severity

An incident level expected to cause very significant damage or information loss, such as 60TB60\,TB of data being encrypted by ransomware.

7
New cards

Moderate level severity

An incident level that may cause damage, corruption, or loss of systems or information, such as the theft of an encrypted laptop.

8
New cards

Low level severity

An incident level that causes inconvenience or irritation with little to no consequences, such as a firewall restart causing a 5minute5\,minute traffic outage.

9
New cards

GDPR / NIS2

Regulatory frameworks that may mandate external reporting of security incidents.

10
New cards

Supply chain attack

A security incident where malware originates from an external computer used to support a third-party software.

11
New cards

Security disaster

An event resulting in large-scale destruction of property, loss of life, or massive changes to the physical environment which disrupts services.

12
New cards

CERT

Computer Emergency Response Team; a national or regional scale CSIRT, such as CERT-SE or Sunet CERT.

13
New cards

Incident Response Process

An iterative process consisting of Preparation, Detection, Analysis, Containment, Eradication, Recovery, and Post Incident steps.

14
New cards

Core CSIRT members

Fixed members typically including a team leader (CSO or CISO), analysts, SOC members, and security engineers.

15
New cards

Incident Response Plan Charter

A section of the response plan defining the mission statement and responsibilities of the team.

16
New cards

War room

A dedicated, prepared workspace for incident handling featuring team displays, note-sharing tools, and limited physical access.

17
New cards

Staff rotation

The practice of working in shifts and sending people home to manage fatigue during major incidents that last many days.

18
New cards

Internal communication plan

A component of the incident response plan designated to handle information flow within the organization to reduce pressure on the IRT.

19
New cards

Public communications rule

The principle for media contact: do not withhold information, do not lie, and do not speculate, while maintaining confidentiality for legal investigations.