DDoS | Distributed Denial of Service |
OS | Operating System |
FRR | False Rejection Rate |
ICMP | Internet Control Message Protocol |
URI | Uniform Resource Identifier |
VBA | Visual Basic |
PBX | Private Branch Exchange |
SaaS | Software as a Service |
SDLC | Software Development Lifecycle |
BASH | Bourne Again Shell |
IPSec | Internet Protocol Security |
NIPS | Network-based Intrusion Prevention System |
RFID | Radio Frequency Identifier |
CSRF | Cross-site Request Forgery |
DEP | Data Execution Prevention |
IM | Instant Messaging |
NTFS | New Technology File System |
PII | Personally Identifiable Information |
RTOS | Real-time Operating System |
CIRT | Computer Incident Response Team |
GPS | Global Positioning System |
HDD | Hard Disk Drive |
ML | Machine Learning |
RACE | Research and Development in Advanced Communications Technologies in Europe |
VDE | Virtual Desktop Environment |
VLAN | Virtual Local Area Network |
ARP | Address Resolution Protocol |
DHE | Diffie-Hellman Ephemeral |
FDE | Full Disk Encryption |
SAE | Simultaneous Authentication of Equals |
EAP | Extensible Authentication Protocol |
IAM | Identity and Access Management |
SIEM | Security Information and Event Management |
VM | Virtual Machine |
CHAP | Challenge Handshake Authentication Protocol |
DLP | Data Loss Prevention |
IEEE | Institute of Electrical and Electronics Engineers |
BIOS | Basic Input/Output System |
CFB | Cipher Feedback |
CSO | Chief Security Officer |
WPS | Wi-Fi Protected Setup |
WTLS | Wireless TLS |
RTO | Recovery Time Objective |
SFTP | Secured File Transfer Protocol |
WAP | Wireless Access Point |
CVE | Common Vulnerability Enumeration |
MDM | Mobile Device Management |
OSPF | Open Shortest Path First |
PPP | Point-to-Point Protocol |
SMS | Short Message Service |
URL | Universal Resource Locator |
VLSM | Variable Length Subnet Masking |
BIA | Business Impact Analysis |
CTM | Counter Mode |
PSK | Pre-shared Key |
SE Linux | Security-enhanced Linux |
WPA | Wi-Fi Protected Access |
CP | Contingency Planning |
MTTF | Mean Time to Failure |
SEH | Structured Exception Handler |
MaaS | Monitoring as a Service |
TPM | Trusted Platform Module |
USB OTG | USB On the Go |
RAT | Remote Access Trojan |
IoC | Indicators of Compromise |
OVAL | Open Vulnerability Assessment Language |
PPTP | Point-to-Point Tunneling Protocol |
SLA | Service-level Agreement |
WIPS | Wireless Intrusion Prevention System |
NTP | Network Time Protocol |
SMTP | Simple Mail Transfer Protocol |
AES | Advanced Encryption Standard |
DPO | Data Privacy Officer |
ECB | Electronic Code Book |
CTO | Chief Technology Officer |
ESP | Encapsulated Security Payload |
AUP | Acceptable Use Policy |
CCMP | Counter Mode/CBC-MAC Protocol |
HMAC | Hashed Message Authentication Code |
IoT | Internet of Things |
MPLS | Multi-protocol Label Switching |
RDP | Remote Desktop Protocol |
PEM | Privacy Enhanced Mail |
PIV | Personal Identity Verification |
GRE | Generic Routing Encapsulation |
HTML | Hypertext Markup Language |
P12 | PKCS #12 |
LEAP | Lightweight Extensible Authentication Protocol |
AP | Access Point |
OT | Operational Technology |
PFS | Perfect Forward Secrecy |
SWG | Secure Web Gateway |
VoIP | Voice over IP |
NGFW | Next-generation Firewall |
SCADA | Supervisory Control and Data Acquisition |
SSD | Solid State Drive |
UEM | Unified Endpoint Management |
KEK | Key Encryption Key |
MSSP | Managed Security Service Provider |
NIDS | Network-based Intrusion Detection System |
ROI | Return on Investment |
TLS | Transport Layer Security |
DHCP | Dynamic Host Configuration Protocol |
FIM | File Integrity Management |
MFP | Multifunction Printer |
MSP | Managed Service Provider |
PUP | Potentially Unwanted Program |
UAV | Unmanned Aerial Vehicle |
SED | Self-encrypting Drives |
ASLR | Address Space Layout Randomization |
CSR | Certificate Signing Request |
DAC | Discretionary Access Control |
HSM | Hardware Security Module |
IRC | Internet Relay Chat |
LAN | Local Area Network |
MSA | Master Service Agreement |
FTPS | File Transfer Protocol Secure |
IR | Incident Response |
NTLM | New Technology LAN Manager |
CMS | Content Management System |
SNMP | Simple Network Management Protocol |
BYOD | Bring Your Own Device |
IPS | Intrusion Prevention System |
PGP | Pretty Good Privacy |
RAID | Redundant Array of Inexpensive Disks |
SDLM | Software Development Lifecycle Methodology |
Authentication | Protocol |
TOC | Time-of-check |
UPS | Uninterruptable Power Supply |
CA | Certificate Authority |
MFD | Multifunction Device |
AIS | Automated Indicator Sharing |
MS-CHAP | Microsoft Challenge-Handshake Authentication Protocol |
RAD | Rapid Application Development |
RTP | Real-time Transport Protocol |
SPF | Sender Policy Framework |
S/MIME | Secure/Multipurpose Internet Mail Extensions |
SPIM | Spam over Internet Messaging |
UTM | Unified Threat Management |
CAPTCHA | Completely Automated Public Turing Test to Tell Computers and Humans Apart |
PHI | Personal Health Information |
AV | Antivirus |
TOU | Time-of-use |
VPN | Virtual Private Network |
ECDSA | Elliptic Curve Digital Signature Algorithm |
RC4 | Rivest Cipher version 4 |
DKIM | DomainKeys Identified Mail |
OSINT | Open-source Intelligence |
IDF | Intermediate Distribution Frame |
IV | Initialization Vector |
MTTR | Mean Time to Recover |
NFC | Near Field Communication |
RIPEMD | RACE Integrity Primitives Evaluation Message Digest |
SQL | Structured Query Language |
SRTP | Secure Real-Time Protocol |
SSH | Secure Shell |
TACACS+ | Terminal Access Controller Access Control System |
TTP | Tactics, Techniques, and Procedures |
HTTPS | Hypertext Transfer Protocol Secure |
IP | Internet Protocol |
IRP | Incident Response Plan |
SDN | Software-defined Networking |
TSIG | Transaction Signature |
WO | Work Order |
POP | Post Office Protocol |
RAS | Remote Access Server |
UAT | User Acceptance Testing |
VDI | Virtual Desktop Infrastructure |
APT | Advanced Persistent Threat |
PAM | Pluggable Authentication Modules |
PDU | Power Distribution Unit |
SoC | System on Chip |
DMARC | Domain Message Authentication Reporting and Conformance |
GPU | Graphics Processing Unit |
MTBF | Mean Time Between Failures |
GPO | Group Policy Object |
HA | High Availability |
IdP | Identity Provider |
PKCS | Public Key Cryptography Standards |
SCAP | Security Content Automation Protocol |
RBAC | Rule-based Access Control |
SHTTP | Secure Hypertext Transfer Protocol |
CAR | Corrective Action Report |
CYOD | Choose Your Own Device |
DoS | Denial of Service |
NIST | National Institute of Standards & Technology |
PAT | Port Address Translation |
CSU | Channel Service Unit |
FACL | File System Access Control List |
L2TP | Layer 2 Tunneling Protocol |
MTU | Maximum Transmission Unit |
NAT | Network Address Translation |
CASB | Cloud Access Security Broker |
MOA | Memorandum of Agreement |
OTA | Over the Air |
SD-WAN | Software-defined Wide Area Network |
SASE | Secure Access Service Edge |
DES | Digital Encryption Standard |
PEAP | Protected Extensible Authentication Protocol |
MAN | Metropolitan Area Network |
CRC | Cyclical Redundancy Check |
SCEP | Simple Certificate Enrollment Protocol |
SLE | Single Loss Expectancy |
OID | Object Identifier |
SIM | Subscriber Identity Module |
SOC | Security Operations Center |
TGT | Ticket Granting Ticket |
COPE | Corporate Owned, Personally Enabled |
PAC | Proxy Auto Configuration |
RSA | Rivest, Shamir, & Adleman |
SOW | Statement of Work |
HTTP | Hypertext Transfer Protocol |
KDC | Key Distribution Center |
POTS | Plain Old Telephone Service |
SAN | Subject Alternative Name |
CCTV | Closed-circuit Television |
GCM | Galois Counter Mode |
PCAP | Packet Capture |
SDK | Software Development Kit |
SQLi | SQL Injection |
WIDS | Wireless Intrusion Detection System |
BPDU | Bridge Protocol Data Unit |
COOP | Continuity of Operation Planning |
PBKDF2 | Password-based Key Derivation Function 2 |
SMTPS | Simple Mail Transfer Protocol Secure |
TOTP | Time-based One-time Password |
ISSO | Information Systems Security Officer |
MFA | Multifactor Authentication |
AI | Artificial Intelligence |
CIO | Chief Information Officer |
DSA | Digital Signature Algorithm |
BCP | Business Continuity Planning |
BGP | Border Gateway Protocol |
CERT | Computer Emergency Response Team |
XSS | Cross-site Scripting |
CIA | Confidentiality, Integrity, Availability |
DNAT | Destination Network Address Translation |
PaaS | Platform as a Service |
PCI | DSS Payment Card Industry Data Security Standard |
ARO | Annualized Rate of Occurrence |
CSP | Cloud Service Provider |
MDF | Main Distribution Frame |
OAUTH | Open Authorization |
PTZ | Pan-tilt-zoom |
XDR | Extended Detection and Response |
DRP | Disaster Recovery Plan |
HOTP | HMAC-based One-time Password |
P2P | Peer to Peer |
AAA | Authentication, Authorization, and Accounting |
ESN | Electronic Serial Number |
IMAP | Internet Message Access Protocol |
XML | Extensible Markup Language |
BPA | Business Partners Agreement |
MD5 | Message Digest 5 |
PKI | Public Key Infrastructure |
XSRF | Cross-site Request Forgery |
MMS | Multimedia Message Service |
VPC | Virtual Private Cloud |
DLL | Dynamic Link Library |
EDR | Endpoint Detection and Response |
ISO | International Standards Organization |
PED | Personal Electronic Device |
SOAP | Simple Object Access Protocol |
SSL | Secure Sockets Layer |
FPGA | Field Programmable Gate Array |
VTC | Video Teleconferencing |
ICS | Industrial Control Systems |
IDEA | International Data Encryption Algorithm |
OCSP | Online Certificate Status Protocol |
TCP/IP | Transmission Control Protocol/Internet Protocol |
UDP | User Datagram Protocol |
MOU | Memorandum of Understanding |
AH | Authentication Header |
GDPR | General Data Protection Regulation |
RPO | Recovery Point Objective |
UEFI | Unified Extensible Firmware Interface |
XOR | Exclusive Or |
TAXII | Trusted Automated eXchange of Indicator Information |
ACL | Access Control List |
DSL | Digital Subscriber Line |
RTBH | Remotely Triggered Black Hole |
WEP | Wired Equivalent Privacy |
ECC | Elliptic Curve Cryptography |
WAF | Web Application Firewall |
GPG | Gnu Privacy Guard |
HIDS | Host-based Intrusion Detection System |
RA | Registration Authority |
DBA | Database Administrator |
IDS | Intrusion Detection System |
RADIUS | Remote Authentication Dial-in User Service |
AES-256 | Advanced Encryption Standards 256-bit |
CVSS | Common Vulnerability Scoring System |
ERP | Enterprise Resource Planning |
FTP | File Transfer Protocol |
MAC | Message Authentication Code |
SHA | Secure Hashing Algorithm |
SSO | Single Sign-on |
UTP | Unshielded Twisted Pair |
API | Application Programming Interface |
ATT&CK | Adversarial Tactics, Techniques, and Common Knowledge |
HIPS | Host-based Intrusion Prevention System |
HVAC | Heating, Ventilation Air Conditioning |
DNS | Domain Name System |
LDAP | Lightweight Directory Access Protocol |
NAC | Network Access Control |
CBC | Cipher Block Chaining |
ISP | Internet Service Provider |
SAML | Security Assertions Markup Language |
STIX | Structured Threat Information eXchange |
CRL | Certificate Revocation List |
ALE | Annualized Loss Expectancy |
PAP | Password Authentication Protocol |
ECDHE | Elliptic Curve Diffie-Hellman Ephemeral |
IaaS | Infrastructure as a Service |
IaC | Infrastructure as Code |
MBR | Master Boot Record |
NDA | Non-disclosure Agreement |
EFS | Encrypted File System |
IKE | Internet Key Exchange |
SOAR | Security Orchestration, Automation, Response |
TKIP | Temporal Key Integrity Protocol |