BC | Business Continuity |
BIA | Business Impact Analysis |
SaaS | Software as a Service |
CSIRT | Cybersecurity Incident Response Team |
CERT | Computer Emergency Response Team |
CI/CD | Continuous Integration and Continuous Delivery |
OWASP | Open Web Application Security Project |
PAM | Privileged Access Management |
BGP | Border Gateway Protocol |
CSRF | Cross-site Request Forgery |
CA | Certificate Authority |
DLP | Data Loss Prevention |
REST | Representational State Transfer |
SASE | Secure Access Secure Edge |
ISO | International Organization for Standardization |
PII | Personally Identifiable Information |
SNMP | Simple Network Management Protocol |
ITIL | Information Technology Infrastructure Library |
PHP | Hypertext Preprocessor |
CVSS | Common Vulnerability Scoring System |
SDLC | Software Development Life Cycle |
LOI | Letter of Intent |
WAN | Wide Area Network |
MOU | Memorandum of Understanding |
MSF | Metasploit Framework |
NTP | Network Time Protocol |
IDS | Intrusion Detection System |
OSSTMM | Open Source Security Testing Methodology Manual |
IT | Information Technology |
RFI | Remote File Inclusion |
TRACE | Trade Reporting and Compliance Engine |
OS | Operating System |
MTTR | Mean Time to Repair |
SDN | Software-defined Networking |
SOC | Security Operations Center |
TTP | Tactics, Techniques, and Procedures |
STIX | Structured Threat Information Expression |
PCI DSS | Payment Card Industry Data Security Standard |
UEBA | User and Entity Behavior Analytics |
LFI | Local File Inclusion |
SMTP | Simple Mail Transfer Protocol |
IPS | Intrusion Prevention System |
OpenVAS | Open Vulnerability Assessment Scanner |
SMB | Server Message Block |
TLS | Transport Layer Security |
VPN | Virtual Private Network |
AV | Antivirus |
CHD | Cardholder Data |
CIS | Center for Internet Security |
BCP | Business Continuity Plan |
URI | Uniform Resource Identifier |
XML | Extensible Markup Language |
NIDS | Network-based Intrusion Detection System |
PID | Process Identifier |
VLAN | Virtual LAN |
JSON | JavaScript Object Notation |
LAN | Local Area Network |
DNS | Domain Name Service |
ZTNA | Zero Trust Network Access |
SLA | Service-level Agreement |
MTTD | Mean Time to Detect |
POC | Proof of Concept |
CASB | Cloud Access Security Broker |
SIEM | Security Information and Event Management |
EDR | Endpoint Detection and Response |
KPI | Key Performance Indicator |
SAML | Security Assertion Markup Language |
SCADA | Supervisory Control and Data Acquisition |
GDB | GNU Debugger |
HTTP | Hypertext Transfer Protocol |
SPF | Sender Policy Framework |
ZAP | Zed Attack Proxy |
IP | Internet Protocol |
VM | Virtual Machine |
FTP | File Transfer Protocol |
NAC | Network Access Control |
URL | Uniform Resource Locator |
TCP | Transmission Control Protocol |
DDoS | Distributed Denial of Service |
SSO | Single Sign-on |
CDN | Content Delivery Network |
MSP | Managed Service Provider |
SOAR | Security Orchestration, Automation, and Response |
API | Application Programming Interface |
ARP | Address Resolution Protocol |
HIPS | Host-based Intrusion Prevention System |
PKI | Public Key Infrastructure |
SLO | Service-level Objective |
FIM | File Integrity Monitoring |
XDR | Extended Detection Response |
COBIT | Control Objectives for Information and Related Technologies |
NDA | Non-disclosure Agreement |
XXE | XML External Entity |
DR | Disaster Recovery |
WAF | Web Application Firewall |
HIDS | Host-based Intrusion Detection System |
IoC | Indicators of Compromise |
DKIM | Domain Keys Identified Mail |
SFTP | Secure File Transfer Protocol |
SSL | Secure Sockets Layer |
ACL | Access Control List |
PLC | Programmable Logic Controller |
GPO | Group Policy Objects |
SSRF | Server-side Request Forgery |
APT | Advanced Persistent Threat |
RCE | Remote Code Execution |
SQL | Structured Query Languge |
IR | Incident Response |
OT | Operational Technology |
IaaS | Infrastructure as a Service |
MFA | Multifactor Authentication |
HTTPS | Hypertext Transfer Protocol Secure |
RXSS | Reflected Cross-site Scripting |
SWG | Secure Web Gateway |
TFTP | Trivial File Transfer Protocol |
LDAPS | Lightweight Directory Access Protocol |
DoS | Denial of Service |
USB | Universal Serial Bus |
C2 | Command and Control |
MAC | Media Access Control |
NGFW | Next-generation Firewall |
RDP | Remote Desktop Protocol |
MSSP | Managed Security Service Provider |
CVE | Common Vulnerabilities and Exposures |
ICMP | Internet Control Message Protocol |
ICS | Industrial Control Systems |
XSS | Cross-site Scripting |
DMARC | Domain-based Message Authentication, Reporting, and Conformance |