Education
Information Security Acronyms Explained
A brief description of common information security acronyms and their definitions.
Information Technology (IT) often seems like a world of its own; there are so many different topics and areas to explore that the process can be overwhelming for beginners. This is why we decided to help newbies with a place to start: A list of acronyms and their meanings. The acronyms and definitions below mostly belong to the area of Information Security, which is when information is secured from a variety of threats through various digital and physical security measures.
AI
Artificial Intelligence is a branch of computer science that focuses on creating intelligent machines capable of performing tasks that typically require human intelligence. These tasks may include understanding natural language, recognizing patterns, learning from experience, and making decisions based on data. AI technologies aim to simulate human-like intelligence and behavior in machines, enabling them to solve complex problems and adapt to new situations.
BIOS
Basic Input Output System is a program that ensures the computer system turns on after being powered on. This program also manages the flow of data between the operating system (OS) of the computer and any attached devices, such as the hard disk, mouse, keyboard, etc.
BCM
Business Continuity Management is a framework that ensures organizations are resilient and can quickly restore business operations after the event of a cyberattack. It includes identifying any potential risks to the organization and implementing measures to prevent or reduce these identified risks.
DDoS
Distributed Denial of Service is a type of attack where the attacker attempts to reduce service availability or block services available on a company network. An example of this would be when you attempt to buy tickets to a concert online but cannot get through to the website and the page keeps loading instead of landing on the page.
EDR
Endpoint Detection and Response is technology that continuously monitors network devices (endpoints) for threats and acts to mitigate those threats before they become a risk to the network.
GDPR
General Data and Protection Regulation is a legal framework established by the European Union that guides how personal data is collected and processed. It went into effect in 2018 and aims to give EU citizens more control over how their information is collected and processed.
IAM
Identity and Access Management is a framework of different business processes, policies and technologies that facilitates the management of digital and electronic identities. This means it the way organizations and companies manage their digital and electronic identities in the online space through internal documentation.
ITDR
Identity Theft Detection and Response is a cybersecurity procedure for identifying, reducing, and responding to identity-based threats such as data breaches, leaked passwords, etc. It involves a combination of tools, processes, and best practices to ensure the organization is prepared for attack and can effectively identify and respond to any potential attacks.
ICT
Information Communication Technology is a term used to describe all communication technologies and devices, such as laptops, mobile phones, computers, satellites, etc., that facilitate the way communication is created, transmitted, and stored.
ISMS
Information Security Management System is a set of policies and procedures aimed at reducing risk to the organization and guaranteeing business continuity by proactively reducing the effects of security breaches. In simple terms, it is the way an organization reduces risk and protects itself from risk to ensure they can still run things safely and effectively.
IoT
Internet of Things refers to a network of physical devices, vehicles, appliances, and other physical objects embedded with sensors, software and network connectivity that allows them to collect and share data. Simply, the IoT is a physical network that collects and shares data in an online space.
ISMS
Information Security Management System is a set of policies and procedures aimed at reducing risk to the organization and guaranteeing business continuity by proactively reducing the effects of security breaches. In simple terms, it is the way an organization reduces risk and protects itself from risk to ensure they can still run things safely and effectively.
IT
Information Technology is a broad subject that at its core means it is any capability that helps protect and preserve data confidentiality, integrity, and availability from any kind of digital threat. In simple terms, IT is ensuring the protection and preservation of data to ensure it was not tampered with or damaged.
ITIL
Information Technology Infrastructure Library is a library of best practices for managing IT services and improving IT support as a service. It aims to ensure there is alignment between IT services and business objectives no matter how they may change.
IDPS
Intrusion Detection and Prevention System is an application that continuously monitors network traffic for any malicious activity or known threats. The IDPS systems will block any suspected threats or malicious activity before they become a threat to the network.
ITSM
Information Technology Service Management is a set of practices that aligns how IT services are delivered to the customer with the organization's needs. It includes all the processes that enable the design, creation, delivery, and support of those IT services.
MDM
Mobile Device Management is security software that organizations enforce that enables them to secure, monitor, manage, and enforce policies relating to the mobile devices of employees. It ensures corporate data is secure while still allowing employees to use their mobile devices for work-related purposes.
OSI
Open Systems Interconnect is a conceptual model that determines how networks communicate and send data. It is divided into seven layers on top of each other that work together to receive and send data over a network. Each layer in the model is independent of the other.
RBAC
Role-Based Access Control is an access control measure that assigns access to users based on their role within the organization. This method is an effective strategy to ensure authorized users have access to relevant and confidential information on a network.
SIEM
Security Information and Event Management is a security solution that combines security information management and event management. It ensures organizations can identify and address threats and vulnerabilities before they can impact business operations.
SOC
Security Operations Center is a team of IT security professionals that protect an organization by monitoring, detecting, analyzing, and investigating cyber threats, networks, servers, computers, end point devices, operating system applications, and databases continually, and ensuring there is no sign of cyber security incidents. Simply put, SOC is a team of IT professionals focused on protecting an organization from hacking attempts or other kinds of cyber threats 24/7.
VPN
Virtual Private Network is a security measure used when the device or system is connected to an unsecure or unsafe network. The VPN will create a secure encrypted network connection to prevent unauthorized access or tracking.
WAF
Web Application Firewall is a protective measure that filters HTTP traffic between a web application (like Gmail) and the internet. It monitors the traffic for certain attack types, like SQL injection or cross site scripting.
This list of basic acronyms and definitions used in the IT space is a good introduction, and sneak peek, into that world. Although IT seems overwhelming, especially at first glance, it is an industry changing the world one day, and invention, at a time.
If this has sparked an interest in the world of IT for you, explore our eLearning platform to get a better understanding of the various terminology used throughout the industry.