Glossary

A | B | C | D | E | G | I | L | M | O | P | R | S | T | U | V | W

A

ACL — Access Control List

ACP — Attorney-Client Privilege

APT — Advanced Persistent Threat

AUV — Acceptable Use Violation

AV — Anti-Virus


B

BA — Business Associate

BAA — Business Associate Agreement

BCP — Business Continuity Planning

BCR — Binding Corporate Rules

BEC — Business Email Compromise

BGP — Border Gateway Protocol

BIA — Business Impact Analysis

BOD — Board of Directors

BYOD — Bring your own device


C

C2 — Command and Control

CAPS — Cyber Attack Against Payment Systems

CCMP — Corporate Crisis Management Plan

CIRP — Cyber Incident Response Plan

CPO — Chief Privacy Officer

CSC — Customer Service Center

CUI — Controlled Unclassified Information


D

DFARS / CDI — Defense Federal Acquisition Regulation Supplement / Covered Defense Information

DMZ — De-Militarized Zone

DNS — Domain Name System

DoS — Denial of Service

DPA — Data Processing Agreement / Data Privacy Agreement / Data Protection Agreement

DPA — Data Protection Authorities (GDPR)

DR — Disaster Recovery


E

EDR — Endpoint Detection and Response

EMT — Executive Management Team

ERM — Enterprise Risk Management


G

GDPR — General Data Protection Regulation


I

I/SOC — Information / Security Operations Center

IDS — Intrusion Detection System

IO — Information Owner

IOC — Indicator of Compromise

IP — Intellectual Property

IP — Internet Protocol

IPS — Intrusion Prevention System

IR — Incident Response / Investor Relations

IRT — Incident Response Team

ISP — Internet Service Provider

IT — Information Technology


L

LE — Law Enforcement


M

M&A — Merger and Acquisition

MFA — Multi-Factor Authentication

MSA — Merchant Services Agreement


O

OT/ICS — Operational Technology / Industrial Control Systems


P

PAN — Primary Account Number

PCI — Payment Card Industry (Data Security Standard)

PFI — PCI Forensics Investigator

PHI — Protected Health Information

PIA — Privacy Impact Assessment

PII — Personally Identifiable Information

PIN — Personal Identification Number

PO — Purchase Order

POC — Point of Contact


R

RBL — Real-time blacklist


S

SEC — Security and Exchange Commission

SME — Subject Matter Expert

SSID — Service Set Identifier

SYN — Synchronization (TCP Handshake)


T

TCP — Transmission Control Protocol

TPSA — Third-Party Security Agreement

TSP / TPSP — Third-Party Service Provider


U

URL — Uniform Resource Locator


V

VLAN — Virtual Local Area Network


W

WAP — Wireless Access Point