Skip to content

Latest commit

 

History

History
41 lines (40 loc) · 5.28 KB

File metadata and controls

41 lines (40 loc) · 5.28 KB

Common Cyberecurity Terminologies & Definitions

  • Authenticity: The assurance that information or a person’s identity is genuine and has not been altered or falsified.
  • Availability: Ensuring that systems, applications, and data are accessible to authorized users when needed, preventing disruptions or downtime.
  • Black Hat: A hacker who engages in malicious or illegal activities to exploit vulnerabilities for personal, financial, or ideological gain.
  • Black Team: Refers more on hardware hacking/pentesting.
  • Blue Team: A defensive security team responsible for protecting an organization’s systems by monitoring, detecting, and mitigating cyber threats.
  • Compliance: Adhering to legal, regulatory, and industry-specific cybersecurity standards and policies (e.g., GDPR, HIPAA, ISO 27001).
  • Confidential: Any data leakage, loss or damage of which can cause harm to data originator, owner, company or customer.
  • Confidentiality: The principle of restricting access to sensitive information to only authorized individuals to prevent unauthorized disclosure.
  • Crown Jewel: The most critical and valuable assets of an organization that require the highest level of security protection.
  • DLP (Data Loss Prevention): Technologies and policies designed to prevent unauthorized access, sharing, or loss of sensitive data.
  • Dumpster Diving: A hacking technique where attackers search through discarded materials (e.g., trash, recycling bins) to find sensitive information.
  • EDR: A security solution that continuously monitors and responds to threats on endpoint devices such as computers and mobile devices.
  • Firewall: A security system that monitors and filters network traffic to block unauthorized access while allowing legitimate communication.
  • Grey Hat: A hacker who may engage in activities that are legally or ethically questionable but does so with good intentions, such as finding security flaws without permission.
  • HUMINT: The collection of intelligence through human interactions, often involving social engineering techniques in cybersecurity.
  • Integrity: Ensuring that data remains unaltered, accurate, and trustworthy, preventing unauthorized modifications or tampering.
  • Malware: Malicious software designed to harm, exploit, or gain unauthorized access to systems, including viruses, worms, ransomware, and trojans.
  • Non-Repudiation: The ability to ensure that an individual cannot deny the authenticity of their actions, such as sending a message or approving a transaction.
  • OSINT: The practice of gathering intelligence from publicly available sources, such as social media, websites, and public records.
  • Patch: A software update that fixes security vulnerabilities, bugs, or improves functionality to protect against cyber threats.
  • Penetration Testing: A security assessment where ethical hackers simulate cyberattacks to identify and address security weaknesses.
  • Phishing: A cyberattack that tricks individuals into revealing sensitive information, typically through deceptive emails, messages, or fake websites.
  • Public: Freely shared information.
  • Purple Team: A collaborative effort between red (attack) and blue (defense) teams to improve an organization’s overall security posture.
  • Red Team: A group of ethical hackers that simulate real-world cyberattacks to test and strengthen an organization’s defenses.
  • Risk: The potential for harm or loss resulting from a cyber threat exploiting a vulnerability in a system.
  • Scareware: Malicious software that tricks users into believing their system is infected, coercing them into downloading more malware or paying for fake security solutions.
  • Sensitive: Any data leakage, loss or damage of which can cause significant harm to data originator, owner, company or customer.
  • SIEM (Security Information and Event Management): A security system that collects, analyzes, and responds to security threats across an organization’s IT infrastructure.
  • SIGINT (Signals Intelligence): Intelligence gathered from electronic signals and communications, often used in cybersecurity and military operations.
  • Social Engineering: Psychological manipulation of people to trick them into revealing confidential information or performing security-compromising actions.
  • Spam: Unsolicited, often deceptive messages sent in bulk, commonly used for advertising, phishing, or spreading malware.
  • Spyware: Malicious software that secretly collects user information, such as keystrokes, passwords, and browsing habits, without consent.
  • Threat Intel: Information about cyber threats that helps organizations predict, prevent, and respond to security incidents.
  • Threat: Any potential danger or malicious activity that can exploit vulnerabilities and cause harm to systems, networks, or data.
  • Virus: A type of malware that replicates itself by attaching to files and spreading when executed, often causing damage to systems.
  • Vulnerability: A weakness in a system, application, or process that can be exploited by attackers to gain unauthorized access or cause harm.
  • White Hat: An ethical hacker who uses their skills to improve security by identifying and fixing vulnerabilities in a legal and responsible manner.
  • XDR (Extended Detection and Response): A security solution that integrates data across multiple layers (network, endpoint, cloud, etc.) to provide advanced threat detection and response.