Продължете към съдържанието
Начало » Блог » Киберречник

Киберречник

Киберречник със съкращения, абревиатури, акроними групирани в няколко раздела:

Роли и екипи

  • CISO – Chief Information Security Officer (директор по информационна сигурност)
  • CIO – Chief Information Officer
  • CSO – Chief Security Officer
  • SOC – Security Operations Center
  • CERT – Computer Emergency Response Team
  • CSIRT – Computer Security Incident Response Team
  • DFIR – Digital Forensics and Incident Response
  • Red Team – екип, симулиращ атаки
  • Blue Team – екип по защита
  • Purple Team – координация между Red и Blue Team

Системи и технологии

  • SIEM – Security Information and Event Management
  • SOAR – Security Orchestration, Automation and Response
  • EDR – Endpoint Detection and Response
  • XDR – Extended Detection and Response
  • NDR – Network Detection and Response
  • MDR – Managed Detection and Response
  • IDS – Intrusion Detection System
  • IPS – Intrusion Prevention System
  • HIDS – Host-based Intrusion Detection System
  • NIDS – Network-based Intrusion Detection System
  • DLP – Data Loss Prevention
  • PAM – Privileged Access Management
  • IAM – Identity and Access Management
  • WAF – Web Application Firewall
  • NGFW – Next Generation Firewall
  • UEBA – User and Entity Behavior Analytics
  • ZTNA – Zero Trust Network Access
  • CASB – Cloud Access Security Broker

Удостоверяване и достъп

  • MFA – Multi-Factor Authentication
  • 2FA – Two-Factor Authentication
  • SSO – Single Sign-On
  • RBAC – Role-Based Access Control
  • ABAC – Attribute-Based Access Control
  • LDAP – Lightweight Directory Access Protocol
  • SAML – Security Assertion Markup Language
  • OIDC – OpenID Connect
  • OAuth – Open Authorization

Атаки и заплахи

  • APT – Advanced Persistent Threat
  • DoS – Denial of Service
  • DDoS – Distributed Denial of Service
  • MITM – Man-In-The-Middle
  • RCE – Remote Code Execution
  • LPE – Local Privilege Escalation
  • XSS – Cross-Site Scripting
  • SQLi – SQL Injection
  • CSRF – Cross-Site Request Forgery
  • BEC – Business Email Compromise
  • IOC – Indicator of Compromise – Индикатор за компрометиране — артефакт в мрежа, показващ пробив.
  • IOA – Indicator of Attack
  • TTP – Tactics, Techniques and Procedures
  • C2 или C&C – Command and Control

Мониторинг и разследване

  • FIM – File Integrity Monitoring
  • OSINT – Open Source Intelligence – Разузнаване от публични източници.
  • CTI – Cyber Threat Intelligence
  • TI – Threat Intelligence
  • IR – Incident Response
  • PCAP – Packet Capture
  • YARA – инструмент за откриване на зловреден софтуер чрез правила

Стандарти и рамки

  • NIST – National Institute of Standards and Technology
  • CIS – Center for Internet Security
  • MITRE – MITRE Corporation
  • ATT&CK – Adversarial Tactics, Techniques and Common Knowledge
  • CVE – Common Vulnerabilities and Exposures
  • CVSS – Common Vulnerability Scoring System
  • CWE – Common Weakness Enumeration
  • OWASP – OWASP Foundation
  • PCI DSS – Payment Card Industry Data Security Standard
  • ISO 27001 – международен стандарт за информационна сигурност

Криптография

  • PKI – Public Key Infrastructure
  • CA – Certificate Authority
  • TLS – Transport Layer Security
  • SSL – Secure Sockets Layer
  • AES – Advanced Encryption Standard
  • RSA – Rivest-Shamir-Adleman
  • ECC – Elliptic Curve Cryptography
  • PGP – Pretty Good Privacy
  • HMAC – Hash-based Message Authentication Code

Облачна сигурност

  • CSPM – Cloud Security Posture Management
  • CWPP – Cloud Workload Protection Platform
  • CNAPP – Cloud-Native Application Protection Platform
  • KMS – Key Management Service

Други

  • BYOD (Bring Your Own Device): Практика, при която служители използват личните си устройства за служебни цели.

Виж още Термини в киберсигурността