Киберречник със съкращения, абревиатури, акроними групирани в няколко раздела:
Роли и екипи
- CISO – Chief Information Security Officer (директор по информационна сигурност)
- CIO – Chief Information Officer
- CSO – Chief Security Officer
- SOC – Security Operations Center
- CERT – Computer Emergency Response Team
- CSIRT – Computer Security Incident Response Team
- DFIR – Digital Forensics and Incident Response
- Red Team – екип, симулиращ атаки
- Blue Team – екип по защита
- Purple Team – координация между Red и Blue Team
Системи и технологии
- SIEM – Security Information and Event Management
- SOAR – Security Orchestration, Automation and Response
- EDR – Endpoint Detection and Response
- XDR – Extended Detection and Response
- NDR – Network Detection and Response
- MDR – Managed Detection and Response
- IDS – Intrusion Detection System
- IPS – Intrusion Prevention System
- HIDS – Host-based Intrusion Detection System
- NIDS – Network-based Intrusion Detection System
- DLP – Data Loss Prevention
- PAM – Privileged Access Management
- IAM – Identity and Access Management
- WAF – Web Application Firewall
- NGFW – Next Generation Firewall
- UEBA – User and Entity Behavior Analytics
- ZTNA – Zero Trust Network Access
- CASB – Cloud Access Security Broker
Удостоверяване и достъп
- MFA – Multi-Factor Authentication
- 2FA – Two-Factor Authentication
- SSO – Single Sign-On
- RBAC – Role-Based Access Control
- ABAC – Attribute-Based Access Control
- LDAP – Lightweight Directory Access Protocol
- SAML – Security Assertion Markup Language
- OIDC – OpenID Connect
- OAuth – Open Authorization
Атаки и заплахи
- APT – Advanced Persistent Threat
- DoS – Denial of Service
- DDoS – Distributed Denial of Service
- MITM – Man-In-The-Middle
- RCE – Remote Code Execution
- LPE – Local Privilege Escalation
- XSS – Cross-Site Scripting
- SQLi – SQL Injection
- CSRF – Cross-Site Request Forgery
- BEC – Business Email Compromise
- IOC – Indicator of Compromise – Индикатор за компрометиране — артефакт в мрежа, показващ пробив.
- IOA – Indicator of Attack
- TTP – Tactics, Techniques and Procedures
- C2 или C&C – Command and Control
Мониторинг и разследване
- FIM – File Integrity Monitoring
- OSINT – Open Source Intelligence – Разузнаване от публични източници.
- CTI – Cyber Threat Intelligence
- TI – Threat Intelligence
- IR – Incident Response
- PCAP – Packet Capture
- YARA – инструмент за откриване на зловреден софтуер чрез правила
Стандарти и рамки
- NIST – National Institute of Standards and Technology
- CIS – Center for Internet Security
- MITRE – MITRE Corporation
- ATT&CK – Adversarial Tactics, Techniques and Common Knowledge
- CVE – Common Vulnerabilities and Exposures
- CVSS – Common Vulnerability Scoring System
- CWE – Common Weakness Enumeration
- OWASP – OWASP Foundation
- PCI DSS – Payment Card Industry Data Security Standard
- ISO 27001 – международен стандарт за информационна сигурност
Криптография
- PKI – Public Key Infrastructure
- CA – Certificate Authority
- TLS – Transport Layer Security
- SSL – Secure Sockets Layer
- AES – Advanced Encryption Standard
- RSA – Rivest-Shamir-Adleman
- ECC – Elliptic Curve Cryptography
- PGP – Pretty Good Privacy
- HMAC – Hash-based Message Authentication Code
Облачна сигурност
- CSPM – Cloud Security Posture Management
- CWPP – Cloud Workload Protection Platform
- CNAPP – Cloud-Native Application Protection Platform
- KMS – Key Management Service
Други
- BYOD (Bring Your Own Device): Практика, при която служители използват личните си устройства за служебни цели.
Виж още Термини в киберсигурността