ASD-Approved Cryptographic Algorithm
ASD-Approved Cryptographic Algorithm
ASD-Approved Cryptographic Protocol
Australasian Certification Authority
The process of granting or denying requests for access to systems, applications and data. Can also refer to the process of granting or denying requests for access to facilities.
A system permitting access to multiple security domains from a single client device.
The illegal practice of collecting email accounts from data in the public domain or by using software to search for email addresses stored locally on a computer. Account harvesting may be used for spamming. See also spamming.
Material that requires the strictest control over its access and movement. Accountable material includes TOP SECRET data, some types of caveated data and any data designated as accountable material by its originator.
Australian Communications Security Instruction
The principle of proactively implementing a spectrum of security measures to strengthen a network or system to make it more robust against attack. Active defence is separate from offensive cyber operations, passive defence or network hardening. Note that some references to active defence focus on employing limited offensive action and counterattacks – commonly referred to as ‘hacking back’. The term 'active defence' is not synonymous with ‘hacking back’, so these terms should not be used interchangeably.
Software that prevents advertisements from appearing with the content the user is intentionally viewing.
See definition of malicious actor.
An ASD ACSC publication that provides timely information and advice about current security issues, vulnerabilities, and exploits.
An application that displays advertisements that can be installed legitimately as part of another application or service, or illegitimately without the consent of the system user or owner.
Advanced Encryption Standard
A secondary market of an industry, concerned with the manufacturing, remanufacturing, distribution, retailing, and installation of all parts, equipment, and accessories, after the sale of the device by the original equipment manufacturer to the consumer.
A network security measure designed to ensure that a network is physically isolated from other networks. This intends to make the isolated network secure by ensuring it does not connect to other less secure networks, such as the internet.
An ASD ACSC publication that provides timely notification concerning threats or activities that have the potential to impact individuals, businesses, organisations, government, devices, peripherals, networks or infrastructure.
Software that is designed to detect, stop and remove viruses and other kinds of malicious software.
Short for ‘application’ and usually referring to mobile phone apps. Can also refer to a desktop or web applications.
A software program or group of software programs designed for end users. Examples of an application include a word processor, web browser, an email client, a media player and a file viewer. The collective noun application software refers to all applications collectively. This contrasts with system software, which is mainly involved with running the computer.
An approach that permits only explicitly approved applications and other executable content to execute on systems.
A place where an accumulation of data is stored. It could be disk storage, a flash drive, an online backup service, or online collaboration, etc.
The simulation of intelligence processes by machines, especially computer systems, which include learning, reasoning, and self-correction. Particular applications of AI include threat identification, expert systems, speech recognition and machine vision.
An application that contains a reasonable degree of artificial intelligence (AI) functionality. This includes AI-enabled applications, AI-powered applications and AI-driven applications.
A computational model that has been trained using data to recognise patterns; predict, classify or make decisions; or generate outputs in response to inputs, using machine-learning or AI techniques.
An application that uses AI to autonomously control most of its decisions and behaviour. Such applications typically have low human involvement, with decisions being driven by AI. Without AI functionality, such applications are unable to operate as intended.
An application that uses AI for secondary or supporting functionality. Such applications typically have high human involvement, with decisions led by humans and informed by AI insights. Without AI functionality, such applications can still function effectively.
An application that uses AI for its primary functionality. Such applications typically have moderate human involvement, with decisions shared between humans and AI. Without AI functionality, such applications can function, but only in a severely limited capacity.
In the context of technology, an overarching term used to refer to applications, IT equipment, OT equipment, services and data. Such assets may also be referred to as technology assets.
Cryptographic algorithms where two different keys are used, commonly a private and a public key. Also known as 'public key cryptographic algorithms'.
Advanced Technology Attachment
The reachable points through which a system could be accessed, manipulated or compromised. This can include hardware and software interfaces, network services, and application programming interfaces.
The process of assessing the source, perpetrator or sponsor of malicious activity. Statements of attribution often use probabilistic language and indicate the level of confidence in the assessment.
A chronological record of system activities including records of system access and operations performed. See also event log.
A chronological record that reconstructs the sequence of activities surrounding, or leading to, a specific operation, procedure or event.
Data not to be passed to, or accessed by, foreign nationals.
Data not to be passed to, or accessed by, foreign nationals, with the exception of seconded foreign nationals.
A program that evaluates products in order to protect systems and data against cyber threats. These evaluation activities are certified by the Australian Certification Authority.
A program under which evaluations are performed by impartial bodies against the Common Criteria. The results of these evaluations are then certified by the Australian Certification Authority within the Australian Signals Directorate (ASD).
An Australian government statutory agency responsible for foreign intelligence, cyber security and offensive cyber operations in support of the Australian Government and the Australian Defence Force.
Cryptography suitably implemented using an ASD-Approved Cryptographic Algorithm, an ASD-Approved Cryptographic Protocol, a high assurance cryptographic algorithm or a high assurance cryptographic protocol.
The Australian Government's lead for cyber security. The ASD's ACSC is part of the Australian Signals Directorate.
Verifying the identity of a user as a prerequisite to allowing access to a system and its resources.
A digital object created or issued during authentication that represents the authenticated identity of a user, or maintains an authenticated session. For example, authentication assertions, authentication tokens and session cookies.
A protocol used in Internet Protocol Security (IPsec) that provides data integrity and data origin authenticity but not confidentiality.
A cyber security documentation package that includes a system’s system security plan, cyber security incident response plan, change and configuration management plan, continuous monitoring plan, security assessment report, and plan of action and milestones. The authorisation package is provided to a system’s authorising officer to assist them in making an informed decision as to whether the security risks associated with the system’s operation are acceptable or not.
The official management decision by a senior executive or senior executives to authorise a system to operate based on the acceptance of the security risks associated with its operation.
An executive with the authority to formally accept the security risks associated with the operation of a system and to authorise it to operate.
The assurance that systems are accessible and useable by authorised entities when required.