A B C D E F G H I J K L M N O P Q R S T U V W X Z
*

A

AACA

ASD-Approved Cryptographic Algorithm

AACP

ASD-Approved Cryptographic Protocol

ACA

Australasian Certification Authority

Access control

The process of granting or denying requests for access to systems, applications and data. Can also refer to the process of granting or denying requests for access to facilities.

Access Cross Domain Solution

A system permitting access to multiple security domains from a single client device.

Account harvesting

The illegal practice of collecting email accounts from data in the public domain or by using software to search for email addresses stored locally on a computer. Account harvesting may be used for spamming. See also spamming.

Accountable material

Material that requires the strictest control over its access and movement. Accountable material includes TOP SECRET data, some types of caveated data and any data designated as accountable material by its originator.

ACSI

Australian Communications Security Instruction

Active defence

The principle of proactively implementing a spectrum of security measures to strengthen a network or system to make it more robust against attack. Active defence is separate from offensive cyber operations, passive defence or network hardening. Note that some references to active defence focus on employing limited offensive action and counterattacks – commonly referred to as ‘hacking back’. The term 'active defence' is not synonymous with ‘hacking back’, so these terms should not be used interchangeably.

Ad blockers

Software that prevents advertisements from appearing with the content the user is intentionally viewing.

Advanced Persistent Threat (APT)

See definition of malicious actor.

Advisory

An ASD ACSC publication that provides timely information and advice about current security issues, vulnerabilities, and exploits.

Adware

An application that displays advertisements that can be installed legitimately as  part of another application or service, or illegitimately without the consent of the system user or owner.

AES

Advanced Encryption Standard

After market devices

A secondary market of an industry, concerned with the manufacturing, remanufacturing, distribution, retailing, and installation of all parts, equipment, and accessories, after the sale of the device by the original equipment manufacturer to the consumer.

Air gap

A network security measure designed to ensure that a network is physically isolated from other networks. This intends to make the isolated network secure by ensuring it does not connect to other less secure networks, such as the internet.

Alert

An ASD ACSC publication that provides timely notification concerning threats or activities that have the potential to impact individuals, businesses, organisations, government, devices, peripherals, networks or infrastructure.

Antivirus software

Software that is designed to detect, stop and remove viruses and other kinds of malicious software.

App

Short for ‘application’ and usually referring to mobile phone apps. Can also refer to a desktop or web applications.

Application

A software program or group of software programs designed for end users. Examples of an application include a word processor, web browser, an email client, a media player and a file viewer. The collective noun application software refers to all applications collectively. This contrasts with system software, which is mainly involved with running the computer.

Application control

An approach that permits only explicitly approved applications and other executable content to execute on systems.

Archive

A place where an accumulation of data is stored. It could be disk storage, a flash drive, an online backup service, or online collaboration, etc.

Artificial intelligence (AI)

The simulation of intelligence processes by machines, especially computer systems, which include learning, reasoning, and self-correction. Particular applications of AI include threat identification, expert systems, speech recognition and machine vision.

Artificial intelligence application

An application that contains a reasonable degree of artificial intelligence (AI) functionality. This includes AI-enabled applications, AI-powered applications and AI-driven applications. 

Artificial intelligence model

A computational model that has been trained using data to recognise patterns; predict, classify or make decisions; or generate outputs in response to inputs, using machine-learning or AI techniques. 

Artificial intelligence-driven application

An application that uses AI to autonomously control most of its decisions and behaviour. Such applications typically have low human involvement, with decisions being driven by AI. Without AI functionality, such applications are unable to operate as intended.

Artificial intelligence-enabled application

An application that uses AI for secondary or supporting functionality. Such applications typically have high human involvement, with decisions led by humans and informed by AI insights. Without AI functionality, such applications can still function effectively.

Artificial intelligence-powered application

An application that uses AI for its primary functionality. Such applications typically have moderate human involvement, with decisions shared between humans and AI. Without AI functionality, such applications can function, but only in a severely limited capacity.

Assets

In the context of technology, an overarching term used to refer to applications, IT equipment, OT equipment, services and data. Such assets may also be referred to as technology assets.

Asymmetric cryptographic algorithms

Cryptographic algorithms where two different keys are used, commonly a private and a public key. Also known as 'public key cryptographic algorithms'.

ATA

Advanced Technology Attachment

Attack surface

The reachable points through which a system could be accessed, manipulated or compromised. This can include hardware and software interfaces, network services, and application programming interfaces.

Attribution

The process of assessing the source, perpetrator or sponsor of malicious activity. Statements of attribution often use probabilistic language and indicate the level of confidence in the assessment.

Audit log

A chronological record of system activities including records of system access and operations performed. See also event log.

Audit trail

A chronological record that reconstructs the sequence of activities surrounding, or leading to, a specific operation, procedure or event.

Australian Eyes Only (AUSTEO) data

Data not to be passed to, or accessed by, foreign nationals.

Australian Government Access Only (AGAO) data

Data not to be passed to, or accessed by, foreign nationals, with the exception of seconded foreign nationals.

Australian Information Security Evaluation Facility (AISEF)

A program that evaluates products in order to protect systems and data against cyber threats. These evaluation activities are certified by the Australian Certification Authority.

Australian Information Security Evaluation Program (AISEP)

A program under which evaluations are performed by impartial bodies against the Common Criteria. The results of these evaluations are then certified by the Australian Certification Authority within the Australian Signals Directorate (ASD).

Australian Signals Directorate (ASD)

An Australian government statutory agency responsible for foreign intelligence, cyber security and offensive cyber operations in support of the Australian Government and the Australian Defence Force.

Australian Signals Directorate-approved cryptography

Cryptography suitably implemented using an ASD-Approved Cryptographic Algorithm, an ASD-Approved Cryptographic Protocol, a high assurance cryptographic algorithm or a high assurance cryptographic protocol. 

Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)

The Australian Government's lead for cyber security. The ASD's ACSC is part of the Australian Signals Directorate.

Authentication

Verifying the identity of a user as a prerequisite to allowing access to a system and its resources.

Authentication artefact

A digital object created or issued during authentication that represents the authenticated identity of a user, or maintains an authenticated session. For example, authentication assertions, authentication tokens and session cookies.

Authentication Header (AH)

A protocol used in Internet Protocol Security (IPsec) that provides data integrity and data origin authenticity but not confidentiality.

Authorisation package

A cyber security documentation package that includes a system’s system security plan, cyber security incident response plan, change and configuration management plan, continuous monitoring plan, security assessment report, and plan of action and milestones. The authorisation package is provided to a system’s authorising officer to assist them in making an informed decision as to whether the security risks associated with the system’s operation are acceptable or not.

Authorisation to operate

The official management decision by a senior executive or senior executives to authorise a system to operate based on the acceptance of the security risks associated with its operation.

Authorising officer

An executive with the authority to formally accept the security risks associated with the operation of a system and to authorise it to operate.

Availability

The assurance that systems are accessible and useable by authorised entities when required.