A B C D E F G H I J K L M N O P Q R S T U V W X Z
*

C

Catfish

Internet predators who create fake online identities to lure people into emotional or romantic relationships for personal or financial gain.

Caveat

A marking that indicates that the data has special requirements in addition to those indicated by its classification. This term covers codewords, source codewords, releasability indicators and special-handling caveats.

CDN

Content delivery network

Certificates

1. (O) In relation to information assurance (IA), a digitally-signed representation of information that identifies the issuing authority, subscriber, and valid operational period (date of issue and expiration).(ACSI 1D) 

2. (O) On the internet, a digital file installed on a secure web server that identifies a website to establish the identity and authenticity of the company or merchant so that online shoppers can trust that the website is secure and reliable.

Certification report

An artefact of Common Criteria evaluations that outlines the outcomes of a product’s evaluation.

Change and configuration management plan

A document that describes the management of changes to the configuration of systems.

Chief executive officer (CEO)

The highest-ranking executive in a company, whose primary responsibilities include making major corporate decisions, managing the overall operations and resources of a company, acting as the main point of communication between the board of directors and corporate operations, and being the public face of the company.

Chief information security officer (CISO)

A senior executive who is responsible for coordinating communication between security and business functions as well as overseeing the application of security controls and associated security risk management processes.

CHIPs

Cyber Hygiene Improvement Program

Classification

The categorisation of information and systems according to the business impact level associated with the information or system.

Classified data

Data that would cause limited through to exceptionally grave damage to Australia’s national interests, the Australian Government generally or to an individual Commonwealth entity if compromised (i.e. data assessed as OFFICIAL: Sensitive, PROTECTED, SECRET or TOP SECRET).

Click farm

Large groups of low paid workers whose job it is to click on links, surf around target websites, perhaps signing up for newsletters and then moving on to another link. It is very hard for an automated filter to analyse this simulated traffic and detect that it is invalid as it has the same profile as a real visitor.

Click fraud

Using a compromised computer to click website ads without the user’s awareness to generate revenue for the website, or drain resources from the advertiser.

Clickbait

A form of false advertisement which uses links that are designed to attract attention and entice users to follow that link and read, view or listen to the linked content, with a defining characteristic of being deceptive, typically sensationalised or misleading.

Cloud

A network of remote servers hosted on the internet and used to store, manage, and process data in place of local servers or personal computers.

Cloud computing

Model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.

Cloud Service Provider (CSP)

A company that offers some component of cloud computing to other businesses or individuals, typically infrastructure-as-a-service (laaS), platform-as-a-service (PasS) or software-as-a-service (SaaS).

CMS

Content Management System

CNSA

Commercial National Security Algorithm

Code

A set of instructions written in a programming language that a computer can understand and execute.

Cold-call

Making an unsolicited visit or phone call to someone, often in an attempt to sell goods or services.

Command and Control (C2)

A set of organisational and technical attributes and processes that employs human, physical and information resources to solve problems and accomplish missions.

Commercial cryptographic equipment

A subset of IT equipment which contains cryptographic components.

Common Criteria (CC)

An International Organization for Standardization (ISO) standard for information security (INFOSEC) evaluations. The governing document provides a comprehensive, rigorous method for specifying security function and assurance requirements for products and systems.

Common Criteria Recognition Arrangement (CCRA)

An international agreement which facilitates the mutual recognition of Common Criteria evaluations by certificate-producing schemes.

Communications

The actions and associated activities that are used to exchange information, provide instructions, give details, etc. Communications include using such tools as phone calls, emails, user guides, in-person classes, instruction manuals, webinars, written instructions, videos, quizzes, frequently asked questions (FAQ) documents, and any other type of tool for such information exchanges.

Communications security (COMSEC)

The security controls applied to protect telecommunications from unauthorised interception and exploitation, as well as ensure the authenticity of such telecommunications

Compromise

The disclosure of information to unauthorised persons, or a violation of the security policy of a system in which unauthorised intentional or unintentional disclosure, modification, destruction or loss of an object may have occurred.

Computer

A programmable electronic device designed to accept data, perform high speed prescribed mathematical and logical operations, and display the results.

Computer accounts

Accounts used to identify computers that belong to a domain, also known as machine accounts. Computer accounts provide a means for authenticating and auditing computer access to networks and domain resources.

Computer network

Two or more interconnected devices that can exchange data.

Conduit

A tube, duct or pipe used to protect cables.

Confidentiality

The assurance that data is disclosed only to authorised entities.

Connected vehicle

Any vehicle that is connected to the internet enabling the relay of data to or from the vehicle. Connected vehicles may be connected to the internet either via embedded internet connectivity, such as a built-in modem, or via a tethered connection to the driver’s smartphone.

Connection forwarding

The use of network address translation to allow a port on a node inside a network to be accessed from outside the network. Alternatively, using a Secure Shell server to forward a Transmission Control Protocol connection to an arbitrary port on the local host.

Consent grant

An authorisation provided by a human user or administrator that permits an application to access specified data or resources on behalf of that user or an organisation.

Consumer guide

Specific configuration and usage guidance for products evaluated through the Australian Signals Directorate (ASD) cryptographic evaluation program or High Assurance evaluation program.

Content filter

A filter that examines content to assess conformance against a security policy.

Content Security Policy (CSP)

A computer security standard introduced to prevent cross-site scripting, clickjacking and other code injection attacks resulting from the execution of malicious content in a trusted web page.

Continuous monitoring plan (CONMON)

A document describing the plan for continuous monitoring and assurance in a system’s security control effectiveness.

Control plane

The administrative interface that allows for the management and orchestration of a system’s infrastructure and applications.

Cookie

A small text file that is transmitted by a website and stored in a user's web browser that is then used to identify the user and prepare customised web pages. A cookie can also be used to track a user’s activity while browsing the internet.

Corporate espionage

The improper or unlawful theft of trade secrets or other knowledge proprietary to a competitor for the purpose of achieving a competitive advantage in the marketplace.

Credential management

The enrolment, issuance, use, protection, change and revocation of credentials and other authentication artefacts.

Credential theft

A type of cybercrime that involves stealing a victim's proof of identity. Once credential theft has been successful, the attacker will have the same account privileges as the victim. Stealing credentials is the first stage in a credential-based attack.

Critical infrastructure

Physical or virtual systems and assets so vital to Australia that their incapacity or destruction would have a debilitating impact on security, national economic security, national public health or safety, or any combination of these.

Critical server

A server that provides critical network or security services. For example, Microsoft Active Directory Domain Services domain controllers, Microsoft Active Directory Certificate Services Certification Authority servers, Microsoft Active Directory Federation Services servers and Microsoft Entra Connect servers.

Cross domain solution

A system capable of implementing comprehensive data flow security policies with a high level of trust between two or more differing security domains.

Cross Domain Solution (CDS)

A system capable of implementing comprehensive data flow security policies with a high level of trust between two or more differing security domains.

Cryptocurrency

A type of digital currency that uses encryption techniques to create and regulate units of online funds and is not controlled by a bank.

Cryptographic algorithm

An algorithm used to perform cryptographic functions, such as encryption, integrity, authentication, digital signatures or key establishment.

Cryptographic application

An application designed to perform cryptographic functions.

Cryptographic equipment

A generic term for commercial cryptographic equipment and High Assurance Cryptographic Equipment.

Cryptographic hash

An algorithm (the hash function) which takes as input a string of any length (the message) and generates a fixed length string (the message digest or fingerprint) as output. The algorithm is designed to make it computationally infeasible to find any input which maps to a given digest, or to find two different messages that map to the same digest.

Cryptographic module

The set of hardware, software and firmware that implements approved cryptographic functions (including key generation) that are contained within the cryptographic boundary of the module.

Cryptographic protocol

An agreed standard for secure communication between two or more entities to provide one or more security properties, such as confidentiality, integrity, authentication or non-repudiation.

Cryptographic software

Software designed to perform cryptographic functions.

Cryptographic system

A related set of hardware, software and supporting infrastructure used for cryptographic communication, processing or storage and the administrative framework in which it operates. Cryptographic systems may be based upon traditional cryptography, post-quantum cryptography or a combination of both.

Cryptographically relevant quantum computer

A quantum computer that is capable of successfully executing attacks against traditional cryptographic systems.

Cryptography

The art or science concerning the principles, means, and methods of rendering plain information unintelligible and for restoring it back into intelligible form.

Cryptomining

A process in which transactions for various forms of cryptocurrency are verified and added to the blockchain digital ledger.

Customer

A person that an organisation has dealings with, typically via the consumption of goods or services. A customer does not necessarily need to purchase goods or services from the organisation.

Cyber attack

A deliberate act through cyberspace to manipulate, disrupt, deny, degrade or destroy computers or networks, or the information resident on them, with the effect of seriously compromising national security, stability or economic prosperity. Note: there are multiple global definitions of what constitutes a cyber attack.

Cyber bullying

A form of harassment using electronic means, such as the internet (particularly social media sites) or other digital spaces.

Cyber defence

Defensive activity designed to protect information and systems against offensive cyber operations.

Cyber espionage

Malicious cyber activity by state or non-state entities to covertly collect information from an adversary’s computer systems for intelligence purposes. It can include theft for commercial advantage.

Cyber Hygiene Improvement Program (CHIPS)

ASD's ACSC's open-source intelligence capability that discovers, identifies and regularly measures the cyber posture and hygiene of internet-facing systems, using objective and data-driven approaches. The program relies on a mixture of open-source, commercial and directly collected data.

Cyber Incident Management Arrangements (CIMA)

The CIMA provides Australian governments with guidance on how they will collaborate in response to, and reduce the harm associated with, national cyber incidents.

Cyber operations

Offensive and defensive activities designed to achieve effects in or through cyberspace.

Cyber resilience

The ability to adapt to disruptions caused by cyber security incidents while maintaining continuous business operations. This includes the ability to detect, manage and recover from cyber security incidents.

Cyber safety

The safe and responsible use of information and communication technologies.

Cyber security

Measures used to protect the confidentiality, integrity and availability of information technology (IT) and operational technology (OT) systems, applications and data.

Cyber security documentation

An organisation’s cyber security strategy; system-specific cyber security documentation; and any supporting diagrams, plans, policies, processes, procedures and registers.

Cyber security event

An occurrence of a system, service or network state indicating a possible breach of security policy, failure of safeguards or a previously unknown situation that may be relevant to security.

Cyber security incident

An unwanted or unexpected cyber security event, or a series of such events, that has either compromised business operations or has a significant probability of compromising business operations.

Cyber security incident responder

A cyber security expert with the skills to rapidly address cyber security incidents or events within an organisation. In the role of a first responder, they use a host of tools to find the root cause of a cyber security incident, limit the damage and significantly reduce he likelihood of it occuring again.

Cyber security incident response plan (CSIRP)

A document that describes the plan for responding to cyber security incidents.

Cyber stalking

The use of the internet or other electronic means to stalk or harass an individual, group or organisation.

Cyber supply chain

The suppliers, manufacturers, distributors and retailers involved in the design, manufacture, storage, delivery, installation, operation, maintenance and decommissioning of products and services utilised within an organisation's IT and OT environments.

Cyber threat

Any circumstance or event with the potential to harm systems, applications or data

Cyber warfare

The use of computer technology to disrupt the activities of a state or organisation, especially the deliberate disruption, manipulation or destruction of information systems for strategic, political or military purposes.

Cyber weapon

A computer code used, or designed to be used, to cause physical, functional, or mental harm to structures, systems, or people. The term is contentious among the international policy and legal communities, and there is an absence of agreement surrounding its connotations and implications. See also exploit.

Cybercrime

Crimes directed at computers, such as illegally modifying electronic data or seeking a ransom to unlock a computer affected by malicious software. It also includes crimes where computers facilitate an existing offence, such as online fraud or online child sex offences.

Cyberspace

The interdependent network of information technology infrastructures which includes the internet, telecommunications networks, computer systems, and embedded processors and controllers in critical industries.