A B C D E F G H I J K L M N O P Q R S T U V W X Z
*

D

Dark web

Websites not indexed by internet search engines and are only accessible through specialty networks, such as The Onion Router (Tor). Dark websites are not stumbled upon by everyday users as the operators often want to remain anonymous and their activities remaining covert. The dark web is a subset of the deep web. See also deep web.

Data

The basic element that can be processed or produced by a computer to convey information.

Data at rest

Data that resides on media or a system.

Data breach

The unauthorised movement or disclosure of sensitive private or business information.

Data dump

A large amount of data transferred from one system or location to another.

Data in transit

Data that is being communicated across a communication medium.

Data protection

Data protection is the process of safeguarding important information from corruption, compromise or loss.

Data repository

A location where data is stored, managed and made available for use.

Data security

Measures used to protect the confidentiality, integrity and availability of data.

Data spill

The accidental or deliberate exposure of data into an uncontrolled or unauthorised environment, or to entities without a need-to-know.

DBMS

Database management system

DCS

Distributed control system

Declassification

A process where information is reduced to an OFFICIAL level and an administrative decision is made to authorise its release into the public domain.

Decommission

The process of removing something from operational service.

Decryption

The act of decoding encrypted messages.

Deep web

The part of the internet not indexed by search engines and includes password-protected and paywalled websites, databases and networks. See also dark web.

Default passwords

When a device needs a username and password to log in, a default password is provided to allow the device to be accessed during initial setup or after resetting to factory defaults.

Defence in depth

The act of implementing multiple layers of security controls in a system to maintain overall security should a security control fail or a vulnerability be exploited in a localised area.

Degausser

A device or magnet assembly which generates a coercive magnetic force for the purpose of degaussing magnetic storage devices.

Degaussing

A process for reducing the magnetisation of a magnetic storage device to zero by applying a reverse magnetic force, rendering any previously stored information unreadable.

Demilitarised zone (DMZ)

A small network with one or more servers that is kept separate from the core network, either on the outside of the firewall, or as a separate network protected by the firewall. Demilitarised zones usually provide information to less trusted networks, such as the internet.

Denial of service (DoS)

When legitimate users are denied access to computer services or resources, usually due to the service being overloaded with requests.

Denial-of-service (DoS) attack

An action taken by an adversary to prevent legitimate access to online services (typically a website), for example, by consuming the amount of available bandwidth or the processing capacity of the server hosting the online service.

Device access control application

An application that can be used to prevent removable media and mobile devices from being connected to workstations and servers via external communication interfaces.

Device access control software

Software used on a system to restrict access to communications ports. It can block all access to a communications port or allow access based on device types, manufacturer’s identifications, or unique device identifiers.

DH

Diffie-Hellman

Dictionary attack

Where cyber actors attempting to access a password-protected system or device apply ‘password dictionaries’ or long lists of the most commonly-used passwords and character combinations systematically against a password entry in order to guess it and break into a system.

Digital certificate

An electronic document used to identify an entity, like an individual, server, system, company, and to associate a public key with that entity. A digital certificate is issued by a Certification Authority (CA) and is digitally signed by that authority.

Digital footprint

The unique set of traceable activities, actions, contributions and communications – in aggregation or isolation – that are manifested on the internet or on digital devices.

Digital preservation

The coordinated and ongoing set of processes and activities that ensure long-term, error-free storage of digital information, with means for retrieval and interpretation, for the time span the information is required

Digital signature

A cryptographic process that allows the proof of the source (with non-repudiation) and the verification of the integrity of that data.

Diode

A device that allows data to flow in only one direction.

Disaster recovery

Combining a set of policies, tools and procedures to enable the recovery or continuation of vital technology infrastructure and systems following a natural or human-induced disaster. Disaster recovery focuses on the IT or technology systems supporting critical business functions, as opposed to business continuity

Distributed-denial-of-service (DDoS) attack

A Denial-of-Service (DoS) where the source is comprised of multiple unique Internet Protocol (IP) addresses used to flood the bandwidth or resources of a targeted system or network. By doing this, the targeted system or network is rendered inaccessible to its users.

DMA

Direct Memory Access

Domain

An environment that includes system resources and entities with the right to access resources as defined by a common security policy, model, or architecture.(ACSI 1D) (O) See also security domain.

Domain Name System (DNS)

The naming system that translates domain names into IP addresses.

Domain-based Message Authentication, Reporting and Conformance (DMARC)

An email authentication protocol designed to give email domain owners the ability to protect their domain from unauthorised use, commonly known as email spoofing.

DomainKeys Identified Mail (DKIM)

A system for authenticating emails that works with modern Message Transfer Agent systems. This resource was created to help fight spam, and uses a digital signature to help email recipients determine whether an email is legitimate.

Downloader

A type of Trojan that downloads other malware onto a computer. The downloader needs to connect to the internet to download the files.

Doxing (also known as doxxing)

Obtaining and publishing private or personally identifiable information (PII) about an individual on the internet. Information can be obtained through a range of methods including network compromise, social engineering, data breaches, or research.

Drive-by download attacks

Refers to the unintentional download of malicious code to your computer or mobile device that leaves you open to a cyberattack. You don't have to click on anything, press download, or open a malicious email attachment to become infected.

Driver

Software interfacing a hardware device with an operating system.

Dropper

A type of Trojan that installs other malware files onto a computer. The other malware is included within the Trojan file, and does not require connection to the internet in order to download.

DSA

Digital Signature Algorithm

Dual-stack network device

A network that implements both Internet Protocol version 4 (IPv4) and Internet Protocol version 6 (IPv6) protocol stacks.