Confirmation that stakeholder requirements for the intended use of operating systems, applications, IT equipment or OT equipment have been met.
Confirmation that stakeholder requirements for the intended use of operating systems, applications, IT equipment or OT equipment have been met.
An access method for cyber operations.
Confirmation that design or compliance requirements for operating systems, applications, IT equipment or OT equipment have been met.
Network devices and other IT equipment grouped logically based on resources, security or business requirements instead of their physical location.
A security measure designed to prevent known exploitation attempts against known vulnerabilities in web applications, typically via the use of a network-based intrusion prevent system or a web application firewall.
A network that maintains privacy through a tunnelling protocol and security procedures. VPNs may use encryption to protect network traffic.
Simulation of hardware or software resources.
A type of malware. Viruses spread on their own by attaching code to other programs, or copying themselves across systems and networks.
A type of media, such as random-access memory, which gradually loses its data when power is removed.
A weakness in a system’s security requirements, design, implementation or operation that could be accidentally triggered or intentionally exploited and result in a violation of the system’s security policy.
A security assessment involving a review of a system’s architecture or an in-depth hands-on assessment to identify as many potential vulnerabilities as possible.
The process of identifying, prioritising and responding to vulnerabilities.
A security assessment using tools to conduct automated checks for known vulnerabilities in a system and its environment.