← Resource Index
Reference
Cybersecurity Acronyms Guide
A comprehensive, categorized guide to common cybersecurity terminology.
In plain English: a free, curated list of resources for people starting or growing a career in cybersecurity.
Welcome to the comprehensive guide to cybersecurity acronyms. This resource helps you understand the common terminology used in the cybersecurity field. Whether you're a student, professional, or enthusiast, this guide will help you navigate the complex world of cybersecurity terminology.
Access & Authentication
| Acronym | Full Term | Definition |
|---|---|---|
| ACL | Access Control List | List defining permissions for accessing resources |
| IAM | Identity and Access Management | Controls user access and identity verification |
| MFA | Multi-Factor Authentication | Requires multiple forms of verification to access systems |
| SSO | Single Sign-On | Allows users to access multiple applications with one login |
| U2F | Universal 2nd Factor | Standard for two-factor authentication using hardware tokens |
| PAM | Privileged Access Management | Controls and monitors access to critical systems and data |
| DAC | Discretionary Access Control | Access control where owners decide permissions |
| MAC | Mandatory Access Control | Access control based on policies and classifications |
| RBAC | Role-Based Access Control | Access restricted based on organizational roles |
Security Systems & Tools
| Acronym | Full Term | Definition |
|---|---|---|
| IDS | Intrusion Detection System | Monitors network traffic for suspicious activity |
| IPS | Intrusion Prevention System | Blocks or prevents detected threats from causing harm |
| SIEM | Security Information and Event Management | System for managing and analyzing security alerts |
| WAF | Web Application Firewall | Protects web applications by filtering HTTP traffic |
| EDR | Endpoint Detection and Response | Monitors and responds to threats on end-user devices |
| DLP | Data Loss Prevention | Measures to protect data from being lost or stolen |
| FIM | File Integrity Monitoring | Monitors files to detect unauthorized changes |
| SOAR | Security Orchestration, Automation, and Response | Tools that allow organizations to streamline security operations |
Cloud & Modern Infrastructure
| Acronym | Full Term | Definition |
|---|---|---|
| SaaS | Software as a Service | Software hosted by a third-party provider |
| IaaS | Infrastructure as a Service | Virtualized computing resources provided over the cloud |
| PaaS | Platform as a Service | Platform for application development provided as a service |
| CSP | Cloud Service Provider | Company offering cloud-based infrastructure (e.g., AWS, Azure) |
| CSPM | Cloud Security Posture Management | Tools for managing and securing cloud infrastructure |
| BYOD | Bring Your Own Device | Policy allowing employees to use personal devices for work |
| CASB | Cloud Access Security Broker | Security checkpoint between cloud users and cloud applications |
Threats & Vulnerabilities
| Acronym | Full Term | Definition |
|---|---|---|
| DDoS | Distributed Denial of Service | Attack that floods a network to disrupt availability |
| RAT | Remote Access Trojan | Malware providing remote control over an infected device |
| XSS | Cross-Site Scripting | Vulnerability allowing script injection into webpages |
| SQLi | SQL Injection | Attack exploiting vulnerabilities in database queries |
| CVE | Common Vulnerabilities and Exposures | List of publicly known security vulnerabilities |
| TTP | Tactics, Techniques, and Procedures | Methods used by attackers to achieve objectives |
| APT | Advanced Persistent Threat | A prolonged and targeted cyberattack (usually state-sponsored) |
Standards, GRC & Education
| Acronym | Full Term | Definition |
|---|---|---|
| NIST | National Institute of Standards and Technology | U.S. agency developing technology and security standards |
| GRC | Governance, Risk, and Compliance | Framework for managing organizational risks and rules |
| CISO | Chief Information Security Officer | Senior executive responsible for information security |
| SOC | Security Operations Center | Centralized unit for monitoring security events |
| Certs | Certifications | Professional credentials verifying skillsets (e.g., Security+, CISSP) |
| BIA | Business Impact Analysis | Evaluates effects of disruptions on operations |
Contributing
Feel free to contribute to this guide by suggesting new acronyms, updating definitions, or improving categorization.
Note
- Acronyms may have different meanings in different contexts.
- Some terms may overlap multiple categories.
- Definitions are simplified for general understanding.
Last updated: November 2024