75
Annex 2
GLOSSARY
CyberInvest – a £6.5m industry
and government scheme to support
cutting-edge cyber security research
and protect the UK in cyberspace.
Data breach – the unauthorised movement
or disclosure of information on a network
to a party who is not authorised to have
access to, or see, the information.
Cyber-physical system – systems with
integrated computational and physical
components; ‘smart’ systems.
Domain – a domain name locates
an organisation or other entity on the
Internet and corresponds to an Internet
Protocol (IP) address.
Cyber resilience – the overall ability of
systems and organisations to withstand
cyber events and, where harm is caused,
recover from them.
Cyber security – the protection of internet
connected systems (to include hardware,
software and associated infrastructure),
the data on them, and the services they
provide, from unauthorised access, harm
or misuse. This includes harm caused
intentionally by the operator of the system,
or accidentally, as a result of failing to
follow security procedures or being
manipulated into doing so.
Cyber Security Challenge – competitions
encouraging people to test their skills and
to consider a career in cyber.
Cyberspace – the interdependent network
of information technology infrastructures that
includes the Internet, telecommunications
networks, computer systems, internet
connected devices and embedded
processors and controllers. It may also refer to
the virtual world or domain as an experienced
phenomenon, or abstract concept.
Cyber threat – anything capable of
compromising the security of, or causing
harm to, information systems and internet
connected devices (to include hardware,
software and associated infrastructure), the
data on them and the services they provide,
primarily by cyber means.
Domain Name System (DNS) – a naming
system for computers and network services
based on a hierarchy of domains.
Doxing – the practice of researching,
or hacking, an individual’s personally
identifiable information on the Internet,
then publishing it.
e-commerce – electronic commerce. Trade
conducted, or facilitated by, the Internet.
Encryption – cryptographic transformation
of data (called ‘plaintext’) into a form (called
‘cipher text’) that conceals the data’s
original meaning, to prevent it from being
known or used.
Horizon scanning – a systematic
examination of information to identify
potential threats, risks, emerging issues
and opportunities allowing for better
preparedness and the incorporation of
mitigation and exploitation into the
policy-making process.
Incident management – the management
and coordination of activities to investigate,
and remediate, an actual or potential
occurrence of an adverse cyber event
that may compromise or cause harm to
a system or network.
National Cyber Security Strategy 2016