Publications of the Prime Minister’s Office 2024:13 8 Concepts and definitions The terms and definitions set out below describe concepts used in this document. These terms have been used in order to explain the strategy more concisely and avoid repetition, and the definitions are provided to help the reader understand the intended context. The recognised need to update terminology related to concepts designated by cybersecurity terms used in this strategy has caused some divergence from the accounts that are already available in existing glossaries, such as the TEPA Term Bank or the Vocabulary of Cyber Security. This divergence arises in particular from the need for concepts that are internationally harmonised, and the need to include concepts that are now used in EU regulation. Attribution Detecting and locating a party conducting a hostile cyber operation, and identifying that party, through an analytical process using various information sources. Nationally this process involves both technical analysis and the duties of public authorities, and discretion related to foreign and security policy. Attribution is the outcome of the analysis process, regardless of whether that outcome is public or non-public. Attribution is often a condition for holding a party legally or politically liable, for measures in accordance with international obligations (retorsion), and for permitted countermeasures. Attribution, such as public attribution, may also serve as a method of retorsion in itself. Critical infrastructure, critical infrastructure of society An asset, a facility, equipment, a network or a system, or a part of an asset, a facility, equipment, a network or a system, or an important service, which is essential for maintaining the vital functions of society or for providing some other key service. 48

Select target paragraph3