Publications of the Prime Minister’s Office 2024:13
8
Concepts and definitions
The terms and definitions set out below describe concepts used in this document.
These terms have been used in order to explain the strategy more concisely and
avoid repetition, and the definitions are provided to help the reader understand
the intended context. The recognised need to update terminology related to
concepts designated by cybersecurity terms used in this strategy has caused some
divergence from the accounts that are already available in existing glossaries, such
as the TEPA Term Bank or the Vocabulary of Cyber Security. This divergence arises in
particular from the need for concepts that are internationally harmonised, and the
need to include concepts that are now used in EU regulation.
Attribution
Detecting and locating a party conducting a hostile cyber operation, and
identifying that party, through an analytical process using various information
sources. Nationally this process involves both technical analysis and the duties of
public authorities, and discretion related to foreign and security policy. Attribution
is the outcome of the analysis process, regardless of whether that outcome is
public or non-public. Attribution is often a condition for holding a party legally
or politically liable, for measures in accordance with international obligations
(retorsion), and for permitted countermeasures. Attribution, such as public
attribution, may also serve as a method of retorsion in itself.
Critical infrastructure, critical infrastructure of society
An asset, a facility, equipment, a network or a system, or a part of an asset, a facility,
equipment, a network or a system, or an important service, which is essential for
maintaining the vital functions of society or for providing some other key service.
48