76
Annex 2
GLOSSARY
Incident response – the activities that
address the short-term, direct effects
of an incident, and may also support
short-term recovery.
Network (computer) – a collection of host
computers, together with the sub-network
or inter-network, through which they can
exchange data.
Industrial Control System (ICS) –
an information system used to
control industrial processes, such
as manufacturing, product handling,
production and distribution, or to control
infrastructure assets.
Offensive cyber – the use of cyber
capabilities to disrupt, deny, degrade or
destroy computers networks and internet
connected devices.
Industrial Internet of Things (IIoT) –
the use of Internet of Things technologies
in manufacturing and industry.
Insider – someone who has trusted access
to the data and information systems of
an organisation and poses an intentional,
accidental or unconscious cyber threat.
Integrity – the property that information
has not been changed accidentally, or
deliberately, and is accurate and complete.
Internet – a global computer network,
providing a variety of information and
communication facilities, consisting
of interconnected networks using
standardised communication protocols.
Internet of Things – the totality of devices,
vehicles, buildings and other items
embedded with electronics, software and
sensors that communicate and exchange
data over the Internet.
London Process – measures resulting
from the 2011 London Conference on
Cyberspace.
Malware – malicious software, or code.
Malware includes viruses, worms, Trojans
and spyware.
National Cyber Security Strategy 2016
Patching – patching is the process
of updating software to fix bugs and
vulnerabilities
Penetration testing – activities designed
to test the resilience of a network or facility
against hacking, which are authorised or
sponsored by the organisation being tested.
Phishing – the use of emails that appear to
originate from a trusted source, to deceive
recipients into clicking on malicious links
or attachments that are weaponised with
malware, or share sensitive information,
with an unknown third party.
Ransomware – malicious software that
denies the user access to their files,
computer or device until a ransom is paid.
Reconnaissance – the phase of an attack
where an attacker gathers information on,
and maps networks, as well as probing
them for exploitable vulnerabilities in order
to hack them.
Risk – the potential that a given cyber
threat will exploit the vulnerabilities of an
information system and cause harm.
Router – devices that interconnect logical
networks by forwarding information to other
networks based upon IP addresses.