77
Annex 2
GLOSSARY
Script kiddie – a less skilled individual who
uses ready-made scripts, or programs, that
can be found on the Internet to conduct
cyber attacks, such as web defacements.
Secure by default – the unlocking of the
secure use of commodity technologies
whereby security comes by default for users.
Secure by design – software, hardware
and systems that have been designed from
the ground up to be secure.
Vishing – vishing or ‘voice phishing’ is the
use of voice technology (landline phones,
mobile phones, voice email, etc) to trick
individuals into revealing sensitive financial
or personal information to unauthorised
entities, usually to facilitate fraud.
Vulnerability – bugs in software
programs that have the potential to be
exploited by attackers.
SMS spoofing – a technique which masks
the origin of an SMS text message by
replacing the originating mobile number
(Sender ID) with alphanumeric text. It may
be used legitimately by a sender to replace
their mobile number with their own name,
or company name, for instance. Or it may
be used illegitimately, for example, to
fraudulently impersonate another person.
Social engineering – the methods
attackers use to deceive and manipulate
victims into performing an action or
divulging confidential information.
Typically, such actions include opening
a malicious webpage, or running an
unwanted file attachment.
Trusted Platform Module (TPM) – an
international standard for a secure
cryptoprocessor, which is a dedicated
microprocessor designed to secure
hardware by integrating cryptographic keys
into devices.
User – a person, organisation entity,
or automated process, that accesses a
system, whether authorised to, or not.
Virus – viruses are malicious computer
programs that can spread to other files.
National Cyber Security Strategy 2016