77 Annex 2 GLOSSARY Script kiddie – a less skilled individual who uses ready-made scripts, or programs, that can be found on the Internet to conduct cyber attacks, such as web defacements. Secure by default – the unlocking of the secure use of commodity technologies whereby security comes by default for users. Secure by design – software, hardware and systems that have been designed from the ground up to be secure. Vishing – vishing or ‘voice phishing’ is the use of voice technology (landline phones, mobile phones, voice email, etc) to trick individuals into revealing sensitive financial or personal information to unauthorised entities, usually to facilitate fraud. Vulnerability – bugs in software programs that have the potential to be exploited by attackers. SMS spoofing – a technique which masks the origin of an SMS text message by replacing the originating mobile number (Sender ID) with alphanumeric text. It may be used legitimately by a sender to replace their mobile number with their own name, or company name, for instance. Or it may be used illegitimately, for example, to fraudulently impersonate another person. Social engineering – the methods attackers use to deceive and manipulate victims into performing an action or divulging confidential information. Typically, such actions include opening a malicious webpage, or running an unwanted file attachment. Trusted Platform Module (TPM) – an international standard for a secure cryptoprocessor, which is a dedicated microprocessor designed to secure hardware by integrating cryptographic keys into devices. User – a person, organisation entity, or automated process, that accesses a system, whether authorised to, or not. Virus – viruses are malicious computer programs that can spread to other files. National Cyber Security Strategy 2016

Select target paragraph3