Knowledge base

Short, tagged, searchable.

Terms, frameworks, and concepts used on an Australian defensive desk. No exploit steps.

18 entries

concepts acsc-glossary

Advanced persistent threat (APT)

A campaign with a pattern, not a single file. Often patient, often aimed, sometimes state-linked. The persistence is the point.

concepts hardening acsc-glossary

Attack surface

Everything a hostile party can reach: apps, IT, OT, services. Bigger surface, more raffle tickets.

concepts acsc-glossary

Availability

Authorised users can actually use the system when the work needs it. Uptime theatre without backups is a bet.

concepts acsc-glossary

CIA triad

Confidentiality, integrity, availability. Lose one and the system is already failing, even if the dashboard is green.

concepts vulnerability

CVE vs CVSS

CVE names a vulnerability. CVSS scores a model of severity. Neither tells you if you are exposed or if it is being used.

concepts acsc-glossary

Confidentiality

The right eyes only. Encryption, access control, and not leaving copies in the wrong tray.

hardening concepts acsc-glossary

Defence in depth

Stacked controls so one failure is not game over. Redundancy, not twelve dashboards of the same alert.

cloud concepts acsc-glossary

Encryption

Turn readable data into ciphertext with an algorithm and a key. The keys are the asset. A key taped to the data is theatre.

concepts acsc-glossary

Integrity

The record is what authorised people made it. Quiet alteration is still a breach.

malware concepts acsc-glossary

Malware

Software that is there to harm you: steal, lock, spy, or hitch a ride. Virus, worm, Trojan, ransomware — different delivery, same job.

identity concepts acsc-glossary

Phishing

A bulk lure: fake message, urgency, a credential or a hostile file. Training helps. Phishing-resistant MFA and mail authentication help more.

identity concepts acsc-glossary

Social engineering

Manipulate a person, skip the software flaw. Phishing, vishing, BEC, and the helpdesk reset are all this family.

concepts acsc-glossary

Spam

Unsolicited bulk messages, usually ads. Not all spam is phishing. Plenty of phishing rides in the same tray.

detection concepts

Threat intelligence

Context that changes a decision. IoCs expire. TTPs last. A feed you never action is a newsletter.

network concepts acsc-glossary

Transport Layer Security (TLS)

The S in HTTPS. Privacy and integrity for data on the wire. Certificates you actually manage.

vulnerability concepts acsc-glossary

Vulnerability

A weakness in requirements, design, build, or operations that can be tripped or abused and break the security policy.

malware concepts acsc-glossary

Watering hole

Poison a site your targets already visit. The prey comes to the water. Patching and isolation still apply.

network identity concepts

Zero trust

Never trust, always verify. A VPN badge is not a day pass. Identity, device, path, and data each get asked again.

Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary