Knowledge base

Short, tagged, searchable.

Terms, frameworks, and concepts used on an Australian defensive desk. No exploit steps.

18 entries

IR hardening acsc-glossary

3-2-1 backups

Three copies, two media, one off-site. Immutable or offline beats a snapshot the ransomware also encrypted.

network hardening acsc-glossary

Air gap

Physically isolated. No cable, no Wi-Fi, no 'just this jump host' to the internet. Removable media is still a path if you let it be.

detection hardening acsc-glossary

Antivirus

Software that looks for known-bad and obvious malice, then tries to stop and clean it. Necessary. Not sufficient.

concepts hardening acsc-glossary

Attack surface

Everything a hostile party can reach: apps, IT, OT, services. Bigger surface, more raffle tickets.

IR hardening acsc-glossary

Backup

A copy stored somewhere else so you can restore after loss. If ransomware can reach it with the same credentials, it is not a backup.

identity hardening acsc-glossary

DMARC, DKIM, and SPF

Mail authentication so others cannot cheaply wear your domain. Publish records. Then set a policy that actually rejects.

identity hardening acsc-glossary

Default passwords

The password the vendor shipped. Fine for unboxing. Malpractice if it is still there at go-live.

hardening concepts acsc-glossary

Defence in depth

Stacked controls so one failure is not game over. Redundancy, not twelve dashboards of the same alert.

frameworks au-compliance hardening

Essential Eight

ASD's baseline of eight mitigation strategies. Maturity 0 to 3. The work is picking a level you can actually hold.

network hardening acsc-glossary

Firewall

A filter on the way in and out, driven by rules. Default allow is a very expensive switch.

identity hardening acsc-glossary

Least privilege

Only the access required, only for as long as required. Standing admin is standing blast radius.

identity hardening acsc-glossary

Need-to-know

Access only to the data the role actually requires. Broad file shares are a rumour mill with NTFS.

network hardening acsc-glossary

Network segmentation

Cut the network into smaller pieces. Segregation is the rule set between them. Flat is a gift.

identity acsc-glossary hardening

Password manager

Generates unique secrets and stores them in a vault. One strong unlock. Not a spreadsheet called passwords_final.

vulnerability hardening acsc-glossary

Patch

A vendor fix for a hole or a defect. Installing it is patching. Explaining why you did not is an exception with an expiry date.

identity hardening acsc-glossary

Privileged user

Someone who can change or sidestep security controls. Developers who can bypass a guardrail count.

hardening detection acsc-glossary

Sandbox

A paddock for untrusted code. If it explodes, the paddock takes it. Production is not a paddock.

vulnerability hardening acsc-glossary

Vulnerability management

Find, rank, fix, check. Known-exploited and exposure beat a 400-page scanner PDF.

Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary