This is not exhaustive and abbreviations will be added as necessary and appropriate.
| Abbreviation | Explanation |
|---|---|
| BCM | Business Continuity Management |
| BCP | Business Continuity Plan |
| BEC | Business Email Compromise |
| BIA | Business Impact Assessment |
| CMDB | Configuration Management Database |
| CoBIT | Control Objectives for Information and related Technology |
| CSF | Cyber Security Framework |
| CTI | Cyber Threat Intelligence |
| DDoS | Distributed Denial of Service |
| DLP | Data Loss Prevention |
| DR | Disaster Recovery |
| DRP | Disaster Recovery Plan |
| EDR / MDR / XDR | Endpoint / Managed / Extended Detection and Response |
| ERM | Enterprise Risk Management |
| GRC | Governance, Risk and Compliance |
| I&T | Information and related Technology |
| IDM | Identity Management |
| IGA | Identity Governance and Administration |
| IR | Incident Response |
| IRP | Incident Response Plan |
| IS | Information System |
| IS&T | Information Systems and Technology |
| ISC2 | International Information System Security Certification Consortium |
| ISMS | IT Security Management System |
| ISO | International Standard Organization |
| ISPF | IT Security Policy Framework |
| IT | Information Technology |
| KPI / KRI | Key Performance / Risk Indicator |
| MSSP | Managed Security Services Provider |
| NIST | National Institute of Standards and Technology |
| NOC | Network Operations Center |
| PIA | Privacy Impact Analysis |
| QA | Quality Assurance |
| RA | Risk Assessment |
| RM | Risk Management |
| RR | Risk Register |
| RTO / RPO | Recovery Time Objective / Recovery Point Objective |
| SIEM | Security Information and Event Management |
| SOC | Security Operations Center |
| SSO | Single Sign-o |
| T&VM | Threat and Vulnerability Management |
| TPM | Third-Party Management |
| VM | Vulnerability Management |