Acronyms Flashcards
CCE
Common Configuration Enumeration - Standard for discussing system configuration issues
CVE
Common Vulnerabilities and Exposures - Standard for describing security-related software flaws
CPE
Common Platform Enumeration - Standard for describing product names and versions
CVSS
Common Vulnerability Scoring System - Standard for measuring and describing the severity of security-related software flaws
XCCDF
Extensible Configuration Checklist Description Format - Language for specifying checklists and reporting checklist results
OVAL
Open Vulnerability and Assessment Language - Language for specifying low-level testing procedures used by checklist
SCAP
Security Content Automation Protocol - Led by NIST to create a standardized approach for communicating security related content (CVE, CVSS, etc.)
NIST
National Institute of Standards and Technology
IDS
Intrusion Detection System
IPS
Intrusion Prevention System
PCI DSS
Payment Card Industry Data Security Standard (PCI DSS) - Not a law, maintained by the PCI SSC, funded by the payment card industry to maintain requirements
PCI SSC
Payment Card Industry Security Standards Council
ASV
Approved Scanning Vendor
FedRAMP
Federal Risk and Authorization Management Program - Fed regulation that establishes a standard approach for assessing, monitoring, and authorizing cloud computing services under the FISMA
FISMA
Federal Information Security Management Act
CIS
Center for Internet Security - Publishes security benchmarks that represent the consensus opinions of SME’s. Provides solid foundation for system configuration efforts
ISO
International Organization for Standardization - Publishes standards related to information security, ISO 27001, ISO 27002 etc.
OWASP
Open Web Application Security Project - Home to devs and security practitioners, hosts community-developed standards, guides, best practice documents, and industry standard open-source tools
ISO 27001
Standard for setting up an information security management system
ISO 27002
More specific than ISO 27001, goes into detail on specific information security controls
ITSM
IT service management - tool that can be used for tracking vulnerabilities
SLA
Service-level Agreement - Business agreement that outlines which services and support will be provided to a client
MOU
Memorandum of Understanding - Agreement between two or more parties that is outlined in formal document, which is not legally binding
GLBA
Gramm-Leach-Bliley Act - Act that governs how financial institutions handle customer financial records