Acronyms Flashcards
AICPA
American Institute of Certified Public Accountants
COBIT
Control Objectives for Information and Related Technologies
A control framework for governance best practices in an organization
ISO
International Organization for Standardization
SOC
System and Organization Controls
SSAE
Statement on Standards for Attestation Engagements
CVE
Common Vulnerabilities and Exposures
A naming system for describing security vulnerabilities
A Component of SCAP
CVSS
Common Vulnerability Scoring System
Standardized scoring system for describing vulnerabilities
A Component of SCAP
CCE
Common Configuration Enumeration
Naming system for system configuration issues
A Component of SCAP
CPE
Common Platform Enumeration
A naming system for operating systems, applications, and devices
A component of SCAP
SCAP
Security Content Automation Protocol
Components include CVE, CVSS, CCE, CPE, XCCDF, OVAL
CISSP
Certified Information Systems Security Professional
ISMS
Information Security Management System
XCCDF
Extensible Configuration Checklist Format
Provides a language for specifying security checklists
OVAL
Open Vulnerability and Assessment Language
Provides a language for describing security testing procedures
port 20/21
FTP
Port 22
ssh
Port 23
telnet
port 25
SMTP
port 53
DNS
port 80
http
port 110
pop3
port 123
ntp
port 135, 137-139, 445
Windows file sharing
port 443
https
port 515
let
port 1433
microsoft sql server
port 1521
oracle
port 1723
pptp
port 1720
h.323
port 3389
RDP
port 9100
HP JetDirect printing
PCI
Payment Card Industry
OWASP
Open Web Application Security Project
SDLC
Software Development Lifecycle
SIEM
Security Information and Event Management
IAM
Identity and Access Management
IDS
Intrusion Detection System
IPS
Intrusion Prevention System
HIDS
Host Based Intrusion Detection System
NIDS
Network Based Intrusion Detection System
MTTR
Mean Time to Repair
A measure of Availability
MTBF
Mean Time Between Failures
A measurement of availability and reliability
MTTF
Mean Time to Failure
Measurement of Reliability for non-repairable systems
CMMS
Computerized Maintenance Management System
CORBA
Common Object Reference Based Architecture
An open vendor-neutral object network object broker framework
COOP
Continuity Of Operations Plan
XCCDF
Extensive Configuration Checklist Description Format
Provides a language for specifying security checklists
A component of SCAP
OVAL
Open Vulnerability and Assessment Language
A language for describing security testing procedures
A Component of SCAP