ECIH 詞彙表(未完成)
A
Application Flaws | 應用程式缺陷
Availability|可用性
After Action Report (AAR) | 事後報告
Ad Hoc | 臨時性的資訊共享
Attack Vector | 攻擊向量
B
Business Impact Analysis (BIA analysis)| 營運衝擊分析
Blue screen of death (BSOD) | 電腦當機
C
Cyber Threat Intelligence (CTI)| 網路威脅情報
Confidentiality|機密性
chain of custody | 證物鏈
D
Deceive | 欺騙
Digital Millennium Copyright Act (DMCA) | 數位千禧年著作權法
Domain Keys Identified Mail (DKIM) | 郵件來源驗證
E
Evict | 區族
enhance | 加強
Explicit Congestion Notificatio (ECN) | (網路)壅塞通知
F
Federal Financial Institutions Examination Council (FFIEC) | 美國聯邦金融機構檢查委員會
G
General Data Protection Regulation (GDPR) | 歐盟《一般資料保護規則》
I
Indicators | 指標
Indicators of Compromise (IoCs) | 入侵指標
Iterative Approach | 迭代式方法(透過持續評估與修正,逐步改善結果)
Intangible Cost|無形成本
Integrity|完整性
Information Sharing and Analysis Center (ISAC) | 資訊共享與分析中心
IP Flow Information Export (IPFIX) | 一種用來收集與傳送網際網路流量統計資訊的國際標準協定
J
JOESandbox | 自動化惡意程式與可疑檔案分析平台
K
Key Performance Indicator (KPI) | 關鍵績效指標
Key Risk Indicator (KRI) | 關鍵風險指標
Key Control Indicator (KCI) | 關鍵控制指標
L
Loss of Business Reputation | 商業信譽損失
M
MITRE D3FEND | 防守框架
N
O
OODA Loops | OODA循環
orchestration | 排程
P
Precursors | 先兆/前兆
Promiscuous Policy|寬鬆開放型政策
Permissive Policy|寬容型政策
Prudent Policy|審慎型政策
Paranoid Policy|極度嚴格型政策
Payment Card Industry Data Security Standard (PCI DSS) | 支付卡產業資料安全標準
R
RE&CT Framework | 事件回應框架
S
System Development Life Cycle (SDLC)| 系統開發生命週期
Structured Threat Information eXpression (STIX) | 結構化威脅資訊表達格式
Service Level Agreement (SLA) | 服務水準協議
Sender Policy Framework (SPF) | 郵件驗證規範
Security Information Management (SIM) | 安全資訊管理
Security Event Management (SEM) | 安全事件管理
Security Information and Event Management (SIEM) | 安全資訊和事件管理
T
Tactics, Techniques, and Procedures (TTPs) | 戰術、技術與程序
Tangible Cost|有形成本