Siglas e acrônimos de cibersegurança

Mais de 100 siglas essenciais para profissionais de cibersegurança. As traduções aprovadas aparecem aqui; as demais redirecionam para a versão em inglês.

SIEMSecurity Information and Event ManagementSOARSecurity Orchestration, Automation, and ResponseEDREndpoint Detection and ResponseXDRExtended Detection and ResponseMDRManaged Detection and ResponseSOCSecurity Operations CenterNOCNetwork Operations CenterIDSIntrusion Detection SystemIPSIntrusion Prevention SystemWAFWeb Application FirewallDLPData Loss PreventionNDRNetwork Detection and ResponseNTANetwork Traffic AnalysisNGFWNext-Generation FirewallEPPEndpoint Protection PlatformPCAPPacket CaptureIOCIndicator of CompromiseIOAIndicator of AttackTTPTactics, Techniques, and ProceduresAPTAdvanced Persistent ThreatCTICyber Threat IntelligenceTIPThreat Intelligence PlatformOSINTOpen-Source IntelligenceMSSPManaged Security Service ProviderMSPManaged Service ProviderDDoSDistributed Denial of ServiceBASBreach and Attack SimulationASMAttack Surface ManagementEASMExternal Attack Surface ManagementCASBCloud Access Security BrokerCSPMCloud Security Posture ManagementCNAPPCloud-Native Application Protection PlatformCWPPCloud Workload Protection PlatformIAMIdentity and Access ManagementPAMPrivileged Access ManagementMFAMulti-Factor AuthenticationSSOSingle Sign-OnRBACRole-Based Access ControlABACAttribute-Based Access ControlPKIPublic Key InfrastructureCACertificate AuthorityZTNAZero Trust Network AccessSDPSoftware-Defined PerimeterSASESecure Access Service EdgeSD-WANSoftware-Defined Wide Area NetworkSAMLSecurity Assertion Markup LanguageOIDCOpenID ConnectOAuthOpen AuthorizationJWTJSON Web TokenNACNetwork Access ControlK8sKubernetesOPAOpen Policy AgentIaCInfrastructure as CodeGRCGovernance, Risk, and ComplianceERMEnterprise Risk ManagementBIABusiness Impact AnalysisBCPBusiness Continuity PlanDRPDisaster Recovery PlanRPORecovery Point ObjectiveRTORecovery Time ObjectiveMTTRMean Time to RecoverMTTDMean Time to DetectKPIKey Performance IndicatorKRIKey Risk IndicatorSLAService Level AgreementSLOService Level ObjectiveNISTNational Institute of Standards and TechnologyISOInternational Organization for StandardizationPCIPayment Card IndustryHIPAAHealth Insurance Portability and Accountability ActGDPRGeneral Data Protection RegulationCCPACalifornia Consumer Privacy ActCMMCCybersecurity Maturity Model CertificationFedRAMPFederal Risk and Authorization Management ProgramFISMAFederal Information Security Modernization ActSTIGSecurity Technical Implementation GuideOWASPOpen Worldwide Application Security ProjectSTRIDESpoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of PrivilegeDREADDamage, Reproducibility, Exploitability, Affected Users, DiscoverabilityNICENational Initiative for Cybersecurity EducationSOXSarbanes-Oxley ActFERPAFamily Educational Rights and Privacy ActNFPANational Fire Protection AssociationRCERemote Code ExecutionXSSCross-Site ScriptingSQLiSQL InjectionCSRFCross-Site Request ForgerySSRFServer-Side Request ForgeryBOFBuffer OverflowROPReturn-Oriented ProgrammingASLRAddress Space Layout RandomizationDEPData Execution PreventionRATRemote Access TrojanC2Command and ControlVMVulnerability ManagementPTPenetration TestingSBOMSoftware Bill of MaterialsSCASoftware Composition AnalysisSASTStatic Application Security TestingDASTDynamic Application Security Testing