Glossary
Security glossary
Clear explanations of terms from corporate and cyber security, intelligence research and regulation — in Slovenian and English.
22 terms
AMOK (active assailant situation)
AMOK denotes a sudden violent attack in which an assailant deliberately injures or kills as many people as possible at a defined location, with the attack typically still under way when help arrives.
Read definitionBlue team
The blue team is the defensive side of a security organization: the people, processes and technology that monitor, detect, investigate and contain security events.
Read definitionBusiness continuity
Business continuity is an organization's capability to keep delivering its most important activities at a predefined acceptable level during and after a disruption.
Read definitionChain of custody
Chain of custody is the unbroken documented record of who held an item of evidence, when, why and what was done with it, from the moment it was secured to its final use.
Read definitionDigital footprint
A digital footprint is the totality of data traces an individual or organization leaves in the digital environment, whether created deliberately or generated automatically.
Read definitionDigital forensics
Digital forensics is the professional preservation, acquisition, analysis and interpretation of digital data in a way that maintains its integrity and allows the findings to be independently reproduced.
Read definitionDORA (Regulation (EU) 2022/2554)
DORA is the EU regulation on digital operational resilience for the financial sector, requiring financial entities to manage ICT risk, report incidents, test their resilience and govern their ICT third-party providers.
Read definitionDue diligence
Due diligence is the structured verification of a counterparty, investment or transaction before entering into a relationship, testing the representations made and identifying legal, financial, commercial and integrity risks.
Read definitionGDPR (General Data Protection Regulation)
The GDPR is the EU regulation that sets the rules for processing personal data, the obligations of controllers and processors and the rights of data subjects, and applies directly in every Member State.
Read definitionInsider threat
An insider threat is the risk that a person with legitimate access to an organization's premises, data or systems uses that access — deliberately or not — in a way that causes the organization harm.
Read definitionIntegrated security system
An integrated security system is an approach in which physical and technical protection, organizational measures, personnel security, information security and business continuity are designed and managed as a single system under unified governance.
Read definitionNIS2 Directive (EU) 2022/2555
NIS2 is an EU directive that imposes mandatory cyber risk management measures, incident reporting duties and management accountability on organizations in designated critical and important sectors.
Read definitionOSINT (open-source intelligence)
OSINT is the intelligence discipline in which publicly available, lawfully obtained information is systematically collected, verified and analyzed into a usable intelligence product.
Read definitionPenetration testing
Penetration testing is an authorized, controlled simulated attack on a system, application, network or facility in which vulnerabilities are actually exploited to demonstrate their real impact.
Read definitionPurple team
A purple team is not a separate standing unit but a way of working in which the offensive and defensive sides collaborate openly and in real time to measure and improve detection capability.
Read definitionRed teaming
Red teaming is an objective-driven exercise in which a team emulates a realistic adversary across digital, physical and human paths to test whether the organization detects the attack and responds to it effectively.
Read definitionRisk assessment
A risk assessment is a structured process of identifying hazards and threats, analyzing their likelihood and consequences, and evaluating whether a given risk is still acceptable to the organization.
Read definitionSocial engineering
Social engineering is the manipulation of people so that a victim discloses information or performs an action that undermines the security of an organization.
Read definitionTSCM (technical surveillance counter-measures)
A TSCM sweep is a technical and physical inspection of premises, vehicles or equipment carried out to detect unauthorized eavesdropping and recording devices and the weaknesses that make such eavesdropping possible.
Read definitionVulnerability assessment
A vulnerability assessment is the systematic identification, classification and prioritization of security weaknesses in systems, as a rule without actually exploiting them.
Read definitionZVOP-2 (Slovenian Personal Data Protection Act)
ZVOP-2 is the Slovenian act that implements the General Data Protection Regulation in national law and regulates in detail the matters the regulation leaves to Member States.
Read definitionZVZD-1 (Slovenian Health and Safety at Work Act)
ZVZD-1 is the Slovenian act requiring employers to ensure the safety and health of workers, including by producing a written safety statement with a risk assessment.
Read definition
Ready to strengthen security across your organization?
Contact us to see how our turnkey solutions can build a safer, more resilient organization.
