Terms in IT/OT
The entries explain technical terms from IT infrastructure and IT/OT security and lead to the service in which they occur.
- Automation & virtual commissioning
- Industrial IoT
- Embedded systems & software
- Artificial intelligence
- IT/OT
0-9
- 19-inch rack
- Standardised cabinet for servers, switches and UPS with a mounting width of 19 inches. Monitoring and operation
- 3-2-1 rule
- Basic rule of data backup: three copies on two different media, one of them off site. Storage and backup
A
- Active Directory
- Directory service from Microsoft that manages users, computers and permissions in a Windows network centrally. Directory services and identities
C
- Cloud
- Computing power, storage and services are provided over the internet from the data centres of a provider. Cloud and third-party systems
- Container
- Self-contained runtime environment that bundles an application with all dependencies and starts in the same way on every suitable host. Backend and distributed systems
- CRACyber Resilience Act
- EU regulation that imposes obligations on manufacturers of products with digital elements regarding security, vulnerability handling and updates. Product and software compliance
- CVECommon Vulnerabilities and Exposures
- Public catalogue of known security vulnerabilities in which every vulnerability receives a unique identifier. Vulnerability and patch management
D
- DMZDemilitarised zone
- Network area between two firewalls for services that must be reachable from another network. Network security and zones
F
- Firewall
- System that allows or blocks data traffic between networks according to defined rules. Network security and zones
G
- GDPRGeneral Data Protection Regulation
- EU regulation that governs the processing of personal data, including when AI is used. AI Act obligations
H
- Hypervisor
- Software that starts virtual machines on a host, separates them from one another and supplies them with computing power, memory and network, for example Proxmox VE or VMware ESXi. Virtualisation and servers
I
- IEC 62443
- Series of standards for the IT security of industrial automation systems with requirements for operators, integrators and manufacturers. OT security
- ISO/IEC 27001
- International standard for information security management systems. Regulation and evidence
- IT/OTInformation technology and operational technology
- Interplay of office IT with the operational technology that controls machines and plants. IT/OT
J
- Jump host
- Central, secured computer through which all remote access to a protected network runs and is logged. Remote access
L
- LDAPLightweight Directory Access Protocol
- Protocol for querying and maintaining directory services with users, groups and devices. Directory services and identities
M
- MFAMulti-factor authentication
- Sign-in with at least two independent proofs, for example password and code from an app. Directory services and identities
- Monitoring
- Continuous monitoring of servers, network and services with an alarm when a limit is exceeded or a service fails. Monitoring and operation
N
- NASNetwork attached storage
- Storage system that provides files over the network for several computers. Storage and backup
- Network segmentation
- A network is divided into separate areas between which only approved traffic flows. Network security and zones
- NIS-2
- EU directive on cybersecurity that obliges important and essential entities to risk management, reporting and evidence. Regulation and evidence
O
- OAuth 2.0
- Standard for authorisation with which an application accesses an interface on behalf of a user without receiving the user's password. Interfaces and data storage
- On-premise
- Software and models run on own hardware in the own building or own data centre. Operation on the premises
- OTOperational technology
- Hardware and software that controls and monitors physical processes, for example controllers, operator panels and control systems. OT security
P
- Patch management
- Regulated process in which security updates are checked, tested and installed. Vulnerability and patch management
R
- RAIDRedundant array of independent disks
- Group of several hard disks that distributes the data so that the failure of one disk loses no data. Storage and backup
- Remote maintenance
- Access to a plant or system from a distance, for example by a supplier, for diagnosis and maintenance. Remote access
S
- SANStorage area network
- Dedicated network that provides servers with block-level storage. Storage and backup
- SIEMSecurity information and event management
- System that collects and analyses logs from network, servers and applications and raises an alarm on attack patterns. Vulnerability and patch management
- SSOSingle sign-on
- Method in which one sign-in applies to several applications. Directory services and identities
- Switch
- Network device that forwards data packets within a network specifically to the port of the recipient. Network engineering
T
- TISAXTrusted Information Security Assessment Exchange
- Assessment and exchange mechanism of the automotive industry for information security, run by the VDA and the ENX Association. Regulation and evidence
U
- UPSUninterruptible power supply
- Device that keeps supplying power from batteries in a power failure and lets the servers shut down in an orderly way. Monitoring and operation
V
- Virtualisation
- Several virtual servers run on one physical computer and share its resources. Virtualisation and servers
- VLANVirtual local area network
- Logically separated network on shared switch hardware. Network engineering
- VPNVirtual private network
- Encrypted connection over a public network that connects a remote computer like a device in the own network. Remote access
- Vulnerability scan
- Automated check of systems for known vulnerabilities and misconfigurations, for example with Greenbone OpenVAS. Vulnerability and patch management
W
- WLANWireless local area network
- Radio network according to IEEE 802.11 for computers, tablets and mobile devices in office and hall. Network engineering
Z
- Zones and conduits
- Concept from IEC 62443: plant sections with the same protection need form a zone, the connections between zones are called conduits and are secured specifically. OT security