Terms in IT/OT

The entries explain technical terms from IT infrastructure and IT/OT security and lead to the service in which they occur.

0-9

19-inch rack
Standardised cabinet for servers, switches and UPS with a mounting width of 19 inches. Monitoring and operation
3-2-1 rule
Basic rule of data backup: three copies on two different media, one of them off site. Storage and backup

A

Active Directory
Directory service from Microsoft that manages users, computers and permissions in a Windows network centrally. Directory services and identities

C

Cloud
Computing power, storage and services are provided over the internet from the data centres of a provider. Cloud and third-party systems
Container
Self-contained runtime environment that bundles an application with all dependencies and starts in the same way on every suitable host. Backend and distributed systems
CRACyber Resilience Act
EU regulation that imposes obligations on manufacturers of products with digital elements regarding security, vulnerability handling and updates. Product and software compliance
CVECommon Vulnerabilities and Exposures
Public catalogue of known security vulnerabilities in which every vulnerability receives a unique identifier. Vulnerability and patch management

D

DMZDemilitarised zone
Network area between two firewalls for services that must be reachable from another network. Network security and zones

F

Firewall
System that allows or blocks data traffic between networks according to defined rules. Network security and zones

G

GDPRGeneral Data Protection Regulation
EU regulation that governs the processing of personal data, including when AI is used. AI Act obligations

H

Hypervisor
Software that starts virtual machines on a host, separates them from one another and supplies them with computing power, memory and network, for example Proxmox VE or VMware ESXi. Virtualisation and servers

I

IEC 62443
Series of standards for the IT security of industrial automation systems with requirements for operators, integrators and manufacturers. OT security
ISO/IEC 27001
International standard for information security management systems. Regulation and evidence
IT/OTInformation technology and operational technology
Interplay of office IT with the operational technology that controls machines and plants. IT/OT

J

Jump host
Central, secured computer through which all remote access to a protected network runs and is logged. Remote access

L

LDAPLightweight Directory Access Protocol
Protocol for querying and maintaining directory services with users, groups and devices. Directory services and identities

M

MFAMulti-factor authentication
Sign-in with at least two independent proofs, for example password and code from an app. Directory services and identities
Monitoring
Continuous monitoring of servers, network and services with an alarm when a limit is exceeded or a service fails. Monitoring and operation

N

NASNetwork attached storage
Storage system that provides files over the network for several computers. Storage and backup
Network segmentation
A network is divided into separate areas between which only approved traffic flows. Network security and zones
NIS-2
EU directive on cybersecurity that obliges important and essential entities to risk management, reporting and evidence. Regulation and evidence

O

OAuth 2.0
Standard for authorisation with which an application accesses an interface on behalf of a user without receiving the user's password. Interfaces and data storage
On-premise
Software and models run on own hardware in the own building or own data centre. Operation on the premises
OTOperational technology
Hardware and software that controls and monitors physical processes, for example controllers, operator panels and control systems. OT security

P

Patch management
Regulated process in which security updates are checked, tested and installed. Vulnerability and patch management

R

RAIDRedundant array of independent disks
Group of several hard disks that distributes the data so that the failure of one disk loses no data. Storage and backup
Remote maintenance
Access to a plant or system from a distance, for example by a supplier, for diagnosis and maintenance. Remote access

S

SANStorage area network
Dedicated network that provides servers with block-level storage. Storage and backup
SIEMSecurity information and event management
System that collects and analyses logs from network, servers and applications and raises an alarm on attack patterns. Vulnerability and patch management
SSOSingle sign-on
Method in which one sign-in applies to several applications. Directory services and identities
Switch
Network device that forwards data packets within a network specifically to the port of the recipient. Network engineering

T

TISAXTrusted Information Security Assessment Exchange
Assessment and exchange mechanism of the automotive industry for information security, run by the VDA and the ENX Association. Regulation and evidence

U

UPSUninterruptible power supply
Device that keeps supplying power from batteries in a power failure and lets the servers shut down in an orderly way. Monitoring and operation

V

Virtualisation
Several virtual servers run on one physical computer and share its resources. Virtualisation and servers
VLANVirtual local area network
Logically separated network on shared switch hardware. Network engineering
VPNVirtual private network
Encrypted connection over a public network that connects a remote computer like a device in the own network. Remote access
Vulnerability scan
Automated check of systems for known vulnerabilities and misconfigurations, for example with Greenbone OpenVAS. Vulnerability and patch management

W

WLANWireless local area network
Radio network according to IEEE 802.11 for computers, tablets and mobile devices in office and hall. Network engineering

Z

Zones and conduits
Concept from IEC 62443: plant sections with the same protection need form a zone, the connections between zones are called conduits and are secured specifically. OT security