Glossary of Terms

Acronyms

ACL  
Access Control List
API  
Application Programming Interface
DDoS  
Distributed Denial of Service
IT  
Information Technology
IaaS  
Infrastructure as a Service
PaaS  
Platform as a Service
SaaS  
Software as a Service
UTM  
Unified Threat Management

Definitions

Authentication  
The act of establishing the genuine identity of an individual or entity.
Authorization  
The act of permitting the proper level of access rights to information or a system.
Business Continuity  
The ability of an entity to effectively continue to execute its mission critical functions in every possible environment.
Certificate  
The digital equivalent of an ID card used in conjunction with a public key encryption system; an electronic cryptographic credential that is used to authenticate an individual or device in a secure system.
Cloud Computing  
The delivery of Internet-based computing as an on-demand service rather than a product, in which the shared resources, software and information are provided to computers and other devices as a utility over a network. In many cases this involves taking computing services and moving them outside the organizational firewall and providing them on shared resources. NIST defines cloud computing across three (3) service models (IaaS, PaaS, SaaS), four (4) deployment models (Public, Private, Community and Hybrid) and five (5) components of secure cloud architecture (On demand self service, broad network access, resource pooling, rapid elasticity, and measured service).
Consumer  
An individual or entity that uses a product or service.
Credentials  
Evidence of authority, status, or rights to system access privileges.
Customer  
An organization that purchases a product or service from Shift.
Cyber Security  
The discipline and practice of defending electronic systems, networks and infrastructure from unauthorized access, corruption, manipulation or natural disaster while allowing the information to remain accessible to its intended users.
Data Stewardship  
The practice of and responsibility for securing and maintaining consistency and integrity of stored data and metadata.
Distributed Computing  
A field of computer science in which a network of multiple autonomous computers work collaboratively to solve computational problems and conduct computational tasks that are solved by one or more computers in parallel.
Encryption  
The process of protecting information by transforming the relevant data through the use of an algorithmic process to make the message unreadable or indecipherable to unintended recipients; commonly refers to Public Key Encryption, in which two separate but related keys are generated: one to encrypt and to decrypt data.
Malware  
Short for malicious software, this is code specifically written with the intent to damage, destroy or exploit systems, gather information, gain unauthorized access and or self-propagate.
Validation  
An act of quality assurance in which one ensures the legitimacy or truth of a verification.
Verification  
An act of quality control in which an individual or system determines whether the process actually does what it was intended to do.
Virtualization  
The creation of a virtual rather than actual version of a device; generally described in three (3) levels of virtualization (full virtualization, partial virtualization and paravirtualization).