Glossary

Terms you may encounter in some of our cybersecurity training programs.

Smishing

Smishing is phishing via text message. Cyber criminals will send tects with links, or try to get the victime to reply with the hopes of somehow exploiting them.

Social engineering

The practice of obtaining confidential information by manipulation of legitimate users. A social engineer will commonly use the telephone or internet to trick people into revealing sensitive information. For example, phishing is a type of social engineering.

Spear phishing

The use of spoofed emails to persuade people within an organization to reveal their usernames or passwords. Unlike phishing, which involves mass mailing, spear phishing is small-scale and well targeted.

Threat and risk assessment

A process of identifying system assets and how these assets can be compromised, assessing the level of risk that threats pose to assets, and recommending security measures to mitigate threats.

Treat event

An actual incident in which a threat agent exploits a vulnerability of an IT asset of value.

TRA

See threat andĀ risk assessment.

Trojan

A malicious program that is disguised as or embedded within legitimate software.

Two-factor authentication

A type of multi-factor authentication used to confirm the identity of a user. Authentication is validated by using a combination of two different factors including: something you know (e.g. a password), something you have (e.g. a physical token), or something you are (a biometric).

Two-step verification

A process requiring two different authentication methods, which are applied one after the other, to access a specific device or system. Unlike two-factor authentication, two-step verification can be of the same type (e.g. two passwords, two physical keys, or two biometrics). Also known as Two-step authentication.

Unpatched application

A supported application that does not have the latest security updates and/or patches installed.