Glossary
Security+ 略語辞書(110語)
CompTIA Security+ で頻出のセキュリティ略語を、正式名称・日本語訳・解説つきでまとめました。アプリでは、問題文中の略語をタップするとこの辞書がその場で開きます。
A
- ABAC属性ベースアクセス制御Attribute-Based Access Control
- AES共通鍵ブロック暗号の標準Advanced Encryption Standard
- ALE年間損失予想額Annualized Loss Expectancy
- APT高度で持続的な脅威Advanced Persistent Threat
- ARO年間発生率Annualized Rate of Occurrence
- ATT&CK攻撃者の戦術・技術のナレッジベースMITRE ATT&CK
- AV資産価値/アンチウイルスAsset Value(リスク計算) / Antivirus
B
- BCP事業継続計画Business Continuity Plan
- BIAビジネス影響度分析Business Impact Analysis
- BPA事業提携契約Business Partners Agreement
- BYOD私物端末の業務利用Bring Your Own Device
C
- C2指令・制御(C&C)Command and Control
- CA認証局Certificate Authority
- CASBクラウドアクセスセキュリティブローカーCloud Access Security Broker
- CI/CD継続的インテグレーション/デリバリーContinuous Integration / Continuous Delivery
- COPE会社所有・私的利用可Corporate-Owned, Personally Enabled
- CRL証明書失効リストCertificate Revocation List
- CSR証明書署名要求Certificate Signing Request
- CSRFクロスサイトリクエストフォージェリCross-Site Request Forgery
- CVE共通脆弱性識別子Common Vulnerabilities and Exposures
- CVSS共通脆弱性評価システムCommon Vulnerability Scoring System
- CYOD承認端末からの選択Choose Your Own Device
D
- DAC任意アクセス制御Discretionary Access Control
- DAST動的アプリケーションセキュリティテストDynamic Application Security Testing
- DDoS分散型サービス妨害攻撃Distributed Denial of Service
- DKIMドメイン認証署名DomainKeys Identified Mail
- DLP情報漏えい防止Data Loss Prevention
- DMARCドメインベースのメール認証・報告Domain-based Message Authentication, Reporting and Conformance
- DMZ非武装地帯Demilitarized Zone
- DNSSECDNSセキュリティ拡張DNS Security Extensions
- DRP災害復旧計画Disaster Recovery Plan
E
- EAP拡張認証プロトコルExtensible Authentication Protocol
- ECC楕円曲線暗号Elliptic Curve Cryptography
- EDRエンドポイントでの検知と対応Endpoint Detection and Response
- EF暴露係数Exposure Factor
F
G
H
- HMACハッシュベースのメッセージ認証コードHash-based Message Authentication Code
- HSMハードウェアセキュリティモジュールHardware Security Module
I
- IaaSインフラストラクチャ・アズ・ア・サービスInfrastructure as a Service
- IaCコードによるインフラ管理Infrastructure as Code
- ICS産業制御システムIndustrial Control System
- IDS侵入検知システムIntrusion Detection System
- IoC侵害の痕跡Indicator of Compromise
- IoTモノのインターネットInternet of Things
- IPS侵入防止システムIntrusion Prevention System
L
M
- MAC強制アクセス制御/MACアドレスMandatory Access Control / Media Access Control
- MDMモバイルデバイス管理Mobile Device Management
- MFA多要素認証Multi-Factor Authentication
- MOU覚書Memorandum of Understanding
- MSA基本契約Master Service Agreement
- MTBF平均故障間隔Mean Time Between Failures
- MTTR平均修復時間Mean Time To Repair / Recover
N
- NACネットワークアクセス制御Network Access Control
- NDA秘密保持契約Non-Disclosure Agreement
- NGFW次世代ファイアウォールNext-Generation Firewall
O
- OAuth認可の委譲フレームワークOAuth 2.0
- OCSPオンライン証明書状態プロトコルOnline Certificate Status Protocol
- OIDCOpenID ConnectOpenID Connect
- OSINT公開情報インテリジェンスOpen Source Intelligence
- OT制御技術Operational Technology
P
- PaaSプラットフォーム・アズ・ア・サービスPlatform as a Service
- PAM特権アクセス管理Privileged Access Management
- PCI DSSクレジットカード業界のデータセキュリティ基準Payment Card Industry Data Security Standard
- PEPポリシー実施ポイントPolicy Enforcement Point
- PHI保護対象医療情報Protected Health Information
- PII個人を特定できる情報Personally Identifiable Information
- PKI公開鍵基盤Public Key Infrastructure
R
- RADIUSRADIUS認証Remote Authentication Dial-In User Service
- RBACロールベースアクセス制御Role-Based Access Control
- RCEリモートコード実行Remote Code Execution
- RPO目標復旧時点Recovery Point Objective
- RSARSA暗号Rivest–Shamir–Adleman
- RTO目標復旧時間Recovery Time Objective
S
- SaaSソフトウェア・アズ・ア・サービスSoftware as a Service
- SAMLSAMLSecurity Assertion Markup Language
- SASEセキュアアクセスサービスエッジSecure Access Service Edge
- SAST静的アプリケーションセキュリティテストStatic Application Security Testing
- SBOMソフトウェア部品表Software Bill of Materials
- SCADA監視制御・データ収集システムSupervisory Control and Data Acquisition
- SD-WANソフトウェア定義WANSoftware-Defined Wide Area Network
- SHAセキュアハッシュアルゴリズムSecure Hash Algorithm
- SIEMセキュリティ情報・イベント管理Security Information and Event Management
- SLAサービスレベル合意Service Level Agreement
- SLE単一損失予想額Single Loss Expectancy
- SOARセキュリティのオーケストレーション・自動化・対応Security Orchestration, Automation and Response
- SOCセキュリティ監視センターSecurity Operations Center
- SOW作業範囲記述書Statement of Work
- SPF送信者ポリシーフレームワークSender Policy Framework
- SQLiSQLインジェクションSQL Injection
- SSOシングルサインオンSingle Sign-On
- SSRFサーバーサイドリクエストフォージェリServer-Side Request Forgery
- STIX脅威情報の構造化記述形式Structured Threat Information eXpression
T
- TACACS+TACACS+Terminal Access Controller Access-Control System Plus
- TAXII脅威情報の自動交換プロトコルTrusted Automated eXchange of Intelligence Information
- TDE透過的データ暗号化Transparent Data Encryption
- TLSトランスポート層セキュリティTransport Layer Security
- TPMトラステッドプラットフォームモジュールTrusted Platform Module
- TTP戦術・技術・手順Tactics, Techniques, and Procedures
U
V
W
X
Z
0-9
略語を覚えたら、問題で確認しましょう。
無料で演習を始める