Terms for IT/OT operations and security

Concise, directly linkable definitions for asset inventories, OT security, critical infrastructure, standards, and platform operations. Each entry stays visible, citable, and connected to sources.

  1. AAS stands for Asset Administration Shell and describes a standardized digital wrapper for assets in Industry 4.0.

    The AAS supports standards-compliant data exchange along the lifecycle, creates vendor-neutral interoperability, and can be understood as an Industry 4.0 implementation of the digital twin.

  2. APT stands for Advanced Persistent Threat and refers to a targeted, well-prepared, long-running attack on a network or system.

    APTs are especially critical for companies because attackers often spy, manipulate data, move laterally, or disrupt business-critical systems over extended periods.

  3. An asset is a physical or digital element that is relevant to operations, control, monitoring, or security.

    In IT and OT environments, assets can be machines, servers, controllers, software, networks, sensors, locations, evidence, or responsibilities.

  4. A B3S is an industry-specific security standard used by critical-infrastructure sectors in Germany to make state-of-the-art requirements concrete.

    An approved B3S is not automatically binding for every organization, but can provide guidance and legal certainty about the state of the art during evidence and audit work.

  5. The BSI is Germany's central federal authority for cyber and information security.

    For German companies and KRITIS operators, the BSI is relevant for standards, situation reports, minimum requirements, and reporting paths.

  6. A CERT is an organizational point of contact that receives, assesses, and coordinates security reports and publishes warnings or advisories.

    In industrial supply chains, CERT and ProductCERT information matters because operators can use advisories, RSS, or CSAF feeds to quickly identify which products are affected.

  7. CIS stands for Center for Internet Security, an organization that publishes practical security benchmarks and controls.

    The CIS Controls are widely used as a best-practice catalog, even though industrial environments have additional OT-specific requirements.

  8. Cloud refers to on-demand IT resources such as compute, storage, platforms, or software that are consumed over a network.

    In operations, cloud services matter for scaling, cost control, identities, permissions, data flows, asset inventory, compliance, and security evidence.

  9. A CMDB is a database for configuration items such as systems, applications, services, relationships, and technical dependencies.

    In operations, a CMDB supports incident, change, and service processes. Data quality is the critical factor: without current reconciliation against inventories, identities, and observations, it quickly becomes static documentation.

  10. A contributor is a person or organization that contributes work, knowledge, code, review, funding, or operating experience to an initiative.

    In open security projects, transparent contributors matter so the origin, maintenance, and expertise behind a project remain traceable.

  11. A cookie is a small file a website stores in the browser to recognize a session or settings across multiple visits.

    After sign-in, a session cookie keeps the user logged in without re-authenticating on every page view. Depending on its purpose, a cookie may be strictly necessary or require consent.

  12. CSAF is a machine-processable format for security advisories, structured security information about vulnerabilities.

    CSAF helps vulnerability management because advisories can be retrieved automatically and matched against asset inventories, products, or SBOMs.

  13. CVE is a public identification system for known cybersecurity vulnerabilities.

    A CVE ID makes a vulnerability referenceable; decisions need additional context such as the affected asset, exposure, and criticality.

  14. A cyber attack is a deliberate attempt to disrupt, manipulate, or use systems, networks, data, or processes without authorization.

    In OT, a cyber attack can affect more than data. It can impact availability, human safety, plant condition, and physical processes.

  15. A cyber-physical system connects digital control, communication, and real physical processes.

    Examples include production lines, energy plants, smart building technology, or connected machines where software acts directly on the real world.

  16. Defense in depth describes a layered security concept in which attackers must overcome multiple organizational, physical, network, system, and component measures.

    IEC 62443 uses this approach for industrial plants and distributes contributions across operators, integrators, and manufacturers instead of relying on a single safeguard.

  17. A DMZ is a separated network segment between security zones that reduces direct connections into highly protected networks.

    In IT/OT architectures, a DMZ often sits between enterprise IT and OT. It concentrates controlled transitions, remote access, data exchange, and monitoring so critical facilities are not unnecessarily reachable through direct connections.

  18. EDR stands for endpoint detection and response and describes security capabilities for detecting, investigating, and responding to threats on endpoints.

    EDR provides important signals about clients and servers, but it does not replace an asset inventory. Prioritization still needs context such as owner, criticality, software state, network context, and affected services.