Terms for IT/OT operations and security

Concise, directly linkable definitions for asset inventories, OT security, critical infrastructure, standards, and platform operations. Each entry stays visible, citable, and connected to sources.

  1. An entitlement defines the scope a tenant receives in an application, such as a plan tier, a limit, or an unlocked feature.

    Entitlements separate the commercial scope from the program logic. The platform holds the values per tenant centrally, and the application queries them at runtime instead of storing them itself.

  2. EOL/EOS describes lifecycle states in which a vendor no longer regularly maintains, sells, or supports a product, firmware, or system.

    For OT and critical-infrastructure operators, EOL/EOS data is operationally important: it affects spare-part planning, maintenance windows, patchability, vulnerability prioritization, and which risks must be accepted or compensated for.

  3. The EUVD is the European vulnerability database operated by ENISA for publicly known vulnerabilities in ICT products and services.

    The EUVD aggregates actionable vulnerability information such as affected products, severity, exploitation status, patches, and notes from CSIRTs or vendors.

  4. A FAT is a factory acceptance test in which a system is checked against its requirements at the manufacturer before delivery.

    FATs help to verify functions, interfaces, and security assumptions early, before a plant is installed in its target environment.

  5. Hardening is the targeted securing of a system by reducing its attack surface.

    Typical measures include secure configurations, disabled services, restrictive permissions, segmentation, logging, and controlled change processes.

  6. An HMI is an operator interface through which people observe and control machines, plants, or processes.

    In OT, an HMI is often critical to operations because operator actions, alarms, process data, and plant status come together there.

  7. HVAC refers to systems for heating, ventilation, and air conditioning.

    HVAC systems are relevant infrastructure assets because they are increasingly networked and influence availability, energy consumption, comfort, and operational safety.

  8. IACS refers to industrial automation and control systems, the technical and organizational components needed to run automated plants safely.

    According to DKE, the IACS term covers hardware, software, and organizational processes for installation and operation, which is exactly what the IEC 62443 series targets.

  9. An IdP creates and manages identity information and provides authentication services for applications.

    In platforms and SaaS environments, an IdP lets users sign in via existing enterprise identities or federated accounts instead of creating isolated logins.

  10. An IDS monitors systems or networks for signs of attacks, policy violations, or suspicious activity.

    An IDS is no substitute for asset context: only when the affected systems are known does it become clear how urgent a finding is and who must respond.

  11. IEC stands for the International Electrotechnical Commission, an international standards body for electrical, electronic, and related technologies.

    For industrial cybersecurity, the IEC is particularly relevant through the IEC 62443 standards series.

  12. IEC 62443 is a series of standards for cybersecurity in industrial automation and control systems.

    It addresses roles, IACS, zones, conduits, security levels, technical requirements, secure product development, and security programs for manufacturers, integrators, and operators.

  13. IIoT is the industrial Internet of Things, the connection of cyber-physical production systems with IT systems, data platforms, and cloud or edge architectures.

    Compared to consumer IoT, IIoT environments have higher requirements for bandwidth, low latency, standardized data formats, IT security, and high availability.

  14. IoT stands for Internet of Things and refers to networked devices that communicate locally or over the internet with other devices, services, or cloud systems.

    From a security perspective, secure authentication, update management, and protected communication are central because poorly secured IoT devices can endanger personal data, business data, or infrastructure.

  15. An ISMS is a management system that organizations use to govern information-security risks, roles, rules, measures, and evidence in a structured way.

    In the IEC 62443 context, part 2-1 describes elements of an ISMS for IACS operators; in classic IT, ISMS is often associated with ISO/IEC 27001.

  16. ISO/IEC 27001 is an international standard for information-security management systems.

    The standard requires structured management of risks, responsibilities, controls, and evidence; asset inventories are a foundational input.

  17. IT comprises systems, networks, and software that process, store, transmit, or provide information.

    In companies, IT typically covers servers, clients, identities, applications, cloud services, networks, and data processes.

  18. Microsoft Entra ID is a cloud-based identity and access management service for users, devices, applications, and resources.

    In operations, Entra ID matters for sign-in, Conditional Access, groups, roles, device identities, and SaaS access. It becomes especially useful for security and inventory work when identity data is connected with assets, MDM, EDR, and ITSM.