Terms for IT/OT operations and security

Concise, directly linkable definitions for asset inventories, OT security, critical infrastructure, standards, and platform operations. Each entry stays visible, citable, and connected to sources.

  1. A risk assessment evaluates threats, impacts, and protection needs so security measures are set based on risk rather than uniformly.

    IEC 62443-3-2 uses risk analysis to define the system under consideration, divide it into zones and conduits, and assign target security levels.

  2. RMM stands for remote monitoring and management and describes software that lets IT teams or MSPs monitor and manage systems, endpoints, and networks remotely.

    RMM provides important operational data about availability, patches, agents, hardware, software, and remote support. Reliable decisions need reconciliation with asset inventory, PSA, identities, EDR, MDM, and customer scope.

  3. SaaS stands for Software as a Service and describes cloud software consumed as a service without customers operating the underlying infrastructure themselves.

    In IT operations, SaaS services matter for cost control, identities, permissions, data flows, contract management, offboarding, and audit evidence.

  4. A SAT is an acceptance test at the real deployment site of a system.

    It verifies that a delivered system functions correctly in its target environment, with real interfaces, processes, and operating conditions.

  5. An SBOM (software bill of materials) is a machine-readable list of a product's software components and their dependencies.

    The CRA requires an SBOM covering at least the product's direct software dependencies; BSI TR-03183 specifies formal and technical requirements. An SBOM does not replace an inventory of the devices actually installed.

  6. SCADA refers to systems for monitoring and remotely controlling industrial processes.

    SCADA systems collect process data, visualize states, forward alarms, and enable operator actions across distributed installations.

  7. Security awareness describes people's knowledge of security risks and the expected behavior in everyday operations.

    It matters because technical safeguards are only resilient when teams recognize warning signs, follow processes, and report incidents.

  8. Security Levels in IEC 62443 describe qualitative protection levels for zones, conduits, systems, or components.

    Levels range from Level 1 for unintentional or accidental attacks to Level 4 for targeted attacks with high effort, specific expertise, and high motivation.

  9. A security plan or security program describes the rules, processes, responsibilities, and evidence an organization maintains to protect its IACS.

    IEC 62443-2-1 addresses security-program requirements for IACS operators; in practice this includes policies, procedures, roles, staffing, review, and technical implementation in operations.

  10. Segmentation divides a network into bounded areas so that data flows, access, and risk become more controllable.

    In OT, segmentation helps to limit lateral movement and to separate sensitive plant areas from less-trusted networks.

  11. A supply chain is the network of people, organizations, components, software, services, and processes that enable a product or service.

    In cybersecurity, supply-chain transparency matters because vulnerabilities, vendor advisories, and dependencies often originate outside the organization.

  12. SzA stands for systems for attack detection: technically supported and organizationally embedded processes to detect attacks on IT systems.

    For KRITIS and energy environments, it is not just a tool but ongoing collection, analysis, threat detection, response, and auditable organizational integration.

  13. A TPM is a dedicated security chip or integrated security processor that stores cryptographic keys securely.

    TPM features help to protect device identity, encryption, and platform integrity; Windows functions such as BitLocker or Windows Hello can use the TPM.

  14. Virtualization provides a simulated computing environment instead of using a physical environment directly.

    A physical server can be partitioned into multiple virtual machines, each running its own operating system or applications and sharing host resources.

  15. A vulnerability is an exploitable weakness in software, hardware, configuration, process, or architecture.

    Whether a vulnerability is critical depends on the affected asset, exposure, existing controls, and the impact on operations and safety.

  16. Zones & Conduits is an IEC 62443 concept that groups systems with similar protection needs into security zones and describes permitted communication paths between these zones as conduits.

    The model documents protection needs, permitted data flows, and segmentation in a traceable way; communication outside defined conduits should not be allowed.