A SAT is an acceptance test at the real deployment site of a system.
It verifies that a delivered system functions correctly in its target environment, with real interfaces, processes, and operating conditions.
SCADA refers to systems for monitoring and remotely controlling industrial processes.
SCADA systems collect process data, visualize states, forward alarms, and enable operator actions across distributed installations.
Security awareness describes people's knowledge of security risks and the expected behavior in everyday operations.
It matters because technical safeguards are only resilient when teams recognize warning signs, follow processes, and report incidents.
Security Levels in IEC 62443 describe qualitative protection levels for zones, conduits, systems, or components.
Levels range from Level 1 for unintentional or accidental attacks to Level 4 for targeted attacks with high effort, specific expertise, and high motivation.
A security plan or security program describes the rules, processes, responsibilities, and evidence an organization maintains to protect its IACS.
IEC 62443-2-1 addresses security-program requirements for IACS operators; in practice this includes policies, procedures, roles, staffing, review, and technical implementation in operations.
Segmentation divides a network into bounded areas so that data flows, access, and risk become more controllable.
In OT, segmentation helps to limit lateral movement and to separate sensitive plant areas from less-trusted networks.
A supply chain is the network of people, organizations, components, software, services, and processes that enable a product or service.
In cybersecurity, supply-chain transparency matters because vulnerabilities, vendor advisories, and dependencies often originate outside the organization.
SzA stands for systems for attack detection: technically supported and organizationally embedded processes to detect attacks on IT systems.
For KRITIS and energy environments, it is not just a tool but ongoing collection, analysis, threat detection, response, and auditable organizational integration.
A TPM is a dedicated security chip or integrated security processor that stores cryptographic keys securely.
TPM features help to protect device identity, encryption, and platform integrity; Windows functions such as BitLocker or Windows Hello can use the TPM.
Virtualization provides a simulated computing environment instead of using a physical environment directly.
A physical server can be partitioned into multiple virtual machines, each running its own operating system or applications and sharing host resources.
A vulnerability is an exploitable weakness in software, hardware, configuration, process, or architecture.
Whether a vulnerability is critical depends on the affected asset, exposure, existing controls, and the impact on operations and safety.
Zones & Conduits is an IEC 62443 concept that groups systems with similar protection needs into security zones and describes permitted communication paths between these zones as conduits.
The model documents protection needs, permitted data flows, and segmentation in a traceable way; communication outside defined conduits should not be allowed.
Terms for IT/OT operations and security
Concise, directly linkable definitions for asset inventories, OT security, critical infrastructure, standards, and platform operations. Each entry stays visible, citable, and connected to sources.