セキュリティ用語の略語集
この用語集は、現代のサイバーセキュリティフレームワークやツールで使われる一般的なセキュリティの略語・用語のクイックリファレンスです。セキュリティドキュメント、コンプライアンス要件、アプリケーション・クラウドセキュリティに関する技術的な議論をより深く理解するためにご活用ください。
AICPA SOC 2 - System and Organization Controls 2(システムと組織の内部統制に関する保証報告)
CVE - Common Vulnerabilities and Exposures
ASPM - Application Security Posture Management
CSPM - Cloud Security Posture Management
SAST - Static Application Security Testing
SCA - Software Composition Analysis
DAST - Dynamic Application Security Testing
EASM - External Attack Surface Management
CNAPP - Cloud-Native Application Protection Platform
DSPM - Data security posture management
SIEM - Security Information and Event Management(セキュリティ情報イベント管理)
RASP - Runtime Application Self Protection
WAF - Web App Firewall
GRC - Governance Risk & Compliance
MDR - Managed Detection Response
SBOM - Software Bill of Materials
NIS2 - Network and Information Security Directive 2(EUネットワーク・情報セキュリティ指令2)
OWASP - Open Worldwide Application Security Project(オープンなWebアプリケーションセキュリティのコミュニティ団体)