コンテンツにスキップ

セキュリティ用語の略語集

この用語集は、現代のサイバーセキュリティフレームワークやツールで使われる一般的なセキュリティの略語・用語のクイックリファレンスです。セキュリティドキュメント、コンプライアンス要件、アプリケーション・クラウドセキュリティに関する技術的な議論をより深く理解するためにご活用ください。

AICPA SOC 2 - System and Organization Controls 2(システムと組織の内部統制に関する保証報告)

CI/CD Pipeline Security

CVE - Common Vulnerabilities and Exposures

ISO 27001:2022

ASPM - Application Security Posture Management

CSPM - Cloud Security Posture Management

SAST - Static Application Security Testing

SCA - Software Composition Analysis

DAST - Dynamic Application Security Testing

EASM - External Attack Surface Management

IaC - Infrastructure as Code

CNAPP - Cloud-Native Application Protection Platform

DSPM - Data security posture management

SIEM - Security Information and Event Management(セキュリティ情報イベント管理)

RASP - Runtime Application Self Protection

WAF - Web App Firewall

GRC - Governance Risk & Compliance

MDR - Managed Detection Response

SBOM - Software Bill of Materials

NIS2 - Network and Information Security Directive 2(EUネットワーク・情報セキュリティ指令2)

OWASP - Open Worldwide Application Security Project(オープンなWebアプリケーションセキュリティのコミュニティ団体)

XSS Vulnerabilities