For the complete documentation index, see llms.txt. This page is also available as Markdown.

Glossary

ABAC

Attribute-Based Access Control. Access decisions based on attributes such as role, clearance, project, classification, device, location or risk context.

BPSS

Baseline Personnel Security Standard. A baseline screening process, not a national security clearance.

CAF

Cyber Assessment Framework. NCSC framework for assessing cyber resilience for organisations responsible for essential functions.

CSM

Cyber Security Model. MOD model for assessing supplier cyber risk and control requirements.

DEFCON 658

MOD defence condition used to contractually apply cyber security requirements.

DPIA

Data Protection Impact Assessment.

Def Stan 05-138

Defence standard specifying cyber controls for defence suppliers at each cyber risk profile level.

IAM

Identity and Access Management.

JML

Joiners, Movers and Leavers access lifecycle process.

JSP 453

MOD Digital Policies and Standards for Defence. Treat as customer or sponsor-controlled where applicable.

Least privilege

Granting only the access required to perform an approved function.

Need-to-know

Access only where the individual has a legitimate business or operational need.

OFFICIAL-SENSITIVE

A handling caveat used where OFFICIAL information needs additional handling protection.

PAM

Privileged Access Management.

RBAC

Role-Based Access Control.

RPO

Recovery Point Objective.

RTO

Recovery Time Objective.

SBOM

Software Bill of Materials.

Secure by Design

Approach that embeds security throughout planning, design, delivery and operation.

Zero trust

Architecture approach that removes inherent trust from networks and verifies access requests against policy.

Last updated

Was this helpful?