IT vocabulary, without the jargon.
Clear definitions of the cybersecurity, compliance and technology terms that come up most in our projects: NIS2, ENS, EDR, Zero Trust and more.
-
NIS2
NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It establishes obligations for covered essential and important entities concerning risk-management measures, governance, incident reporting and supervision, while Member States implement it through national law. Applicability depends on sector, entity type, size, jurisdiction and specific rules; supplying technology to a covered customer does not automatically place every provider in the same category. Compliance requires organisational and technical evidence, supplier-risk management, continuity and reporting processes rather than one certificate or tool. A glossary cannot determine whether an organisation is in scope. The current directive, national implementing law and competent guidance should be checked for each legal entity, service and country, with qualified advice where needed.
IT glossary -
National Security Framework (ENS)
Spain’s National Security Framework, known as ENS, establishes security principles and requirements for public-sector systems and for covered entities when they provide services or solutions. System category and scope determine measures, responsibilities and assessment; applying a generic control list is insufficient. Compliance or certification must be checked against the specific entity, system, category, scope and validity. ENS is not a universal company certification and does not guarantee absence of incidents. An organisation should maintain policy, risk analysis, an applicability statement, evidence, supplier management, incident handling and improvement. For an international context, the Spanish ENS should not be presented as an automatic substitute for local law or other applicable frameworks. Applicability must be confirmed from Royal Decree 311/2022 and competent guidance.
IT glossary -
DORA
DORA, Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, establishes harmonised requirements for in-scope financial entities concerning ICT risk management, incidents, resilience testing, third-party risk and information sharing. It has applied since 17 January 2025. It also creates an EU oversight framework for ICT third-party service providers designated as critical; this does not mean every technology supplier is directly supervised or certified. Scope depends on the specific entity, service, function and contractual relationship. Compliance requires governance, evidence, registers, contracts and proportionate testing rather than purchase of one tool. Applicability and interpretation should be checked against the current official text and competent advice for each organisation, because a glossary summary cannot determine a particular legal obligation.
IT glossary -
GDPR
The GDPR, Regulation (EU) 2016/679, governs protection of natural persons when personal data is processed and the free movement of that data. Applicability depends on the specific activity, establishment, people affected and territorial reach. Duties may include principles, legal basis, transparency, rights, security, processors, records, assessments and breach notification according to the processing. Compliance is not achieved by publishing a policy or buying a tool. An organisation should know purposes, data, flows, retention, recipients and owners and demonstrate risk-proportionate decisions. Anonymisation, pseudonymisation and encryption are not equivalent. A general definition cannot determine obligations for one case; the current official text, competent authorities and qualified advice should be consulted where appropriate.
IT glossary -
EDR (Endpoint Detection and Response)
EDR (Endpoint Detection and Response) collects endpoint activity to detect, investigate and respond to suspicious behaviour on computers, servers or other supported devices. It may correlate processes, files, network activity and identity and provide isolation or remediation actions, depending on the product and permissions. EDR extends traditional prevention but does not guarantee real-time detection or complete coverage. Unmanaged devices, disabled agents, unsupported systems and poorly tuned rules create gaps. Deployment should define assets, policies, retention, privacy, response authority, exceptions and integration with incident handling. Teams need to test safe scenarios, monitor agent health and review false positives. An alert is not a resolved incident, and “zero detections” is meaningful only when telemetry coverage and the detection pipeline are known to be healthy.
IT glossary -
XDR (Extended Detection and Response)
XDR (Extended Detection and Response) combines security signals from multiple domains such as endpoints, identity, email, network and cloud to support detection, investigation and response. Products differ substantially in the data they ingest, retain and correlate, so the label alone does not define coverage. XDR can reduce investigation effort when identities, timestamps and assets reconcile correctly, but automation may also propagate a bad decision. Deployment should identify authoritative data sources, missing assets, permissions, retention, escalation and which response actions require approval. Detection content needs tuning against the organisation’s environment and threat model. Validation uses known test scenarios and traces each event from collection to alert and containment. An empty console may mean no threat, a blind spot or a failed connector; source health must therefore be monitored separately.
IT glossary -
MDR (Managed Detection and Response)
MDR (Managed Detection and Response) is a service in which a provider helps operate detection, investigation and response using agreed telemetry and tools. Scope may include endpoints, identity, network or cloud, but complete coverage or continuous attention should not be assumed unless the contract states it. MDR and EDR are not equivalent: one describes a managed operation and the other a technology capability. Before contracting, organisations should define sources, hours, severities, contacts, authority to contain, evidence preservation and retained responsibilities. Integrations and agents need health monitoring because a failed source reduces visibility. Evaluation should follow simulated cases from detection to closure and measure decision quality and time. More alerts or an attended console do not guarantee lower risk.
IT glossary -
SOC (Security Operations Center)
A SOC (Security Operations Center) combines people, processes and technology to monitor security signals, investigate events and coordinate incident response. It can be internal, outsourced or hybrid, and its operating hours depend on the contracted model; the term SOC does not automatically mean continuous coverage. Typical inputs include SIEM, endpoint or XDR telemetry, identity, network logs, threat intelligence and an asset inventory. Tools do not replace analysis. Evaluation should examine connected sources, asset coverage, detection rules, observed handling times, classification, evidence retention and responsibilities during an incident. A large alert count is not proof of effectiveness. Useful outcomes are contextual investigation, documented decisions, controlled escalation and completed corrective actions, tested against scenarios relevant to the organisation.
IT glossary -
SIEM (Security Information and Event Management)
A SIEM (Security Information and Event Management) collects, normalises and correlates events from multiple sources to support detection, investigation and evidence. It may combine identity, endpoint, server, application, network and cloud data, but only sees information that arrives with sufficient quality. Installing connectors or default rules does not guarantee coverage; clocks, fields, retention, volume and asset context need control. Deployment should define priority sources, use cases, owners, escalation and privacy boundaries. Rules are tuned with authorised tests and observed false positives. Useful measures include source health, ingestion delay and investigation time. An empty dashboard may mean no incident, an unsuitable rule or a failed source; these states must not be treated as equivalent.
IT glossary -
Zero Trust
Zero Trust is a security approach that avoids granting automatic trust from network location and requires explicit verification of identity, device, context and authorisation for each relevant access. It is not one product, a replacement name for VPN or an instruction to block everything. Implementation combines inventory, strong identity, least privilege, segmentation, device protection, policy, logging and response. Decisions rely on signals whose quality and availability need monitoring; missing data should not silently become trust. Adoption is usually incremental, beginning with higher-risk resources and journeys, with visible exceptions and recovery paths. Validation tests allowed and denied access, signal loss and revocation. Buying a product labelled Zero Trust does not prove that actual flows follow these principles.
IT glossary -
MFA (Multi-Factor Authentication)
MFA (Multi-Factor Authentication) requires evidence from at least two different factor categories, such as something known, possessed or inherent, before granting access. Two passwords are not two factors. MFA reduces the value of a stolen password, but strength varies: SMS, push prompts, authenticator codes, hardware keys and passkeys resist different attacks. Recovery and enrolment paths are part of the control and can become the easiest route around it. Design should cover privileged accounts, legacy protocols, service accounts, phishing resistance, lost devices, fallback and audit logs. Rollout needs representative testing and a controlled exception process. MFA complements secure sessions, least privilege and monitoring; it does not make a compromised device or approved malicious session safe.
IT glossary -
DLP (Data Loss Prevention)
DLP (Data Loss Prevention) combines policy, classification and controls to detect or limit unauthorised use of information. It may observe email, web, endpoints, cloud applications or removable devices, but coverage depends on the channels and data actually integrated. A rule does not understand business context by itself and may block legitimate work or miss poorly classified information. Deployment should define owners, categories, exceptions, response and handling of personal data. Observation mode and false-positive review help teams introduce blocking gradually. Encryption, access control and training perform complementary roles. Zero alerts can mean no leakage, an inadequate policy or a sensor that stopped reporting. Effectiveness therefore requires source-health monitoring, sampled validation and a process for reviewing exceptions rather than simply enabling a product.
IT glossary -
Ransomware
Ransomware is malicious software or an intrusion technique used to deny access to systems or data and demand payment. Modern campaigns may steal information before encryption, threaten disclosure, disrupt backups or use credentials to move through the network. Paying does not guarantee recovery or deletion of stolen data. Risk reduction combines identity protection, patching, segmentation, controlled privileges, endpoint and network detection, immutable or isolated backups, and rehearsed incident procedures. Backup completion alone is insufficient: organisations need tested restoration, known recovery objectives and copies that the attacker cannot alter. When an incident occurs, priorities include containment, evidence preservation, legal and regulatory assessment, safe recovery and communication. The exact sequence depends on the affected environment and the incident-response plan.
IT glossary -
Phishing
Phishing is social engineering that impersonates a trusted person, service or process to persuade someone to disclose information, approve access, send money or run malicious content. It may arrive through email, messaging, voice, QR codes or convincing websites and may use real account context. Filtering and awareness reduce exposure but neither catches every attempt. MFA helps, although some methods can still be bypassed through session theft or approval abuse. Defence should combine protected identity, verified payment or change procedures, reporting channels, browser and email controls and rapid response. Tests and exercises must be authorised and avoid shaming users. Useful measures include reporting speed, containment and repeated process weaknesses, not only how many recipients clicked a simulated message.
IT glossary -
3-2-1 backup rule
The 3-2-1 backup rule is a resilience guideline: keep at least three copies of important data, use two different storage types or failure domains, and place one copy off-site. Modern variants add an offline or immutable copy and verification. Counting copies is not enough if they share credentials, synchronise corruption or cannot be restored. The rule also does not define retention, recovery time, encryption, ownership or application consistency. A backup design should map data and dependencies, set RPO and RTO targets, isolate administration and monitor failed jobs. Regular restore exercises with acceptance criteria are essential because a successful backup status only confirms that a job completed. Results and exceptions should be recorded so protection gaps remain visible and actionable.
IT glossary -
RPO and RTO
RPO (Recovery Point Objective) and RTO (Recovery Time Objective) describe different business-continuity targets. RPO expresses the maximum acceptable amount of data loss after disruption, usually as the time between the incident and the latest recoverable state. RTO expresses how long a process can remain unavailable before an acceptable service level must be restored. Both should be set per process rather than per product because payroll, production and email may require different targets. Backup frequency influences RPO, while restoration capacity and dependencies influence RTO, but a completed backup proves neither. Organisations should map dependencies, define acceptance criteria and run timed recovery exercises. Test evidence, observed results and documented exceptions provide a firmer basis than vendor features or an untested continuity plan.
IT glossary -
vCISO (Virtual CISO)
A vCISO (virtual Chief Information Security Officer) provides security leadership through an external or fractional engagement. It may support governance, risk, policy, priorities, measures, suppliers and stakeholder communication, but it does not automatically replace legal, technical or business owners. Scope, time, authority and access vary by contract; the title does not guarantee continuous availability or certification. Organisations should define objectives, deliverables, conflicts, confidentiality, escalation and who approves and executes decisions. A useful strategy starts from actual assets, threats, obligations and capacity and maintains a visible risk and action record. Reports and meetings alone do not prove improvement. The service should measure outcomes, transfer knowledge and plan continuity and return of access at termination.
IT glossary -
SD-WAN
SD-WAN (Software-Defined Wide Area Network) uses central policy and software control to route traffic among sites, data centres and cloud services over one or more connections. It may select paths by application, quality, cost or availability and create an encrypted overlay, depending on the product. It cannot improve a saturated physical circuit or guarantee application performance by itself; underlay links, destinations and configuration still constrain the service. SD-WAN also does not automatically replace firewall, identity or segmentation. Design should cover applications, latency, loss, failure capacity, addressing, local breakout, monitoring and out-of-band management. Cutover, failover and recovery tests confirm how policies and active sessions behave before legacy circuits or equipment are removed.
IT glossary -
Microsoft 365
Microsoft 365 is a subscription family of cloud and desktop services that can include Exchange Online, Teams, SharePoint, OneDrive and Office applications, depending on the licence. Security, compliance, storage and management capabilities vary by plan and configuration; they should not be assumed from the product name. Microsoft operates the service platform, while the customer remains responsible for identities, permissions, devices, data governance, sharing and many retention or recovery choices. Adoption should define tenant ownership, administrative roles, MFA, guest access, data locations, lifecycle and exit. Native retention or recycle features are not automatically equivalent to an independent backup requirement. Licensing, configuration, monitoring and user behaviour determine the operational result more than simply moving email or files into the suite.
IT glossary -
Penetration test (pentest)
A penetration test is an authorised assessment that attempts to exploit vulnerabilities within a defined scope and period to demonstrate attack paths and impact. It differs from a basic automated scan through human validation and reasoning, but it does not prove absence of weaknesses outside what was tested. Before work begins, parties should agree systems, exclusions, data, timing, contacts, limits, stopping conditions and evidence handling. Production may require restricted techniques to avoid disruption. The report separates confirmed findings, risk, evidence and remediation without turning obtained access into unnecessary damage. After fixes, targeted retesting verifies relevant conditions. A completion certificate or tool name does not establish coverage, quality or continuous security; methodology, tester competence and exact scope matter.
IT glossary -
IT/OT segmentation
IT/OT segmentation separates and controls communication between information technology —users, business systems and office services— and operational technology —machines, controllers and physical processes. Its purpose is to limit lateral movement while allowing only necessary flows without compromising industrial safety or availability. It involves more than adding a firewall: teams need asset inventory, zones and conduits, justified rules, controlled remote access, logging and change management. Legacy protocols and narrow maintenance windows require cautious testing. Vendors, engineering workstations and shared services must also be included. Effective separation is verified against observed traffic and controlled failure scenarios; an updated diagram is valuable, but it does not prove that deployed rules match the approved design.
IT glossary -
SCADA
SCADA (Supervisory Control and Data Acquisition) monitors industrial processes and allows authorised supervision or control through field devices, communications, servers and operator interfaces. It is used in environments such as energy, water and manufacturing, but architecture and safety responsibilities vary. SCADA is not the process controller itself in every design and “real time” depends on operational requirements. Connectivity creates useful visibility and also dependencies and attack paths. Security should begin with asset and flow inventory, segmentation, controlled remote access, backups, logging and tested change procedures that respect safety and availability. Legacy protocols and limited maintenance windows require caution. Validation should cover data quality, alarms, loss of communications, manual operation and recovery, not just whether the dashboard displays values.
IT glossary -
OEE (Overall Equipment Effectiveness)
OEE (Overall Equipment Effectiveness) is a manufacturing indicator commonly calculated as availability multiplied by performance and quality. It shows how much of planned production time produced good output at the defined ideal rate. The figure depends on agreed definitions for planned time, stops, ideal cycle and good units, so values from different lines or companies may not be comparable. OEE does not explain root cause and should not become a target that encourages hiding downtime or defects. Teams use its components and loss categories to focus investigation, then verify improvement with operational evidence. Data collection, reason codes and change control matter as much as the formula. A rising OEE is useful only when safety, quality, demand and maintenance outcomes remain acceptable.
IT glossary -
Industry 4.0
Industry 4.0 describes the integration of industrial operations with connected sensors, machines, software and data to improve visibility, traceability, control and decision-making. Typical elements include industrial networks, edge computing, analytics, digital work instructions and links between operational technology and business systems. It is a transformation model rather than a single product, and it does not always require replacing existing machinery; gateways or staged integration may expose useful data from legacy equipment. Success depends on a defined operational outcome, reliable data and ownership, not on connecting everything. Programmes should address safety, cybersecurity, interoperability, latency, change control and workforce adoption. A limited pilot with measurable baseline and rollback criteria is safer than a broad rollout based only on technology demonstrations.
IT glossary -
WMS (Warehouse Management System)
A WMS (Warehouse Management System) coordinates warehouse activities such as receiving, putaway, replenishment, picking, packing and dispatch. It may exchange orders and stock movements with ERP, transport, automation, carrier and customer systems. The WMS record is only reliable when master data, scanning, interfaces and exception procedures are controlled. Wireless coverage, handheld devices, printers and identity services can be as operationally important as the application. Before implementation, teams should define location structure, units, lot or serial rules, roles, cut-off times and what happens when an integration or device fails. Tests should follow complete physical journeys and reconcile quantities and status across systems. Faster screens do not guarantee better throughput; layout, workload, training, data quality and process constraints must be measured together.
IT glossary -
POS (Point of Sale)
A POS (Point of Sale) system records a sale and may coordinate products, prices, taxes, stock, receipts and payment devices. The till, application, network, payment terminal and back-office platform can have different owners and failure modes. A card terminal is therefore only one component, and processing a payment does not prove that inventory or accounting was updated. Design should separate payment data from other traffic where required, restrict access, maintain supported software and define offline behaviour. Availability planning considers power, connectivity, peripherals, credentials and reconciliation after recovery. Support procedures should identify the affected component before replacing equipment. Useful tests cover a complete transaction, refund, receipt, stock update and failure recovery. Security scope and validation depend on the actual payment-data flow, not merely on calling the device a POS.
IT glossary -
Omnichannel
Omnichannel coordinates physical and digital channels so a person can continue an interaction without losing context when the process supports it. Identity, catalogue, stock, orders, support and returns may be shared, but every channel need not offer identical functions. The challenge is aligning data, rules and ownership rather than merely adding an application. Before implementation, teams should define priority journeys, systems of record, inventory update timing, consent, exceptions and behaviour when an integration fails. Measures such as abandonment, resolution, stock accuracy and cycle time should be evaluated by journey. A single customer or inventory view that is wrong can be more damaging than separate channels, so reconciliation, data quality and a manual recovery path are operational requirements.
IT glossary -
VLAN
A VLAN (Virtual Local Area Network) creates a logical Layer 2 broadcast domain across compatible network equipment. It can separate users, voice, guests, management or devices without requiring a different physical switch for each group. VLANs organise traffic but do not automatically enforce security: communication between them depends on routing, firewall rules and access controls. Tags, native VLANs, trunks and allowed lists must agree across links, while endpoint ports normally use the intended access VLAN. Poor configuration can cause leakage, loops or loss of connectivity. Design should document identifiers, subnets, gateways, DHCP, ownership and permitted flows. Validation checks isolation and required communication from real ports and wireless networks. A VLAN diagram alone is insufficient unless switch configuration, routing and policy remain reconciled after changes.
IT glossary -
Purdue model
The Purdue Model organises industrial functions into levels from physical process and control through operations and enterprise systems, helping teams reason about dependencies and separation. It is a conceptual reference, not a universal map or a rule that all communication must follow one rigid hierarchy. Modern environments may include cloud, remote access, IIoT and safety systems that require explicit representation. Design should start with actual assets and flows, zones, conduits, owners and operational impact. Placing a firewall between levels does not guarantee segmentation if alternative routes or broad rules exist. Inventory and diagrams need reconciliation with configuration. Authorised tests verify required and denied communication, operation during connectivity loss and recovery while respecting process safety and availability.
IT glossary -
SLA (Service Level Agreement)
An SLA (Service Level Agreement) records measurable commitments between customer and provider for a defined service. It may include hours, availability, response time, priority, resolution, maintenance, exclusions, dependencies and measurement method. Response does not necessarily mean resolution, and an average can hide critical incidents; each metric needs clear start, pause, data source and time zone. The agreement should also separate supplier and customer duties such as access, approval or required information. Penalties do not replace continuity or correct a poorly designed objective. Review should use reconciled reports, explained exceptions and trends rather than only green percentages. An SLA is useful when it reflects real impact, is operationally achievable and leads to defined actions.
IT glossary -
Managed IT services (MSP)
Managed IT services assign recurring technology operations to a provider, commonly called an MSP. Scope may include help desk, monitoring, patching, backup, identity, cloud administration or security, but the label does not guarantee a particular tool, service window, response time or fee. Compared with break-fix support, the model aims to use inventory, prevention, alerts, procedures and periodic review. A useful agreement identifies included systems, ownership, priorities, maintenance windows, vendor escalation, evidence, change handling and exit conditions. Metrics need a known source and reporting period, and missing telemetry must not be reported as healthy. Managed service can replace an internal function or complement one; in either case, responsibilities between the client, provider and third parties should be explicit.
IT glossary -
IT outsourcing
IT outsourcing means assigning an external provider some or all technology functions. It may cover specific roles, helpdesk, administration, security, projects or service coordination; it does not necessarily transfer strategy or the whole department. Unlike a one-off intervention, it establishes ongoing responsibilities and an operating relationship. Before contracting, organisations should define scope, ownership of assets and data, hours, escalation, metrics, access, subcontractors, exit and coordination with internal teams. The provider remains subject to customer priorities and agreed controls. Labels such as “outsourced IT department” do not guarantee national coverage, response times or a particular staffing model. A sound arrangement makes exclusions, dependencies and retained customer responsibilities visible and tests how knowledge and access will be returned at termination.
IT glossary -
Virtualisation
Virtualisation abstracts physical resources so virtual machines or other isolated environments can run on a hypervisor. It enables workload consolidation and allocation of CPU, memory, storage and networking through a shared management layer. It does not create unlimited capacity or automatic availability: contention, drivers, licences, storage, network and failure domains still matter. A snapshot can support a short change but is not an independent backup or tested recovery process. Design should map workloads, dependencies, reservations, growth, administrative access and behaviour when a host fails. Guest and hypervisor monitoring answer different questions. Validation measures performance and recovery under representative load. Consolidating many services also concentrates impact, so redundancy and operations need evidence.
IT glossary -
High availability (HA)
High availability (HA) is an architectural approach that reduces service interruption by removing single points of failure and using redundancy, health checks and failover. It can apply to power, networks, compute, storage, applications and people, but duplicating one component does not make the whole service highly available. Availability percentages require a defined measurement window, exclusions and service boundary; “five nines” is a target, not a feature. HA is also different from backup and disaster recovery: replicated corruption or a regional dependency can affect redundant nodes at once. Design should examine quorum, capacity during failure, maintenance, data consistency and failback. Regular fault tests and observed recovery times are needed to confirm that automation works and that dependent services remain usable.
IT glossary -
Disaster recovery (DR)
Disaster recovery (DR) is the combination of plans, people, technology and procedures used to restore systems and data after a serious disruption. It should start from priority business processes, dependencies and approved RPO and RTO targets rather than from a replication product. Backup, high availability and DR are complementary: available data does not prove that identity, networks, applications and teams can operate. A plan should define who declares a disaster, communication, recovery order, acceptance criteria and return to normal service. Regular timed exercises should cover plausible failures and record results and exceptions. An untested document or a replica using the same administrative credentials can create confidence without recoverability. Evidence from restoration tests is more useful than a successful backup or replication status alone.
IT glossary -
Business continuity plan (BCP)
A business continuity plan (BCP) defines how priority products and processes will continue or recover during disruption. It starts from business-impact analysis covering time, dependencies, minimum resources and alternatives; it is not only an IT document. The plan assigns owners, activation criteria, communications, locations, suppliers, manual work and return to normal. Backup, disaster recovery, redundancy and crisis management support different parts. Priorities should consider people, facilities, data, technology and third parties. A plan whose contacts or access depend on the affected system may fail. Tabletop exercises and operational tests validate assumptions, timing and decisions and generate corrective actions. Possessing a document does not demonstrate continuity capability unless it remains current, accessible and exercised.
IT glossary -
Immutable backup
An immutable backup is a recovery copy protected from alteration or deletion for a defined retention period, including by ordinary administrative actions. Immutability can reduce the risk that ransomware or a compromised account destroys every copy, but implementation varies by storage, credentials and retention controls. It does not guarantee that the captured data is complete, clean or restorable, and a misconfigured source may faithfully preserve unusable content. Design should separate duties, protect backup identities, define retention locks, monitor failures and preserve at least one independent path where appropriate. Capacity and legal retention also require planning because locked data may not be removable early. Recovery tests must select real workloads and verify integrity, dependencies and time. A successful backup job is evidence of copying, not proof of recoverability.
IT glossary -
Firewall
A firewall enforces network-traffic policy between defined zones, hosts or applications. It can filter by addresses, ports, state, identity or application context, depending on the product and placement. A rule that permits required traffic may also broaden exposure, while a block can interrupt legitimate service. Design should begin with documented flows, default behaviour, ownership, logging and a controlled exception process. Internet-edge filtering is only one layer; internal segmentation and host controls address different paths. Firmware, signatures and administrative access require maintenance. Rule reviews should examine usage, shadowing, temporary access and business owner rather than merely count entries. Tests confirm both allowed and denied journeys from relevant locations. A clean dashboard does not prove security if traffic bypasses the firewall or logging has failed.
IT glossary -
VPN (Virtual Private Network)
A VPN (Virtual Private Network) creates an encrypted tunnel between a device, network or service and a VPN endpoint across an untrusted network such as the internet. Remote-access VPNs connect individual users, while site-to-site VPNs link networks. Encryption protects traffic in transit through the tunnel, but it does not make an infected device trustworthy or automatically restrict what an authenticated user can reach. A secure design also considers multi-factor authentication, device posture, least privilege, logging, split tunnelling, key management and redundancy. Performance depends on latency, bandwidth and the encryption endpoint. Some organisations use Zero Trust Network Access for more granular application access, but the approaches can coexist. Selection should follow the applications, users, risks and recovery needs involved.
IT glossary -
SAN (Storage Area Network)
A SAN (Storage Area Network) provides block-level storage connectivity between servers and shared storage, commonly using Fibre Channel or iSCSI. Hosts see logical volumes rather than ordinary network file shares. A SAN can centralise capacity and support clusters, but high performance or availability is not automatic: controllers, fabrics, paths, zoning, multipathing, cache and workloads must be designed together. Redundancy should avoid shared failure points and be tested during maintenance and faults. Access controls, firmware, monitoring, snapshots and backup have separate roles; a snapshot on the same array is not an independent recovery copy. Sizing should use latency, throughput, IOPS, queue behaviour and growth. Clear ownership and change procedures reduce the risk of one storage change affecting many systems.
IT glossary -
Helpdesk
A helpdesk is an organised point for users to report incidents, request services and obtain support. It may use phone, portal, email or chat, but the channel is not the service itself. Effective operation defines scope, hours, priorities, ownership, escalation, communication and closure evidence. First response and final resolution are different measures, and closing a ticket does not prove the user’s outcome was restored. Knowledge articles and automation can improve consistency when they are current and exceptions reach a person. Identity should be verified before sensitive changes, and records should avoid unnecessary personal data. Demand, backlog, repeat contacts and ageing reveal different problems. A helpdesk works best when it connects support with problem, change and asset processes rather than becoming a queue that merely counts tickets.
IT glossary -
Endpoint
An endpoint is a device or workload that communicates on a network as a source or destination, such as a laptop, desktop, phone, server, virtual machine or specialised appliance. Definitions vary between tools, so an inventory should state which types are included and who manages them. Endpoints process identities and data and can provide an entry path, but installing an EDR agent does not guarantee complete protection and may not be possible on every device. Management combines inventory, configuration, updates, encryption, privilege, protection, logging and response. Temporary, unsupported or agentless devices need explicit treatment. Coverage should be reconciled between sources: zero alerts on an endpoint that stopped reporting does not mean that it is healthy.
IT glossary -
Hyperconvergence (HCI)
Hyperconverged infrastructure (HCI) combines computing, software-defined storage and virtualisation in nodes managed as a system. It can simplify growth and operations through similar building blocks, but it does not remove network, licence, capacity or failure-domain dependencies. Adding a node increases resources according to product rules and may not fix the component that is actually constrained. Design should distinguish usable from raw capacity and consider replication, growth, maintenance, compatibility and failure behaviour. Central management eases change but also concentrates privilege. Backups, snapshots and internal redundancy have different purposes; data replicated within one cluster is not an independent recovery copy. Tests should measure representative workloads, rebuild, node loss, upgrades and restore. Commercial simplicity does not replace sizing or operating procedures.
IT glossary -
VoIP (Voice over IP)
VoIP (Voice over Internet Protocol) carries calls as data traffic over IP networks rather than a dedicated telephone circuit end to end. A solution may include endpoints, a PBX, SIP, codecs, provider, DNS, NAT, firewall and internet connectivity. Successful phone registration does not guarantee two-way audio or quality; latency, jitter, loss and prioritisation matter. Design should define numbering, concurrent calls, emergency calling where applicable, security, fraud controls, recording, power and failure routes. QoS can manage contention but cannot create bandwidth. Tests should cover inbound and outbound calls, transfer, caller identity, codecs and recovery after loss of connectivity or service. Cost and resilience depend on the specific contract, network and architecture.
IT glossary -
IaaS (Infrastructure as a Service)
IaaS (Infrastructure as a Service) provides virtual compute, storage and networking on demand while the cloud provider operates the physical facilities and hardware. The customer normally manages operating systems, identities, applications, data and much of the network configuration; the precise split depends on the service. IaaS removes hardware purchasing from the immediate workflow but does not remove architecture, patching, security, backup or cost governance. Before adoption, teams should evaluate regions, quotas, performance, egress, licensing, logging, recovery and exit procedures. Infrastructure as code, tagging, budgets and least privilege improve control. Availability features must be deliberately configured and tested because placing a virtual machine in a cloud region does not make the workload resilient. Total cost includes operations, data transfer, protection and retained capacity, not only runtime hours.
IT glossary -
PaaS (Platform as a Service)
PaaS (Platform as a Service) provides a managed environment for developing, deploying and running applications without directly operating all underlying infrastructure. It may include runtimes, databases, queues, identity, scaling and tools, depending on provider and plan. The provider manages part of the platform while the customer retains responsibility for code, data, access, configuration, dependencies and cost. PaaS can accelerate deployment but may introduce limits, proprietary services and regional or vendor dependency. Before adoption, teams should review portability, network, observability, backup, recovery, updates, quotas and exit. High availability should not be assumed because a service is cloud-based; architecture and configuration matter. Load, failure and restore tests validate the design better than a feature list.
IT glossary -
SaaS (Software as a Service)
SaaS (Software as a Service) is an application delivered over the internet and mainly operated by its provider, commonly by subscription. The customer avoids running application infrastructure but retains responsibilities for users, permissions, configuration, devices, data and compliance. Updates, availability, retention and backup depend on contract and design and should not be assumed. Before adoption, teams should review data location and export, authentication, integration, logging, recovery, limits, portability and exit. They should also know what happens when connectivity fails or the subscription ends. Total cost includes licences, implementation, integrations, training and governance, not only the advertised fee. Provider status does not prove that the configured tenant, customer data or business process is healthy.
IT glossary -
Hybrid cloud
Hybrid cloud is an operating model that connects privately controlled infrastructure with one or more public cloud services so applications, data or management span both environments. It does not necessarily mean workloads move freely between them; portability depends on architecture, platforms and data design. Organisations may use it for latency, regulation, existing investment, resilience or phased migration, but each additional boundary adds identity, networking, monitoring and support complexity. Design should define workload placement, connectivity, ownership, data flows, consistency, security controls, cost and failure behaviour. Common tooling can improve visibility but does not erase provider differences. A useful hybrid model has a stated reason for each workload and tested recovery paths, rather than maintaining two environments merely because both already exist.
IT glossary -
Microsoft Azure
Microsoft Azure is a cloud platform offering computing, storage, networking, databases, identity and many managed services across regions. Available features, resilience and pricing depend on the selected service, region, tier and configuration. Microsoft operates the underlying platform to an agreed boundary, while customers retain responsibilities for identities, data, access, workloads, configuration and cost control. Moving a server to Azure does not automatically make it scalable, secure or highly available. Architecture should define subscriptions, ownership, network boundaries, logging, backup, recovery, quotas and exit. Native integration with Microsoft products can help but also needs explicit permissions and lifecycle management. Validation should include deployment, failure, restore and billing scenarios. A green resource status does not prove that the business application or its dependencies are healthy.
IT glossary -
Cloud migration
Cloud migration moves or transforms applications, data and dependencies into cloud services. Strategies may include rehosting, refactoring, replacing or retiring, and one portfolio often combines them. Copying a virtual machine does not resolve architecture, identity, network, licences, performance, compliance or cost. Before moving, teams should inventory owners, flows, data, dependencies, baselines and acceptance criteria. The plan defines waves, backup, synchronisation, testing, cutover, rollback and later operations. Temporary coexistence can add complexity and spend. Each workload needs functional, security, performance, recovery and observability validation in the destination. Completing data transfer is not completing migration: reconciliation, safe source retirement, documentation, support and confirmation of the intended business outcome remain. Provider status alone does not prove that the migrated service works.
IT glossary -
PoE (Power over Ethernet)
PoE (Power over Ethernet) carries data and electrical power over the same Ethernet cable to compatible devices such as access points, phones, sensors or cameras. The equipment supplying power is the PSE and the receiver is the PD. IEEE standards define negotiation and power classes; matching connectors are not enough. Design should verify standard, device demand, total switch budget, distance and cable quality. An injector can add PoE but also needs compatibility. Loss and temperature reduce margin, and a system may fail when many devices draw maximum power together. Validation should measure link, consumption and behaviour during restart or peak load, not merely confirm that a device powers on. Redundant data paths also need suitable power resilience.
IT glossary -
Optical fibre
Optical fibre carries information as light through a glass or plastic core. Single-mode and multimode fibres use different optics, distances and installation constraints, while connectors, splices, cleanliness and bend radius affect the complete link. Fibre can provide high bandwidth and electrical isolation, but the word fibre alone does not guarantee speed, redundancy or a particular service level. Design should define route, strand count, connector type, optical budget, transceivers, growth, physical protection and ownership. Installation records and labels must match both ends. Validation includes inspection, loss measurement and, when required, trace testing against the chosen specification. A link light only confirms that some signal is received; it does not prove margin, correct polarity, expected capacity or resilience to a path failure.
IT glossary -
Structured cabling
Structured cabling is a standards-based system of cables, connectors, patch panels, racks and pathways that supports communications in a building or campus through a documented topology. It is organised into subsystems and performance categories; using a high-category component does not certify the complete link. Design should consider routes, electrical separation, bend radius, pathway capacity, grounding where applicable, PoE, growth and labelling. After installation, each link is tested against the relevant limit and its report is tied to a unique identifier. A tidy rack is not evidence of electrical performance. Drawings, port inventory and change control help locate faults and prevent later additions from degrading a valid installation. Application speed also depends on active equipment and endpoints, not cabling alone.
IT glossary -
Network switch
A network switch connects devices on a local network and forwards frames to the port associated with a destination. Managed models may support VLANs, spanning tree, aggregation, QoS, PoE, authentication and monitoring, but functions depend on model, licence and configuration. Advertised capacity does not guarantee performance in every workload; ports, uplinks, tables, buffers, power and traffic patterns matter. Design should consider loop-free redundancy, PoE budget, protected management, supported firmware and port documentation. A saved configuration does not prove that a recoverable copy or compatible replacement exists. Validation includes representative traffic, link and power failure and management access. Green lights show physical link, not the correct VLAN, route or application outcome.
IT glossary -
Bandwidth
Bandwidth is the maximum quantity of data a link can carry per unit of time, commonly expressed in Mbps or Gbps. It describes capacity rather than the speed perceived by an application. Actual throughput also depends on latency, packet loss, jitter, protocol overhead, congestion, Wi-Fi conditions, remote servers and sharing among users. Capacity may be asymmetric and vary across a path, so one speed test does not represent an entire working day. Network sizing should use representative measurements, peak and percentile demand, growth and degraded-operation needs. Quality of service can prioritise selected traffic but cannot create bandwidth. Any result should identify source, destination, time, method and whether the tested segment was wired, wireless or an internet service.
IT glossary -
QoS (Quality of Service)
QoS (Quality of Service) classifies and handles network traffic according to policy to protect applications sensitive to delay, loss or jitter, such as voice and video. It may mark, prioritise, rate-limit or queue traffic depending on equipment and path. QoS does not create bandwidth or permanently fix a saturated circuit; it decides which traffic is affected first during contention. Policy needs clear classes, trusted markings, sufficient capacity and consistent application across relevant points. Excess priority for one class can harm others. Teams should measure real patterns and establish a baseline before activation. Tests under load and per-class measures confirm whether latency, loss and queues improve without unintended effects. A configured rule does not prove end-to-end treatment if another device rewrites or ignores it.
IT glossary -
DNS (Domain Name System)
DNS (Domain Name System) translates names used by people and applications into records such as IP addresses and service locations. Resolution may involve local caches, recursive resolvers, authoritative servers and registrars, with separate owners and failure modes. DNS does more than map a website to one address, and cached answers can delay a change. Design should document zones, delegation, record ownership, time to live, access and recovery. Redundant servers must avoid a shared provider or configuration failure if genuine independence is required. DNSSEC can authenticate signed data but does not encrypt queries or correct a bad record. Tests should use external and internal paths, confirm intended answers and observe expiry. A server responding successfully does not prove that every resolver sees the same current configuration.
IT glossary -
Wi-Fi 6
Wi-Fi 6 is the commercial name associated with IEEE 802.11ax, a wireless generation designed to use spectrum more efficiently and serve dense device environments. It includes techniques such as OFDMA and MU-MIMO, but real improvement depends on compatible clients, channels, interference, power, cabling and access-point capacity. Replacing a router does not guarantee higher speed for every device or correct poor coverage. Design should start from requirements, floor plans, density, applications and radio measurements and also consider security and roaming. Excessively wide channels can increase interference. Validation is performed in real areas and devices, checking coverage, capacity, latency and stability under load rather than only measuring speed next to an access point.
IT glossary -
NAC (Network Access Control)
NAC (Network Access Control) applies policy when devices or users connect to wired or wireless networks. It may use identity, device posture, certificates, location or role to assign access, quarantine or remediation, depending on integrations. NAC does not automatically know that every device is trustworthy, and a failed dependency can block legitimate work or grant fallback access. Design should define authoritative identities, device ownership, unmanaged and guest paths, enforcement points, exceptions and behaviour when authentication services fail. Discovery mode helps reveal unknown equipment before blocking. Certificates and posture agents require lifecycle management. Tests should cover authorised, denied, expired, non-compliant and emergency cases on real ports and wireless networks. A successful connection does not prove least privilege if the assigned VLAN or policy allows excessive communication.
IT glossary -
IDS / IPS (Intrusion Detection/Prevention)
IDS and IPS inspect activity for signs of attacks or policy violations. An Intrusion Detection System observes traffic or host events and raises alerts; an Intrusion Prevention System sits in a position where it can also block, reset or otherwise interrupt matching activity. Detection may use signatures, protocol analysis, reputation, behaviour or anomaly models, each with limitations. An IPS can reduce exposure quickly, but an inaccurate rule may interrupt legitimate business traffic, so changes require tuning, monitoring and rollback. Placement and visibility matter: encrypted or bypassing traffic may not be inspected. Useful evaluation covers protected segments, update sources, false positives, response ownership, logging and failure mode. IDS/IPS complements patching, identity controls, endpoint protection and segmentation rather than replacing them.
IT glossary -
WAF (Web Application Firewall)
A WAF (Web Application Firewall) inspects HTTP and HTTPS traffic to enforce rules in front of a web application or API. It can block known attack patterns, rate-limit requests and add visibility, but it does not repair vulnerable code or understand every business workflow. Placement, TLS handling, origin access and trusted proxy headers determine what the WAF can see and protect. Generic managed rules need tuning because aggressive settings may reject legitimate users while permissive exceptions create gaps. APIs, uploads, authenticated areas and automated clients often require separate policies. Logs should reach the response process without retaining unnecessary sensitive data. Validation combines safe test cases, application monitoring and review of bypass paths. A clean WAF dashboard does not prove the application is secure or even that all production traffic passes through it.
IT glossary -
DDoS attack
A DDoS (Distributed Denial of Service) attack tries to exhaust network capacity, protocol resources or application functions with traffic from multiple sources. Not every attack produces enormous volume; some exploit expensive operations or limited state. A local firewall may saturate before filtering, so mitigation often requires coordination with a carrier, delivery network or specialist service. Preparation identifies critical services, dependencies, thresholds, contacts and escalation routes. Rate limiting, caching, distribution and filtering can reduce impact but must be tested without blocking legitimate users. Network, application and business measures help distinguish attack, failure and genuine demand. Restoring availability does not prove the cause has disappeared or that no parallel intrusion occurred, so investigation and monitoring should continue.
IT glossary -
Hosted PBX
A hosted PBX provides business telephony functions from infrastructure operated by a provider rather than a call-control appliance kept at the customer site. It may manage extensions, numbers, routing, voicemail, queues and applications, depending on the plan. Handsets, internet access, local network, emergency calling, number porting and integrations still create customer-side dependencies. Cloud hosting does not guarantee call quality or uninterrupted service; resilience depends on provider design, circuits, endpoints and failure routing. Before adoption, organisations should define ownership, support boundaries, concurrent-call capacity, recording, retention, security, exit and what happens during a site outage. Tests should cover inbound and outbound calls, transfers, caller identity, two-way audio and recovery. Subscription price alone is not the total operating or migration cost.
IT glossary -
SIP (Session Initiation Protocol)
SIP (Session Initiation Protocol) is a signalling protocol used to create, modify and end IP communication sessions such as voice or video calls. It negotiates participants and parameters, while media commonly travels through protocols such as RTP; successful signalling therefore does not guarantee audio quality. A deployment may involve endpoints, a PBX, carrier, NAT, DNS and security controls with separate responsibilities. Design should address authentication, compatible encryption, fraud, numbering, codecs, ports and failure behaviour. Session border controllers, firewalls and call policies can reduce exposure but require correct configuration. Testing should cover inbound and outbound calls, transfer, caller identity, two-way media, emergency calling where applicable and recovery after loss of connectivity or provider service.
IT glossary -
SIP trunk
A SIP trunk is an IP service that connects a business phone system to a telephony provider for inbound and outbound calls. SIP handles signalling, while voice media commonly uses RTP or a secured equivalent, so successful registration does not guarantee two-way audio or call quality. The service may depend on the PBX, session border controller, firewall, NAT, DNS, numbering and internet access, each with separate responsibilities. Capacity is usually described through concurrent calls rather than physical lines. Design should address authentication, compatible encryption, fraud controls, emergency calling where applicable, number presentation and failure routing. Testing should cover inbound and outbound calls, transfers, caller identity, codecs, media in both directions and recovery after losing a circuit or provider. Cost and resilience depend on the contracted service and architecture.
IT glossary -
IVR (Interactive Voice Response)
IVR (Interactive Voice Response) answers calls and guides callers through menus or speech recognition before routing them or completing a defined task. It can collect intent, authenticate within limits and provide routine information, but it should not create a dead end for cases it cannot understand. Design should use clear language, short choices, accessible timing, retry limits and an escape to appropriate human help. Caller identity cannot be assumed from the phone number alone. Integrations with CRM or payment systems require controlled data handling and failure behaviour. Tests cover accents, noise, invalid input, silence, after-hours routes, transfer context and system outages. Measures such as abandonment and repeated calls need interpretation by journey. Shorter handling time is not success if callers fail to resolve their need.
IT glossary -
CCTV (Closed-Circuit Television)
CCTV (Closed-Circuit Television) is a system of cameras, transmission, recording and viewing used to observe defined areas for a security or operational purpose. It may be analogue, IP or hybrid and can add analytics, but capability depends on cameras, recorder, licences and environment. More resolution does not automatically produce useful evidence: lens, distance, light, angle, compression and retention determine the result. Design should justify purpose, coverage, notices, access, retention and export for the applicable context, while protecting credentials and firmware. Tests should use real scenes by day and night and verify search, playback and component loss. Seeing live video does not prove recording or recoverability. Human procedures and response ownership are as important as camera placement.
IT glossary -
NVR (Network Video Recorder)
An NVR (Network Video Recorder) receives, records and manages video streams from IP cameras over a network. Depending on the design, it may provide live viewing, search, user permissions, retention controls, export and event integration. Recording duration is determined by camera count, resolution, frame rate, compression, storage capacity and retention policy; it is not fixed by the term NVR. The recorder and cameras also depend on network capacity, time synchronisation, power and secure credentials. Remote access is optional and should be configured with appropriate authentication and exposure controls. When selecting an NVR, organisations should review supported cameras, storage resilience, export format, audit logs, privacy requirements and recovery after hardware failure. Legal basis, signage and retention decisions remain organisational responsibilities.
IT glossary -
IP camera
An IP camera captures digital video and sends it over an Ethernet or wireless network to a recorder, service or authorised viewer. It may receive power through PoE and include audio, storage or analytics, but these features vary by model and licence. Image usefulness depends on lens, distance, angle, lighting, frame rate, compression and scene movement; headline resolution alone is insufficient. Design should define purpose, field of view, retention, access, bandwidth, time synchronisation and behaviour when network or recorder fails. Credentials, firmware and exposed services need protection. Tests should use representative day and night scenes and confirm recording, search and export, not only live view. Network access does not mean internet exposure is necessary, and a connected camera does not prove that footage is being retained.
IT glossary -
ONVIF
ONVIF defines standardised interfaces and profiles intended to improve interoperability between IP-based physical-security devices and clients. A product is not generically ONVIF compatible: conformance is tied to a claimed profile and specific firmware or software version listed in the official conformant-products database. Different profiles cover different feature sets, so two conformant products may still lack the same required function. Procurement should identify streams, events, analytics, access-control or configuration capabilities needed and verify both device and client declarations. Network, credentials, codecs and vendor implementation still affect integration. Testing should use the exact versions and required workflows, including discovery, live video, events, recording and failure recovery. A logo or successful connection alone is not evidence of complete interoperability.
IT glossary -
Video analytics
Video analytics uses software to interpret camera images or streams and flag defined events, objects or patterns. Typical functions include line crossing, occupancy, queue measurement or abandoned-object detection, but capability varies by camera, model, licence and scene. An alert is a probabilistic observation, not proof of intent or identity. Angle, lighting, weather, occlusion, resolution and changing layouts affect accuracy, so demonstrations in another environment are not sufficient. A deployment should define purpose, lawful handling, retention, human review, acceptable false positives and response procedures before choosing technology. Tests need representative day and night scenes and documented thresholds. Processing at the edge and centrally have different bandwidth and maintenance trade-offs. More alerts do not necessarily improve security or operations; usefulness depends on verified detection and a workable response.
IT glossary -
LPR (Licence Plate Recognition)
LPR (Licence Plate Recognition), also called ANPR in some markets, uses cameras and image processing to detect a vehicle registration plate and convert it into searchable text. It can support access decisions, parking workflows, investigations and entry records when integrated with the relevant system. Accuracy varies with angle, distance, speed, lighting, weather, plate condition and regional formats, so a laboratory percentage is not a site guarantee. Design should cover camera placement, allow-list logic, manual exceptions, retention, audit trails and what happens when recognition fails. Plate data may be personal data and requires an appropriate purpose, access controls and retention policy. Testing should use representative vehicles and conditions and measure both missed reads and incorrect matches before automated barriers or alerts are trusted.
IT glossary -
Access control
Physical access control manages who may enter a door, zone or site and under which conditions. A solution can combine credentials, readers, controllers, locks, sensors, software and procedures, with each component affecting the result. A valid credential does not prove the person’s identity unless the process provides additional verification, and an event log does not guarantee that a door closed correctly. Design should define zones, schedules, visitors, emergency egress, lost credentials, offline behaviour, retention and ownership of approvals. Biometrics or mobile credentials introduce different privacy and availability considerations. Testing should follow authorised and denied journeys, power and network loss, alarms and removal of access. Security also depends on physical installation and administration; adding a reader to an unsuitable door can create safety or bypass problems.
IT glossary -
Biometrics
Biometrics uses measured human characteristics, such as fingerprint, face, iris or voice, to support recognition or authentication. A system stores a template derived from a sample rather than needing the original image for every comparison, but implementations differ. Biometric matching is probabilistic: false accepts and false rejects depend on thresholds, sensors, environment and population. A biometric trait is not secret or easily replaced if compromised, so it should not automatically be treated as stronger than every card or PIN. Design should cover liveness detection, fallback, enrolment, accessibility, retention, lawful purpose and template protection. Evaluation requires representative users and conditions, documented thresholds and monitoring of exceptions, not only a vendor accuracy figure.
IT glossary -
RFID (Radio-Frequency Identification)
RFID (Radio-Frequency Identification) identifies tagged objects or credentials using radio waves. A solution combines tags, readers, antennas and software, and may operate at low, high or ultra-high frequency with different range, speed and material behaviour. Passive tags draw energy from the reader; active tags contain a power source and can support longer range. RFID can improve access, inventory and traceability, but a detected tag does not prove the identity or location of an item without suitable process controls. Metals, liquids, orientation and interference affect reads. Security also varies: identifiers may be copied or observed unless the selected technology supports appropriate authentication and encryption. A pilot should test representative tags, environments, collision rates, exceptions, integration and reconciliation with the system of record.
IT glossary -
Indoor air quality (IAQ)
Indoor air quality (IAQ) describes conditions inside a building that can affect comfort, health and work, including ventilation, carbon dioxide, particles, humidity, temperature and volatile compounds. A sensor reading is an indicator, not a diagnosis: placement, calibration, occupancy, outdoor air and the device’s measurement method affect results. Carbon dioxide can help assess ventilation in occupied spaces but does not represent every pollutant. An IAQ programme should define purpose, locations, sampling interval, thresholds from applicable guidance, maintenance and who responds to alerts. Trends and corroborating measurements are more useful than a single value. Any corrective action should consider the building and HVAC system, while suspected health or regulatory issues require competent professional assessment rather than an unverified dashboard conclusion.
IT glossary -
HVAC
HVAC means heating, ventilation and air conditioning: the systems that manage temperature, airflow, humidity and, in some designs, filtration within a building. Equipment may include air handling units, chillers, heat pumps, ducts, controls and sensors with separate maintenance needs. A thermostat reading does not represent every occupied zone, and comfort does not by itself prove adequate air quality. Design and operation should consider occupancy, loads, outside conditions, zoning, maintenance, alarms and safe access. Building-management integration can improve visibility but also introduces network and control dependencies. Set-points must reflect applicable requirements and the real use of the space. Validation uses calibrated measurements across relevant locations and operating modes. Energy efficiency, comfort, preservation of equipment and ventilation can involve trade-offs that require monitored adjustment.
IT glossary -
CO₂ sensor
A CO₂ sensor measures carbon-dioxide concentration in air and can help indicate ventilation conditions in occupied spaces. The value is a partial indicator, not a complete indoor-air-quality measure or direct proof of infection risk. Accuracy depends on sensing technology, calibration, placement, height, airflow, occupancy and maintenance. Positioning beside a person, window or supply vent can distort readings. A deployment should define purpose, interval, recording, alerts, owner and intended response using criteria applicable to the building and activity. Comparing devices without checking calibration can drive poor decisions. Validation includes a reference, response to occupancy changes and communication failures. A green dashboard does not prove that the sensor is correctly placed or measuring accurately.
IT glossary -
Generative AI
Generative AI describes models that produce text, images, code or other content from instructions and context. Output is probabilistic and can be plausible but wrong, incomplete or derived from unsuitable data. A model does not automatically know internal policy or verify facts. Before business use, organisations should define purpose, permitted data, human review, rights, retention, security, suppliers and response to errors. Sensitive information should not be submitted without an appropriate basis and controls. Connecting a model to tools can amplify impact because an answer may trigger actions. Validation uses representative cases, measures quality, risk and cost and retains proportionate traceability. Automating generation does not transfer accountability; significant decisions need supervision, criteria and a fallback when the service or output is unreliable.
IT glossary -
LLM (Large Language Model)
A Large Language Model (LLM) is trained to predict and generate language sequences from large datasets. It can summarise, classify, extract or create text and code, but output is probabilistic and may contain fabricated facts, bias or unsafe instructions. The model does not automatically consult a current source or understand business accountability. Appropriate use defines permitted data, context, human review, evaluation, retention, suppliers and action limits. Adding retrieval or tools may improve usefulness and also increase impact. Tests should use representative cases and measure error, safety, latency and cost. Fluency is not evidence of truth; important output needs verifiable support and a fallback when the model fails. Connecting an LLM to actions requires stronger approval and monitoring than using it for drafts.
IT glossary -
RPA (Robotic Process Automation)
RPA (Robotic Process Automation) uses software bots to perform repeatable, rule-based actions across user interfaces or APIs, such as moving data, checking fields or generating routine outputs. It suits stable, high-volume processes with explicit decisions; it is less suitable when inputs are ambiguous or applications change frequently. A bot can reproduce errors faster, so the process should be simplified and controlled before automation. Production design needs credential management, least privilege, logging, exception queues, monitoring, versioning and an accountable process owner. Interface-based automation can be fragile compared with a supported API, although it may bridge legacy systems. Benefits should be measured against maintenance and failed cases, and a manual recovery path should remain available when the bot or a dependent system stops.
IT glossary -
Machine learning
Machine learning uses statistical models that learn patterns from data to make predictions, classifications or recommendations without encoding every rule explicitly. Performance depends on the data, target, context and measure chosen; a high test score does not guarantee useful behaviour in production. Historical data can preserve bias, leakage or outdated relationships. A project should define the decision, owner, acceptable errors, baseline, data provenance, privacy, review and fallback before selecting a model. Training, validation and final evaluation need separation, and deployed input or outcomes should be monitored for drift. More complex models are not always better if they reduce explainability or maintainability. Automation does not remove accountability: significant decisions require proportionate human oversight, appeal paths and evidence that the model remains fit for its actual population.
IT glossary -
RMM (Remote Monitoring and Management)
RMM (Remote Monitoring and Management) is a platform used by IT teams or managed service providers to observe and administer endpoints, servers and sometimes network devices from a central console. An installed agent or another management channel can collect health data, generate alerts, deploy scripts or patches and support remote troubleshooting. RMM does not make every action safe or proactive by default. Its value depends on inventory coverage, alert ownership, maintenance policies, access controls, audit logs and testing. Because the platform can execute privileged actions across many devices, it is itself a high-value security target and should use strong authentication, restricted roles and controlled automation. Organisations should also define what happens when an agent is offline, a script fails or the provider relationship ends.
IT glossary -
Active Directory
Active Directory Domain Services is Microsoft’s directory technology for organising users, computers, groups and resources in a Windows domain and applying authentication and policy. Domain controllers store and replicate directory data, while DNS, time, sites and trusts support correct operation. Active Directory is not the same as Microsoft Entra ID, although environments can integrate them. Its central role makes privileged accounts, service accounts, backups, patching and replication important security and continuity concerns. Good administration uses least privilege, separate administrative identities, controlled group changes and monitored authentication. Recovery planning must include tested system-state or forest procedures rather than ordinary file copies alone. Health checks should examine replication, DNS, time and dependencies, not merely whether users can sign in.
IT glossary -
ITIL
ITIL is a body of guidance for managing digital products and IT services through principles, practices and continual improvement. It covers areas such as incidents, service requests, changes, problems, service levels and configuration, but it is not a prescriptive process map or a software product. Organisations select and adapt relevant practices to their context instead of implementing every term mechanically. Effective adoption starts with outcomes, roles, value streams and evidence of where work waits or fails. Metrics should reflect user and business results as well as ticket speed. A tool labelled “ITIL compliant” does not prove that responsibilities or decisions are effective. Improvement requires feedback, review and proportionate controls; excessive approval steps can reduce value just as much as missing governance.
IT glossary -
Patch management
Patch management identifies, evaluates, tests, deploys and verifies updates for operating systems, applications, firmware and devices. Installing everything immediately is not always safe, but indefinite delay preserves exposure; priority should consider severity, exploitation, asset importance, dependencies and compensating controls. Inventory and support status are prerequisites because a console only reports devices it knows and can reach. The process defines owners, windows, backups, pilots, exceptions, rollback and handling of failures. Some changes require restart or prerequisites and may affect compatibility. Validation confirms the installed version and service operation, not merely job completion. Measures should separate pending, excluded, failed and unseen assets. A device absent from the report is not evidence of a patched device, so coverage must be reconciled with authoritative inventory.
IT glossary -
ISO 27001
ISO/IEC 27001 is an international standard that specifies requirements for establishing, operating and improving an information security management system (ISMS). It asks an organisation to understand its context, assess risks, select and justify controls, assign responsibilities, measure performance and correct nonconformities. Certification is performed against a stated scope by an accredited certification body; it does not automatically cover every office, supplier, product or service. The standard does not prescribe one technology and certification does not prove that incidents cannot occur. When evaluating a certificate, check the legal entity, scope, sites, issue and expiry dates and certification body. More useful evidence also includes the statement of applicability, audit findings where shareable, risk treatment and proof that the management cycle operates between external audits.
IT glossary -
PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) defines technical and operational requirements for protecting payment-account data in environments that store, process or transmit it and may also cover service providers able to affect its security. Scope starts with data flows and connected systems, not a generic server list. Requirements address networks, configuration, access, vulnerabilities, logs, testing and policy. Compliance does not eliminate risk or replace other obligations. Validation depends on the entity’s role and payment-brand or acquirer requirements. Reducing stored data, segmenting correctly and retaining evidence can simplify assessment, but every exclusion needs justification and periodic verification. Applicability should be confirmed with current PCI SSC material and relevant parties rather than inferred from a product or marketing claim.
IT glossary
Need help with any of these?
30 minutes with a senior consultant. No commitment, no sales pitch. An honest conversation about what you need and what we can do together.