Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Glossary

The sector's technical and regulatory terms, each defined in one sentence.

SOC (Security Operations Center)

A team and toolset dedicated to the continuous detection and qualification of security incidents.

MDR (Managed Detection & Response)

A managed service combining detection, investigation, and incident response, operated by an external provider.

SIEM (Security Information and Event Management)

A platform that collects and correlates technical logs to detect abnormal behavior.

CISO

The executive responsible for an organization's information security strategy and governance.

ISO/IEC 27001

The international reference standard for an information security management system.

GDPR

The European regulation governing the collection and processing of personal data.

PASSI

The qualification delivered by DGSSI to information systems security audit providers in Morocco.

MITRE ATT&CK

A public knowledge base of attacker tactics and techniques, organized as a matrix.

Penetration test (pentest)

A controlled attack simulation aimed at identifying exploitable vulnerabilities within a defined scope.

Ransomware

Malicious software that encrypts an organization's data and demands a ransom for its release.

Phishing

A social engineering technique aimed at obtaining sensitive information by impersonating a trusted identity.

Zero-day

A vulnerability exploited before a fix is available from the responsible vendor.

EDR (Endpoint Detection & Response)

An agent installed on endpoints and servers to detect and respond to malicious behavior locally.

IAM (Identity & Access Management)

The practices and tools managing digital identities and their access rights to systems.

CVSS (Common Vulnerability Scoring System)

A standardized scoring system for vulnerability severity, from 0 to 10.

GRC (Governance, Risk, Compliance)

The discipline aligning an organization's security strategy with its regulatory obligations and risk management.

vCISO

Executive-level security leadership delivered as a service, without a full-time hire.

OT / ICS

Operational technology and industrial control systems, distinct from conventional business IT.

Threat Intelligence

The collection and analysis of threat information to anticipate and detect attacks targeting an organization.

DNSSEC

A DNS protocol extension that guarantees the authenticity of domain name resolution responses.