Search

Find the concept or answer.

The research works simultaneously on terms, definitions, questions and answers.

35 results available.

Glossary

Definitions with source and context.

Legal definition#

Active

Information and communication system, equipment or other physical or logical resource managed or held by the entity supporting, directly or indirectly, one or more services.

RJCS, Article 2(a) ↗
Legal definition#

Competent cybersecurity authority

The CNCS or, where applicable, the relevant national cybersecurity sector authority, without prejudice to the powers reserved to other public entities.

RJCS, Article 2(b) ↗
Structural explanation#

Essential entity

Qualified entity as essential in accordance with the RJCS. The classification does not result from the choice of the organization itself.

RJCS, Articles 3, 6 and 8 ↗
Structural explanation#

Important entity

Entity concerned and qualified as important according to the criteria of RJCS, subject to the supervisory model and the measures applicable to its qualification.

RJCS, Articles 3, 7 and 8 ↗
Operational explanation#

Evidence

A factual, documentary or technical element that allows verifying the application and, where relevant, the effectiveness of a cybersecurity measure.

Regulation No. 756/2026Annexes III and IV ↗
Legal definition#

Incident

an event that calls into question the availability, authenticity, integrity or confidentiality of data or services offered by information networks and systems.

RJCS, Article 2(j) ↗
Summary legal definition#

Significant incidence

Incident that causes or may cause serious operational disturbances or financial losses, or affects or may affect third parties causing considerable material or immaterial damage.

RJCS, Article 2(l) ↗
Legal definition#

Risk matrix

Reference framework establishing risk values for scenarios that fall on a sector and subsector, considering common assets, threats and vulnerabilities.

RJCS, Article 2(m); Regulation, Annex II ↗
Summary legal definition#

Cybersecurity measures

technical, operational and organizational measures to manage risks and to prevent or minimise the impact of incidents on the services and their recipients.

RJCS, Article 2(n) ↗
Operational explanation#

MyCiber

Electronic platform managed by CNCS for identification, qualification, registration, communications, documents, notifications and other acts provided for in RJCS and the Regulation.

RJCS, Article 8 Regulation, Articles 4 to 22 ↗
Legal explanation#

Permanent contact point (PCP)

Person or team, internal or ensured by a third party, communicated to ensure permanent contact under the terms of the RJCS. In this context, PCP does not mean continuity plan.

RJCS, Article 32; Regulation, Article 15 ↗
Regulatory explanation#

QNRCS

National Cybersecurity Reference Framework, a national instrument that organizes objectives, categories and controls according to the cybersecurity management cycle.

Regulation, Articles 23 to 26 and Annex I ↗
Legal explanation#

Cybersecurity Officer (RCS)

Person designated by the entity to carry out the tasks provided for in Article 31 of the RJCS, whose identification is communicated through the platform MyCiber where applicable. RCS is the documental convention adopted by Cyberprotech; the legislation identifies the function in full and does not define this acronym.

RJCS, Article 31; Regulation, Article 14 ↗
Legal definition#

Incident handling

Actions and procedures for the prevention, detection, analysis, containment, response and recovery of an incident.

RJCS, Article 2(tt) ↗
Legal definition#

Vulnerability

Weakness, susceptibility or failure that affects ICT networks, systems, products or services and that can be exploited by a cyberthreat.

RJCS, Article 2(u) ↗

Frequently Asked Questions

Direct responses, with the way to deepen.

Are the RJCS and the NIS2 Directive the same thing?

No. NIS2 is Directive (EU) 2022/2555. Decree-Law No. 125/2025 transposes that Directive and establishes the Portuguese Cybersecurity Legal Framework.

Understanding the framework →
Does Regulation No. 756/2026 replace the RJCS?

No. The Regulation implements matters laid down in RJCS, including the platform, risk matrix, minimum measures and verification criteria. The two acts must be read together.

Consult Regulation →
How do I know my organization is covered?

It is necessary to analyze type of entity, sector or subsector, size, establishment and any special rules. The simulator supports the analysis but is not an administrative decision.

Analyze the scope →
Does the entity choose whether it is Essential or Important?

No. The qualification shall be decided by the competent cybersecurity authority after the self-identification and hearing of those concerned.

See the qualification path →
There is an account MyCiber per sector?

No. The platform provides for an account and a provisional registration per entity, regardless of the number of sectors or subsectors of activity.

Prepare MyCiber →
The result of the simulator MyCiber Is it binding?

No. The automated solution is informative, does not bind the Administration and does not dispense with self-identification when mandatory.

Understand the difference →
PCP Does that mean continuity plan?

Not in this framework. PCP means permanent contact point. It is the person, team or third party notified to ensure availability of contact.

Distinguishing roles →
Can I choose the Basic, Substantial or High Level?

No. The level results from the applicable risk matrix. The entities at the Substantial and High levels also apply the measures of the lower levels.

View levels →
Does having an approved policy prove that the measure is implemented?

Not always. Policy demonstrates decision and guidance, but execution may require factual and technical evidence, such as records, configurations, tests and samples.

Types of evidence →
What features should have good evidence?

It shall be relevant to the current measure, attributable, intact and sufficient to support the conclusion that the measure has been applied.

Organize implementation →
Do all entities apply the same measures?

No. The measures shall depend on the relevant qualification, level or group, residual risk and any additional sectoral rules.

Explore domains →
Can I rely on automatic alerts to meet incident deadlines?

No. The platform may issue alerts, but the absence or impossibility of issuing does not waive timely compliance with obligations.

Consult critical rules →
A voluntary notification requires registration in MyCiber?

No. The Regulation provides that the voluntary notification of relevant information does not require authentication or registration of the natural or legal person.

Consult articles →
Does the process end after qualification?

No. The entity shall keep the information up to date and use the platform for communications, documents, notifications, incidents and other relevant acts.

View continuous operation →
CyberComply is part of MyCiber?

No. MyCiber is the official platform managed by CNCS. CyberComply is an external product that can support compliance management, documentation and evidence.

Visit CyberComply ↗

Acronies

Acronyms to understand the context.

Editorial selection of acronyms relevant to cybersecurity, governance, continuity, cloud, data protection and technical implementation. The same acronym may have different meanings depending on the context.

137 acronyms available.

Regulation, standards and governance18 entries
NIS2

Network and Information Systems Direction 2

Directive (EU) 2022/2555 on measures to ensure a high common level of cybersecurity in the Union.

DORA

Digital Operational Resilience Act

European Regulation on digital operational resilience of the financial sector.

CRA

Cyber Resilience Act

European Regulation on horizontal cybersecurity requirements for digital products.

EAA

European Accessibility Act

European Accessibility Act, transposed to establish accessibility requirements for certain products and services.

RGPD

General Data Protection Regulation

Regulation (EU) 2016/679 on the protection of personal data and free movement of such data.

RGPDI

General Scheme for the Protection of Infringement Reporters

Portuguese regime for the protection of whistleblowers, approved by Law 93/2021.

DSA / RSD

Digital Services Act / Digital Services Regulation

European Regulation applicable to intermediate services and digital platforms.

RJCS

Cybersecurity Legal Scheme

Portuguese scheme approved by Decree-Law No. 125/2025, transposing the Directive NIS2.

QNRCS

National Cybersecurity Reference Framework

National reference that organizes cybersecurity objectives, categories and controls.

ENSC

National Cyberspace Security Strategy

National strategic instrument defining priorities and objectives for cyberspace security.

NCSS

National Cybersecurity Strategy

General international designation for a national cybersecurity strategy.

BCMS

Business Continuity Management System

Business continuity management system; in Portuguese, continuity management system.

ECSF

European Cybersecurity Skills Framework

TESTS European reference for professional cybersecurity profiles, skills, knowledge and tasks.

C5

Cloud Computing Compliance Criteria Catalog

BSI catalog with criteria to assess information security in cloud services.

SoA

Statement of Application

Declaration of applicability identifying selected controls, exclusions and their justification in an information security management system.

TPRM

Third-Party Risk Management

Risk management associated with suppliers, providers and other third parties.

ESG

Environmental, Social and Governance

Environmental, social and governance dimensions used in evaluation and organizational management.

RGPC

General Corruption Prevention Scheme

Portuguese corruption prevention scheme applicable to the entities concerned.

Functions and service models9 entries
CISO

Chief Information Security Officer

Leadership function responsible for information security strategy and governance.

vCISO

Virtual Chief Information Security Officer

External professional ensuring leadership of information security with defined mandate and scope.

CISOaa

CYMBER the Service

Continued leadership and cybersecurity governance service, which can integrate vCISO, team, method, delivery and continuity.

RCS

Cybersecurity Officer

Documentary convention used by Cyberprotech for the person designated pursuant to Article 31 of the RJCS; the legislation does not define this acronym.

PCP

Permanent Accountct Point

Person or team notified to ensure permanent contact under the RJCS; in this context does not mean continuity plan.

PCPaaS

Accountct Point Permanent Service

Service model to operationalise reception, sorting, registration, activation and scaling of cybersecurity communications.

DPO/DPO

Data Protection Officer / Data Protection Officer

Function provided for in RGPD to advise, monitor compliance and cooperate with the supervisory authority.

QSP

Qualified Service Provider

Qualified provider; the range depends on the regime or program in which the designation is used.

QTSP

Qualified Trust Service Provider

Qualified provider of trust services under the applicable European framework.

Operations and incident response18 entries
SOC

Security Operations Center

Security operations center dedicated to operational monitoring, detection, analysis and coordination.

CSOC

Cybersecurity Operations Center

Variant designation SOC which explains the focus on cybersecurity operations.

CSIRT

Computer Security Incident Response Team

Team responsible for receiving, analysing, coordinating and responding to computer security incidents.

CERT

Computer Emergency Response Team

Name used by incident response teams; use of the name may depend on specific authorization or affiliation.

PSIRT

Product Security Incident Response Team

Team dedicated to product related vulnerabilities and safety incidents.

IR

Incident Response

Incident response, including preparation, analysis, containment, eradication, recovery and learning.

CIPR

Cyber Incident Planning and Response

Planning and responding to cybersecurity incidents.

SIEM

Security Information and Event Management

Technology for gathering, correlation, research and analysis of events and security information.

MDR

Managed Detection and Response

managed detection, investigation and threat response service.

MTH

Managed Threat Hunting

Managed service of proactive search for threats that have not yet been detected by automatic mechanisms, supported by hypotheses, telemetry and specialized analysis.

EDR

Endpoint Detection and Response

Ability to detect, investigate and respond in endpoints.

XDR

Extended Detection and Response

Detection and response correlation between multiple technological layers.

CTI

Cyber Threat Intelligence

Knowledge analyzed about threats, agents, capabilities, intentions and relevant indicators.

TTP

Tactics, Techniques and Procedures

Behavior patterns used to describe the form of action of threat agents.

BEC

Business Email Compromise

Fraud or commitment that exploits e-mail and organizational trust.

KEV

Known Exploited Vulnerabilities

Known vulnerabilities with confirmed exploitation, often prioritized in the management of corrections.

VAPT

Vulnerability Assessment and Penetration Testing

Evaluation of vulnerabilities and intrusion tests, with different objectives and depths.

NOC

Network Operations Center

Operations center focused on availability, performance and network and infrastructure management.

Vulnerability and coordinated dissemination8 entries
CVE

Common Vulnerabilities and Exposures

Public and standardized identification system of known vulnerabilities.

CNA

CVE Numbering Authority

Organization authorized to assign identifiers CVE within its scope.

CVD

Coordinated Vulnerability Disclosure

Coordinated process of communication, analysis, correction and dissemination of vulnerabilities.

VDP

Vulnerability Disclosure Program

Program establishing channels, rules and expectations for responsible reporting of vulnerabilities.

CSAF

Common Security Advisory Framework

Structured format for publication and exchange of machine-readable safety warnings.

EUVD

European Vulnerability Database

European Vulnerability Database maintained by TESTS.

CVS

Common Vulnerability Scoring System

Technical scoring system of severity of vulnerabilities; it does not replace contextual risk analysis.

SBOM

Bill of Materials Software

Structured inventory of components that integrate a product or software application.

Risk, projects and methodologies6 entries
BIA

Business Impact Analysis

Business impact analysis used to identify critical activities, impacts and recovery needs.

APR

Preliminary Risk Analysis

Initial analysis to identify hazards, scenarios, consequences and preventive measures.

RCA

Root Cause Analysis

Root cause analysis to identify underlying factors and avoid recurrence.

ERM

Enterprise Risk Management

Integrated risk management relevant to the objectives of the organization.

SOW

Scope of Work / Statement of Work

Document delimiting scope, activities, deliverables, responsibilities and conditions of execution.

SDLC

Development Life Cycle Software

Lifecycle of software development, from design to maintenance and withdrawal.

Cloud and technological services14 entries
CNAPP

Cloud-Native Application Protection Platform

Platform that brings together security capabilities for cloud-native applications and loads throughout its life cycle.

CASB

Cloud Access Security Broker

Control and visibility layer between users, organizations and cloud services.

CMP

Cloud Management Platform

Cloud resource management, governance and operation platform.

CWPP

Cloud Workload Protection Platform

Workload protection platform in cloud and hybrid environments.

CSP

Cloud Service Provider

Cloud service provider. The acronym CSP can also mean Content Security Policy in web security.

BYOL

Bring Your Own License

Model for using existing licenses in a compatible service or environment.

BMR

Bare Metal Restore

Full recovery of a system for hardware or environment without equivalent prior installation.

BaaS

Backup the Service

Managed service of copying, retention and recovery of data.

DRaaS

Disaster Recovery as a Service

Technical recovery service after disaster or serious unavailability.

STaaS

Storage as a Service

Storage capacity available as a service.

FWaaS

Firewall as a Service

Firewall functions provided as a service, often through cloud architecture.

SASE

Secure Access Service Edge

Architecture that combines connectivity and security controls delivered as service.

SSE

Security Service Edge

A cloud set of access security capabilities, usually integrated into a SASE architecture.

SSPM

SaaS Security Posture Management

Continuous configuration management and security posture of SaaS applications.

Continuity, backup and recovery8 entries
BC

Business Continuity

Continuity of business or activity to disturbance.

DR

Disaster Recovery

Recovery of technological systems and services after disaster or serious failure.

RTO

Recovery Time Objective

Target time to restore an activity, system or service after interruption.

RPO

Recovery Point Objective

Maximum permissible data loss point, expressed in time.

MTPD

Maximum Tolerable Period of Disruption

Maximum tolerable period during which an activity may remain interrupted.

MBCO

Minimum Business Continuity Objective

Minimum acceptable level of products or services during a disturbance.

GFS

Grandfather-Father-Son

Copy rotation scheme with daily, weekly and monthly or equivalent retention cycles.

WORM

Write Once, Read Many

Storage model that prevents or limits data change after recorded.

Data, identity and access control19 entries
DLP

Date Loss Prevention

Controls to prevent exposure, transfer or improper loss of data.

MSM

Hardware Security Module

Device dedicated to the generation, protection and safe use of cryptographic keys.

ECC

Elliptic Curve Cryptography

Elliptical curve encryption used in public key mechanisms.

FQC

Post-Quantum Cryptography

Encryption designed to withstand attacks from sufficiently capable quantum computers.

QKD

Quantum Key Distribution

Distribution of cryptographic keys using quantum communication properties.

WFP

Privileged Access Management

Management and control of privileged accesses.

IAM

Identity and Access Management

Identity management, authentication, authorizations and life cycle of accesses.

RBAC

Roll-Based Access Control

Access control based on functions assigned to users.

ABAC

Attribute-Based Access Control

Access control based on subject attributes, resource, action or context.

DACL

Discretionary Access Control List

Discretionary list defining access permissions to an object.

NAC

Network Access Control

Network access control based on identity, device, posture and policy.

IDS

Intrusion Detection System

System for detecting suspicious activities or intrusions.

IPS

Intrusion Prevention System

System that detects and can block suspicious activities or intrusions.

LPE

Local Privilege Escalation

Local scale of privileges in a compromised or accessed system.

WDAC

Windows Defend Application Control

Microsoft application control technology and code authorized to execute.

MFA

Multi-Factor Authentication

Authentication that requires factors of different categories.

SSO

Single Sign-On

Mechanism allowing access to multiple services via centralized authentication.

PKI

Public Key Infrastructure

Trust infrastructure for digital certificates, public keys and their life cycle.

CSP

Content Security Policy

Web security policy sent by the server to restrict executable or downloadable origins and types of content.

Internet, DNS and networks12 entries
DoH

DNS over HTTPS

DNS resolution carried over HTTPS.

DoT

DNS over TLS

DNS resolution transported directly on TLS.

STUN

Session Traversal Utilities for NAT

Protocol that helps applications identify addresses and cross certain NAT scenarios.

SDN

Software-Defined Networking

Software-defined networks with logical separation between control and forwarding.

ASN

Autonomous System Number

Number identifying an autonomous system when routing between Internet networks.

RIR

Regional Internet Registry

Regional register responsible for managing and allocating numerical resources from the Internet.

NIR

National Internet Registry

National register managing Internet numerical resources under an RIR.

PMF

Protected Management Frames

Encryption protection of certain management frameworks on Wi-Fi networks.

NGFW

Next-Generation firewall

Firewall with additional inspection, enforcement and threat prevention capabilities.

VPN

Virtual Private Network

Secured logical connection over an unreliable or shared network.

TLS

Transport Layer Security

Cryptographic protocol to protect communications in transit.

DNS

Domain Name System

Distributed system linking domain names to technical information, including network addresses.

Artificial intelligence and automation5 entries
AI-SPM

Artificial Intelligence Security Posture Management

Management of safety posture of systems, models, data and artificial intelligence services.

RPA

Robotic Process Automation

Repetitive task automation through configured software to run defined streams.

RAG

Retrieval-Augmented Generation

Technique that combines information recovery with generation of responses by a model.

MCP

Model Context Protocol

Protocol to integrate artificial intelligence applications with tools and context sources. The acronym may have other meanings in other domains.

GEO

Generating Engine Optimization

Optimization of content to improve its understanding and use by generative mechanisms without ensuring citation or recommendation.

Management, Business and Training14 entries
ITSM

IT Service Management

Structured management of information technology services.

TCO

Total Cost of Ownership

Total cost of acquisition, operation, maintenance and withdrawal of a solution throughout your life cycle.

OEM

Original Equipment Manufacturer

Original manufacturer of equipment or components supplied to other brands or integrators.

B2B

Business-to-business

commercial or service relations between organizations.

B2G

Business-to-government

Relationship between companies and public entities, including hiring and providing services.

DPI

Public-Priva Partnership

The contractual model of cooperation between public and private entities subject to the applicable framework.

SMEs / EMS

Small and Medium Enterprise / Small and Medium-sized Enterprise

Business classification determined by criteria such as actuals, turnover and balance sheet.

EPE

Corporate Public Entity

Public collective person of a corporate nature integrated into the public business sector.

MOOC

Massive Open Online Course

Open online course designed for large-scale participation.

OER

Open Educational Resources

Open educational resources, provided with conditions that allow use and adaptation.

CPE

Continuing Professional Education

Continuing vocational education to maintain or develop skills.

STEM

Science, Technology, Engineering and Mathematics

Areas of science, technology, engineering and mathematics.

EdTech

Educational Technology

Technology applied to education teaching, learning and management.

RHAQ

Highly Qualified Human Resources

Name used in specialized qualification and employment programs and policies.

Systems and architecture6 entries
MVC

Model-View-Controller

Architecture pattern that separates data, presentation and interaction logic.

OPA

Open Policy Agent

Open source policy engine for rules-based authorization and compliance decisions.

UC&C

Unified Communications and Collaboration

Integration of communications, presence, meetings and collaboration into a common architecture.

SSCS

Software Supply Chain Security

Software supply chain security, including code, dependencies, tools and delivery processes.

EMM

Enterprise Mobility Management

Integrated management of enterprise mobile devices, applications, content and identities.

MDM

Mobile Device Management

Centralised management of the configuration, posture and life cycle of mobile devices.

This index explains the meaning normally used by Cyberprotech. It does not replace the constant definition of applicable legislation, standard, contract, manufacturer or benchmark.

Informational content published on . Content and references checked on .