Glossary and FAQ
Clear concepts. Verifiable answers.
Search for concepts, acronyms and questions about the Cybersecurity Legal Regime, MyCiber, operations and practical implementation.
Search
Find the concept or answer.
The research works simultaneously on terms, definitions, questions and answers.
35 results available.
Glossary
Definitions with source and context.
Active
Information and communication system, equipment or other physical or logical resource managed or held by the entity supporting, directly or indirectly, one or more services.
RJCS, Article 2(a) ↗Competent cybersecurity authority
The CNCS or, where applicable, the relevant national cybersecurity sector authority, without prejudice to the powers reserved to other public entities.
RJCS, Article 2(b) ↗Cyber threat
Circumstance, event or potential action likely to damage, disrupt or adversely affect information networks and systems, users or other persons.
RJCS, Article 2(c) by reference to Regulation (EU) 2019/881 ↗Cybersecurity
A set of activities necessary to protect networks and information systems, their users and other people affected by cyber-threats.
RJCS, Article 2(e) by reference to Regulation (EU) 2019/881 ↗Essential entity
Qualified entity as essential in accordance with the RJCS. The classification does not result from the choice of the organization itself.
RJCS, Articles 3, 6 and 8 ↗Important entity
Entity concerned and qualified as important according to the criteria of RJCS, subject to the supervisory model and the measures applicable to its qualification.
RJCS, Articles 3, 7 and 8 ↗Relevant public entity
Public entity covered by the RJCS and subject to measures corresponding to the group determined under the scheme and Annex IV to the Regulation.
RJCS, Articles 3, 8 and 33; Regulation, Annex IV ↗Evidence
A factual, documentary or technical element that allows verifying the application and, where relevant, the effectiveness of a cybersecurity measure.
Regulation No. 756/2026Annexes III and IV ↗Incident
an event that calls into question the availability, authenticity, integrity or confidentiality of data or services offered by information networks and systems.
RJCS, Article 2(j) ↗Significant incidence
Incident that causes or may cause serious operational disturbances or financial losses, or affects or may affect third parties causing considerable material or immaterial damage.
RJCS, Article 2(l) ↗Risk matrix
Reference framework establishing risk values for scenarios that fall on a sector and subsector, considering common assets, threats and vulnerabilities.
RJCS, Article 2(m); Regulation, Annex II ↗Cybersecurity measures
technical, operational and organizational measures to manage risks and to prevent or minimise the impact of incidents on the services and their recipients.
RJCS, Article 2(n) ↗MyCiber
Electronic platform managed by CNCS for identification, qualification, registration, communications, documents, notifications and other acts provided for in RJCS and the Regulation.
RJCS, Article 8 Regulation, Articles 4 to 22 ↗Conformity level
Result applicable to essential and important entities according to the risk matrix: Basic, Substantial or High. The level determines minimum measures and is not freely chosen.
Regulation, Articles 28 and 30 and Annexes II and III ↗Permanent contact point (PCP)
Person or team, internal or ensured by a third party, communicated to ensure permanent contact under the terms of the RJCS. In this context, PCP does not mean continuity plan.
RJCS, Article 32; Regulation, Article 15 ↗QNRCS
National Cybersecurity Reference Framework, a national instrument that organizes objectives, categories and controls according to the cybersecurity management cycle.
Regulation, Articles 23 to 26 and Annex I ↗Cybersecurity Officer (RCS)
Person designated by the entity to carry out the tasks provided for in Article 31 of the RJCS, whose identification is communicated through the platform MyCiber where applicable. RCS is the documental convention adopted by Cyberprotech; the legislation identifies the function in full and does not define this acronym.
RJCS, Article 31; Regulation, Article 14 ↗Residual risk
Risk that remains after cybersecurity measures have been applied and should be analyzed, treated and monitored.
RJCS, Article s 27 to 29; Regulation, Article 31 ↗Incident handling
Actions and procedures for the prevention, detection, analysis, containment, response and recovery of an incident.
RJCS, Article 2(tt) ↗Vulnerability
Weakness, susceptibility or failure that affects ICT networks, systems, products or services and that can be exploited by a cyberthreat.
RJCS, Article 2(u) ↗Frequently Asked Questions
Direct responses, with the way to deepen.
Are the RJCS and the NIS2 Directive the same thing?
No. NIS2 is Directive (EU) 2022/2555. Decree-Law No. 125/2025 transposes that Directive and establishes the Portuguese Cybersecurity Legal Framework.
Understanding the framework →Does Regulation No. 756/2026 replace the RJCS?
No. The Regulation implements matters laid down in RJCS, including the platform, risk matrix, minimum measures and verification criteria. The two acts must be read together.
Consult Regulation →How do I know my organization is covered?
It is necessary to analyze type of entity, sector or subsector, size, establishment and any special rules. The simulator supports the analysis but is not an administrative decision.
Analyze the scope →Does the entity choose whether it is Essential or Important?
No. The qualification shall be decided by the competent cybersecurity authority after the self-identification and hearing of those concerned.
See the qualification path →There is an account MyCiber per sector?
No. The platform provides for an account and a provisional registration per entity, regardless of the number of sectors or subsectors of activity.
Prepare MyCiber →The result of the simulator MyCiber Is it binding?
No. The automated solution is informative, does not bind the Administration and does not dispense with self-identification when mandatory.
Understand the difference →PCP Does that mean continuity plan?
Not in this framework. PCP means permanent contact point. It is the person, team or third party notified to ensure availability of contact.
Distinguishing roles →Can I choose the Basic, Substantial or High Level?
No. The level results from the applicable risk matrix. The entities at the Substantial and High levels also apply the measures of the lower levels.
View levels →Does having an approved policy prove that the measure is implemented?
Not always. Policy demonstrates decision and guidance, but execution may require factual and technical evidence, such as records, configurations, tests and samples.
Types of evidence →What features should have good evidence?
It shall be relevant to the current measure, attributable, intact and sufficient to support the conclusion that the measure has been applied.
Organize implementation →Do all entities apply the same measures?
No. The measures shall depend on the relevant qualification, level or group, residual risk and any additional sectoral rules.
Explore domains →Can I rely on automatic alerts to meet incident deadlines?
No. The platform may issue alerts, but the absence or impossibility of issuing does not waive timely compliance with obligations.
Consult critical rules →A voluntary notification requires registration in MyCiber?
No. The Regulation provides that the voluntary notification of relevant information does not require authentication or registration of the natural or legal person.
Consult articles →Does the process end after qualification?
No. The entity shall keep the information up to date and use the platform for communications, documents, notifications, incidents and other relevant acts.
View continuous operation →CyberComply is part of MyCiber?
No. MyCiber is the official platform managed by CNCS. CyberComply is an external product that can support compliance management, documentation and evidence.
Visit CyberComply ↗We didn't find any results. Try another term or select all themes.
Acronies
Acronyms to understand the context.
Editorial selection of acronyms relevant to cybersecurity, governance, continuity, cloud, data protection and technical implementation. The same acronym may have different meanings depending on the context.
137 acronyms available.
Regulation, standards and governance18 entries
Network and Information Systems Direction 2
Directive (EU) 2022/2555 on measures to ensure a high common level of cybersecurity in the Union.
Digital Operational Resilience Act
European Regulation on digital operational resilience of the financial sector.
Cyber Resilience Act
European Regulation on horizontal cybersecurity requirements for digital products.
European Accessibility Act
European Accessibility Act, transposed to establish accessibility requirements for certain products and services.
General Data Protection Regulation
Regulation (EU) 2016/679 on the protection of personal data and free movement of such data.
General Scheme for the Protection of Infringement Reporters
Portuguese regime for the protection of whistleblowers, approved by Law 93/2021.
Digital Services Act / Digital Services Regulation
European Regulation applicable to intermediate services and digital platforms.
Cybersecurity Legal Scheme
Portuguese scheme approved by Decree-Law No. 125/2025, transposing the Directive NIS2.
National Cybersecurity Reference Framework
National reference that organizes cybersecurity objectives, categories and controls.
National Cyberspace Security Strategy
National strategic instrument defining priorities and objectives for cyberspace security.
National Cybersecurity Strategy
General international designation for a national cybersecurity strategy.
Business Continuity Management System
Business continuity management system; in Portuguese, continuity management system.
European Cybersecurity Skills Framework
TESTS European reference for professional cybersecurity profiles, skills, knowledge and tasks.
Cloud Computing Compliance Criteria Catalog
BSI catalog with criteria to assess information security in cloud services.
Statement of Application
Declaration of applicability identifying selected controls, exclusions and their justification in an information security management system.
Third-Party Risk Management
Risk management associated with suppliers, providers and other third parties.
Environmental, Social and Governance
Environmental, social and governance dimensions used in evaluation and organizational management.
General Corruption Prevention Scheme
Portuguese corruption prevention scheme applicable to the entities concerned.
Functions and service models9 entries
Chief Information Security Officer
Leadership function responsible for information security strategy and governance.
Virtual Chief Information Security Officer
External professional ensuring leadership of information security with defined mandate and scope.
CYMBER the Service
Continued leadership and cybersecurity governance service, which can integrate vCISO, team, method, delivery and continuity.
Cybersecurity Officer
Documentary convention used by Cyberprotech for the person designated pursuant to Article 31 of the RJCS; the legislation does not define this acronym.
Permanent Accountct Point
Person or team notified to ensure permanent contact under the RJCS; in this context does not mean continuity plan.
Accountct Point Permanent Service
Service model to operationalise reception, sorting, registration, activation and scaling of cybersecurity communications.
Data Protection Officer / Data Protection Officer
Function provided for in RGPD to advise, monitor compliance and cooperate with the supervisory authority.
Qualified Service Provider
Qualified provider; the range depends on the regime or program in which the designation is used.
Qualified Trust Service Provider
Qualified provider of trust services under the applicable European framework.
Operations and incident response18 entries
Security Operations Center
Security operations center dedicated to operational monitoring, detection, analysis and coordination.
Cybersecurity Operations Center
Variant designation SOC which explains the focus on cybersecurity operations.
Computer Security Incident Response Team
Team responsible for receiving, analysing, coordinating and responding to computer security incidents.
Computer Emergency Response Team
Name used by incident response teams; use of the name may depend on specific authorization or affiliation.
Product Security Incident Response Team
Team dedicated to product related vulnerabilities and safety incidents.
Incident Response
Incident response, including preparation, analysis, containment, eradication, recovery and learning.
Cyber Incident Planning and Response
Planning and responding to cybersecurity incidents.
Security Information and Event Management
Technology for gathering, correlation, research and analysis of events and security information.
Managed Detection and Response
managed detection, investigation and threat response service.
Managed Threat Hunting
Managed service of proactive search for threats that have not yet been detected by automatic mechanisms, supported by hypotheses, telemetry and specialized analysis.
Endpoint Detection and Response
Ability to detect, investigate and respond in endpoints.
Extended Detection and Response
Detection and response correlation between multiple technological layers.
Cyber Threat Intelligence
Knowledge analyzed about threats, agents, capabilities, intentions and relevant indicators.
Tactics, Techniques and Procedures
Behavior patterns used to describe the form of action of threat agents.
Business Email Compromise
Fraud or commitment that exploits e-mail and organizational trust.
Known Exploited Vulnerabilities
Known vulnerabilities with confirmed exploitation, often prioritized in the management of corrections.
Vulnerability Assessment and Penetration Testing
Evaluation of vulnerabilities and intrusion tests, with different objectives and depths.
Network Operations Center
Operations center focused on availability, performance and network and infrastructure management.
Vulnerability and coordinated dissemination8 entries
Common Vulnerabilities and Exposures
Public and standardized identification system of known vulnerabilities.
CVE Numbering Authority
Organization authorized to assign identifiers CVE within its scope.
Coordinated Vulnerability Disclosure
Coordinated process of communication, analysis, correction and dissemination of vulnerabilities.
Vulnerability Disclosure Program
Program establishing channels, rules and expectations for responsible reporting of vulnerabilities.
Common Security Advisory Framework
Structured format for publication and exchange of machine-readable safety warnings.
European Vulnerability Database
European Vulnerability Database maintained by TESTS.
Common Vulnerability Scoring System
Technical scoring system of severity of vulnerabilities; it does not replace contextual risk analysis.
Bill of Materials Software
Structured inventory of components that integrate a product or software application.
Risk, projects and methodologies6 entries
Business Impact Analysis
Business impact analysis used to identify critical activities, impacts and recovery needs.
Preliminary Risk Analysis
Initial analysis to identify hazards, scenarios, consequences and preventive measures.
Root Cause Analysis
Root cause analysis to identify underlying factors and avoid recurrence.
Enterprise Risk Management
Integrated risk management relevant to the objectives of the organization.
Scope of Work / Statement of Work
Document delimiting scope, activities, deliverables, responsibilities and conditions of execution.
Development Life Cycle Software
Lifecycle of software development, from design to maintenance and withdrawal.
Cloud and technological services14 entries
Cloud-Native Application Protection Platform
Platform that brings together security capabilities for cloud-native applications and loads throughout its life cycle.
Cloud Access Security Broker
Control and visibility layer between users, organizations and cloud services.
Cloud Management Platform
Cloud resource management, governance and operation platform.
Cloud Workload Protection Platform
Workload protection platform in cloud and hybrid environments.
Cloud Service Provider
Cloud service provider. The acronym CSP can also mean Content Security Policy in web security.
Bring Your Own License
Model for using existing licenses in a compatible service or environment.
Bare Metal Restore
Full recovery of a system for hardware or environment without equivalent prior installation.
Backup the Service
Managed service of copying, retention and recovery of data.
Disaster Recovery as a Service
Technical recovery service after disaster or serious unavailability.
Storage as a Service
Storage capacity available as a service.
Firewall as a Service
Firewall functions provided as a service, often through cloud architecture.
Secure Access Service Edge
Architecture that combines connectivity and security controls delivered as service.
Security Service Edge
A cloud set of access security capabilities, usually integrated into a SASE architecture.
SaaS Security Posture Management
Continuous configuration management and security posture of SaaS applications.
Continuity, backup and recovery8 entries
Business Continuity
Continuity of business or activity to disturbance.
Disaster Recovery
Recovery of technological systems and services after disaster or serious failure.
Recovery Time Objective
Target time to restore an activity, system or service after interruption.
Recovery Point Objective
Maximum permissible data loss point, expressed in time.
Maximum Tolerable Period of Disruption
Maximum tolerable period during which an activity may remain interrupted.
Minimum Business Continuity Objective
Minimum acceptable level of products or services during a disturbance.
Grandfather-Father-Son
Copy rotation scheme with daily, weekly and monthly or equivalent retention cycles.
Write Once, Read Many
Storage model that prevents or limits data change after recorded.
Data, identity and access control19 entries
Date Loss Prevention
Controls to prevent exposure, transfer or improper loss of data.
Hardware Security Module
Device dedicated to the generation, protection and safe use of cryptographic keys.
Elliptic Curve Cryptography
Elliptical curve encryption used in public key mechanisms.
Post-Quantum Cryptography
Encryption designed to withstand attacks from sufficiently capable quantum computers.
Quantum Key Distribution
Distribution of cryptographic keys using quantum communication properties.
Privileged Access Management
Management and control of privileged accesses.
Identity and Access Management
Identity management, authentication, authorizations and life cycle of accesses.
Roll-Based Access Control
Access control based on functions assigned to users.
Attribute-Based Access Control
Access control based on subject attributes, resource, action or context.
Discretionary Access Control List
Discretionary list defining access permissions to an object.
Network Access Control
Network access control based on identity, device, posture and policy.
Intrusion Detection System
System for detecting suspicious activities or intrusions.
Intrusion Prevention System
System that detects and can block suspicious activities or intrusions.
Local Privilege Escalation
Local scale of privileges in a compromised or accessed system.
Windows Defend Application Control
Microsoft application control technology and code authorized to execute.
Multi-Factor Authentication
Authentication that requires factors of different categories.
Single Sign-On
Mechanism allowing access to multiple services via centralized authentication.
Public Key Infrastructure
Trust infrastructure for digital certificates, public keys and their life cycle.
Content Security Policy
Web security policy sent by the server to restrict executable or downloadable origins and types of content.
Internet, DNS and networks12 entries
DNS over HTTPS
DNS resolution carried over HTTPS.
DNS over TLS
DNS resolution transported directly on TLS.
Session Traversal Utilities for NAT
Protocol that helps applications identify addresses and cross certain NAT scenarios.
Software-Defined Networking
Software-defined networks with logical separation between control and forwarding.
Autonomous System Number
Number identifying an autonomous system when routing between Internet networks.
Regional Internet Registry
Regional register responsible for managing and allocating numerical resources from the Internet.
National Internet Registry
National register managing Internet numerical resources under an RIR.
Protected Management Frames
Encryption protection of certain management frameworks on Wi-Fi networks.
Next-Generation firewall
Firewall with additional inspection, enforcement and threat prevention capabilities.
Virtual Private Network
Secured logical connection over an unreliable or shared network.
Transport Layer Security
Cryptographic protocol to protect communications in transit.
Domain Name System
Distributed system linking domain names to technical information, including network addresses.
Artificial intelligence and automation5 entries
Artificial Intelligence Security Posture Management
Management of safety posture of systems, models, data and artificial intelligence services.
Robotic Process Automation
Repetitive task automation through configured software to run defined streams.
Retrieval-Augmented Generation
Technique that combines information recovery with generation of responses by a model.
Model Context Protocol
Protocol to integrate artificial intelligence applications with tools and context sources. The acronym may have other meanings in other domains.
Generating Engine Optimization
Optimization of content to improve its understanding and use by generative mechanisms without ensuring citation or recommendation.
Management, Business and Training14 entries
IT Service Management
Structured management of information technology services.
Total Cost of Ownership
Total cost of acquisition, operation, maintenance and withdrawal of a solution throughout your life cycle.
Original Equipment Manufacturer
Original manufacturer of equipment or components supplied to other brands or integrators.
Business-to-business
commercial or service relations between organizations.
Business-to-government
Relationship between companies and public entities, including hiring and providing services.
Public-Priva Partnership
The contractual model of cooperation between public and private entities subject to the applicable framework.
Small and Medium Enterprise / Small and Medium-sized Enterprise
Business classification determined by criteria such as actuals, turnover and balance sheet.
Corporate Public Entity
Public collective person of a corporate nature integrated into the public business sector.
Massive Open Online Course
Open online course designed for large-scale participation.
Open Educational Resources
Open educational resources, provided with conditions that allow use and adaptation.
Continuing Professional Education
Continuing vocational education to maintain or develop skills.
Science, Technology, Engineering and Mathematics
Areas of science, technology, engineering and mathematics.
Educational Technology
Technology applied to education teaching, learning and management.
Highly Qualified Human Resources
Name used in specialized qualification and employment programs and policies.
Systems and architecture6 entries
Model-View-Controller
Architecture pattern that separates data, presentation and interaction logic.
Open Policy Agent
Open source policy engine for rules-based authorization and compliance decisions.
Unified Communications and Collaboration
Integration of communications, presence, meetings and collaboration into a common architecture.
Software Supply Chain Security
Software supply chain security, including code, dependencies, tools and delivery processes.
Enterprise Mobility Management
Integrated management of enterprise mobile devices, applications, content and identities.
Mobile Device Management
Centralised management of the configuration, posture and life cycle of mobile devices.
We did not find acronyms with these criteria.
This index explains the meaning normally used by Cyberprotech. It does not replace the constant definition of applicable legislation, standard, contract, manufacturer or benchmark.
Primary sources
Legal definitions must be confirmed in the official act.
RGPD
NIS2
DORA
OTHER
The definitions marked as summarized or operational facilitate reading and do not replace the full text of official acts.