defencia/knowledge/abbreviations
Glossary · DFIR · Governance

Abbreviations

A glossary of the DFIR and governance abbreviations that come up most often — handy when the acronyms start flying.

Glossary

DFIR

TermMeaning
Image / Image fileA raw copy of original hardware (HDD, SSD, SD, USB).
ActioncardA short, descriptive way of approaching a task, aligned with management expectations.
CTFCapture The Flag — a challenge to find hidden treasures.
CoCChain of Custody — documenting when and how evidence changes hands.
DDData Duplication — an uncompressed image file format.
DFIRDigital Forensics and Incident Response.
E01EnCase image file (raw drive data); compressed or uncompressed.
ForensicsA scientific way of finding the truth of what happened.
Live Image BootBootable drive (e.g. CAINE, Paladin) for acquisition where hardware can't be removed.
Live triageTriage and acquisition from a running system.
PlaybookA guided way of approaching a problem (see also actioncards).
Triage / SWB / WBQuick pre-analysis · Software Write-Blocker · Write-Blocker.

Governance

TermMeaning
BCPBusiness Continuity Plan (a.k.a. contingency / beredskabsplan).
CBCertification Body — responsible for e.g. ISO certification.
CMMCCybersecurity Maturity Model Certification.
FUDFear, Uncertainty and Doubt.
GRCGovernance, Risk Management and Compliance.
Risk appetiteThe level of risk an organisation is willing to accept.
PCI DSSPayment Card Industry Data Security Standards.
TNO / ZTTrust No One · Zero Trust — strict access control and encryption around your data.