Toolbox

All tools in the Toolbox

Appendix F · Reference

Glossary and resource catalogue

Acronym index, a glossary of the central terms and a catalogue of authorities, standards and reporting routes. Search in the field below to filter.

Acronym index

AEL
Annual Expected Loss.
AI
Artificial intelligence.
API
Application Programming Interface.
APT
Advanced Persistent Threat.
BCP
Business Continuity Plan.
BIA
Business Impact Analysis.
CE
Conformite Europeenne. European product conformity marking.
CEO
Chief Executive Officer.
CER
Critical Entities Resilience. EU directive on the resilience of critical entities.
CERT-SE
The Swedish national CSIRT, part of NCSC.
CFO
Chief Financial Officer.
CIA
Confidentiality, Integrity, Availability.
CIO
Chief Information Officer.
CIS
Center for Internet Security.
CISO
Chief Information Security Officer.
CLOUD Act
Clarifying Lawful Overseas Use of Data Act. United States.
COM-B
Capability, Opportunity, Motivation, Behavior. Model of behaviour.
CRA
Cyber Resilience Act. EU cybersecurity regulation for products.
CSIRT
Computer Security Incident Response Team.
CSL
The Swedish Cybersecurity Act (2025:1506).
CTI
Cyber Threat Intelligence.
DCS
Distributed Control System.
DLP
Data Loss Prevention.
DMZ
Demilitarized Zone.
DNS
Domain Name System.
DORA
Digital Operational Resilience Act. EU regulation for the financial sector.
DPIA
Data Protection Impact Assessment.
EES
European Economic Area (EEA).
ENISA
European Union Agency for Cybersecurity.
EU
European Union.
EUCS
European Cybersecurity Certification Scheme for Cloud Services.
FIPS
Federal Information Processing Standards. United States.
FISA
Foreign Intelligence Surveillance Act. United States.
FMV
Swedish Defence Materiel Administration.
FRA
Swedish National Defence Radio Establishment.
GDPR
General Data Protection Regulation. The EU data protection regulation.
GNSS
Global Navigation Satellite System.
GPS
Global Positioning System.
GRC
Governance, Risk and Compliance.
HMI
Human-Machine Interface.
HR
Human Resources.
IAM
Identity and Access Management.
IEC
International Electrotechnical Commission.
IKT
Information and communications technology (ICT).
IMY
Swedish Authority for Privacy Protection.
IP
Internet Protocol.
IRT
Incident Response Team.
ISMS
Information Security Management System (LIS in Swedish).
ISO
International Organization for Standardization.
IT
Information technology.
ITIL
Information Technology Infrastructure Library.
LEC
Loss Exceedance Curve.
LEK
Swedish Electronic Communications Act (2022:482).
LIS
Swedish term for an information security management system (equivalent to ISMS).
MCF
Swedish Civil Defence Agency (formerly MSB).
MCFFS
Code of statutes of the Swedish Civil Defence Agency.
MDR
Managed Detection and Response.
MEUR
Millions of euro.
MFA
Multi factor authentication.
MISP
Malware Information Sharing Platform.
MISP-SE
Swedish national platform for threat intelligence sharing.
MPF
Swedish Agency for Psychological Defence.
MSB
Swedish Civil Contingencies Agency (reshaped into MCF in 2026).
MSBFS
Code of statutes of the Swedish Civil Contingencies Agency.
MSEK
Millions of Swedish kronor.
MSSP
Managed Security Service Provider.
MTPD
Maximum Tolerable Period of Disruption. The longest a critical process can be down before the business is seriously threatened.
NATO
North Atlantic Treaty Organization.
NCSC
Swedish National Cybersecurity Centre (part of FRA).
NIS
Network and Information Security. EU directive 2016/1148.
NIS2
EU directive 2022/2555 on cybersecurity.
NIST
National Institute of Standards and Technology. United States.
OSL
Swedish Public Access to Information and Secrecy Act (2009:400).
OT
Operational Technology.
PDCA
Plan-Do-Check-Act. Improvement cycle.
PIR
Priority Intelligence Requirements.
PKI
Public Key Infrastructure.
PLC
Programmable Logic Controller.
PTS
Swedish Post and Telecom Authority.
RFID
Radio-Frequency Identification.
RPO
Recovery Point Objective. Target for maximum tolerable data loss.
RTO
Recovery Time Objective. Target for maximum tolerable recovery time.
SBOM
Software Bill of Materials.
SCADA
Supervisory Control and Data Acquisition.
SCC
Standard Contractual Clauses.
SIEM
Security Information and Event Management.
SIS
Swedish Institute for Standards.
SLA
Service Level Agreement.
SoA
Statement of Applicability. Statement of which controls apply, which do not, and why.
SOAR
Security Orchestration, Automation and Response.
SOC
Security Operations Center.
SOU
Statens offentliga utredningar, Swedish government official reports.
STIX
Structured Threat Information eXpression.
SWOT
Strengths, Weaknesses, Opportunities, Threats. Method for strategic assessment.
TAXII
Trusted Automated eXchange of Indicator Information.
TIA
Transfer Impact Assessment. Assessment of a transfer to a third country.
TIP
Threat Intelligence Platform.
TLP
Traffic Light Protocol.
TLPT
Threat-Led Penetration Testing.
TTP
Tactics, Techniques and Procedures.
USB
Universal Serial Bus.
VD
Verkstallande direktor, Swedish for chief executive officer.
VPN
Virtual Private Network.
WPA2/WPA3
Wi-Fi Protected Access. Encryption standard for wireless networks.
XSS
Cross-Site Scripting.

Glossary

AEL (Annual Expected Loss)
Expected annual loss. Calculated as likelihood times average consequence, and used in quantitative risk analysis to compare and prioritise risks in financial terms.
Authenticity
The property that the origin, sender and genuineness of information can be verified. Under MCFFS 2026:11 it forms part of the concept of integrity.
BIA (Business Impact Analysis)
Identifies the critical processes of an organisation, their maximum tolerable period of disruption and their dependencies on systems, suppliers and staff. The basis for continuity planning.
CERT-SE
The Swedish national CSIRT. Part of NCSC and, from July 2026, placed organisationally under FRA. Receives incident reports and issues warnings.
Compliance
Adherence to regulation. Often used in contrast to resilience: meeting the requirements on the documentation is not the same as actual resistance to attack.
Crypto agility
The ability to change cryptographic algorithms without major system change. Central ahead of the move to quantum safe cryptography.
CTI (Cyber Threat Intelligence)
The systematic collection, analysis and dissemination of information about cyber threats, their techniques, motives and indicators. A core function for preventive detection.
DLP (Data Loss/Leak Prevention)
Technology and processes preventing sensitive information from leaving the organisation, whether accidentally or through an attacker. Built on classification, monitoring and blocking.
Entity covered by the law
The party the Swedish Cybersecurity Act is aimed at. Divided into essential, important and public, which determines supervision and sanctions.
LEC (Loss Exceedance Curve)
Visualises the likelihood that a total loss over a period, usually a year, exceeds various amounts. A central tool in quantitative cyber risk analysis.
LIS
Ledningssystem for informationssakerhet, the Swedish term for what ISO 27001 calls an ISMS. Covers the policy, processes, roles and controls that govern systematic security work.
MISP-SE
The Swedish national platform for threat intelligence sharing, launched in February 2026 and run by CERT-SE. Enables sharing of indicators and analysis between participating organisations.
MTPD (Maximum Tolerable Period of Disruption)
The longest a critical process can be interrupted before the business is seriously threatened. Distinct from RTO, which is a target for recovery.
Resilience
The ability to withstand, adapt to and recover from disruption. The central goal, in contrast to invulnerability.
RPO (Recovery Point Objective)
Target for maximum data loss on recovery. It determines how often backups have to be taken: an RPO of four hours means up to four hours of data can be lost.
RTO (Recovery Time Objective)
Target for maximum recovery time. The time it may take to restore a process after an interruption. Distinct from MTPD, which is what the business can actually tolerate.
SBOM (Software Bill of Materials)
A structured list of every component, dependency and version in a piece of software. Required under the Cyber Resilience Act for products on the EU market.
Sector wide approach
The Swedish implementation of NIS2 means that if an organisation is covered, the obligations apply to the whole operation, not only to the systems delivering the essential service.
SoA (Statement of Applicability)
The central document in ISO 27001 stating which of the 93 controls in Annex A apply, which do not, and the reasoning in each case.
Sovereignty, digital
The ability to take independent decisions about digital infrastructure, data and services without depending on actors or jurisdictions you do not trust. Not an absolute level but a freedom of action that varies with context.
TIA (Transfer Impact Assessment)
Assessment of a planned transfer of personal data to a third country. Required after the Schrems II ruling to ensure the level of protection in the receiving country is sufficient.
TLP (Traffic Light Protocol)
Protocol governing onward sharing of sensitive information. Four levels: TLP:RED (the recipient only), TLP:AMBER (the recipient and their organisation), TLP:GREEN (community wide), TLP:CLEAR (open).
Traceability
The ability to establish afterwards which events affected the information and who carried them out. In practice it rests on logging. Whether traceability forms part of integrity is disputed, and MCFFS 2026:11 does not take a position.
Zero Trust
Architectural principle: always verify, never trust implicitly. No user or device is trusted merely for its place in the network.

Resource catalogue