No matches. Try another search term.
Acronym index
- AEL
- Annual Expected Loss.
- AI
- Artificial intelligence.
- API
- Application Programming Interface.
- APT
- Advanced Persistent Threat.
- BCP
- Business Continuity Plan.
- BIA
- Business Impact Analysis.
- CE
- Conformite Europeenne. European product conformity marking.
- CEO
- Chief Executive Officer.
- CER
- Critical Entities Resilience. EU directive on the resilience of critical entities.
- CERT-SE
- The Swedish national CSIRT, part of NCSC.
- CFO
- Chief Financial Officer.
- CIA
- Confidentiality, Integrity, Availability.
- CIO
- Chief Information Officer.
- CIS
- Center for Internet Security.
- CISO
- Chief Information Security Officer.
- CLOUD Act
- Clarifying Lawful Overseas Use of Data Act. United States.
- COM-B
- Capability, Opportunity, Motivation, Behavior. Model of behaviour.
- CRA
- Cyber Resilience Act. EU cybersecurity regulation for products.
- CSIRT
- Computer Security Incident Response Team.
- CSL
- The Swedish Cybersecurity Act (2025:1506).
- CTI
- Cyber Threat Intelligence.
- DCS
- Distributed Control System.
- DLP
- Data Loss Prevention.
- DMZ
- Demilitarized Zone.
- DNS
- Domain Name System.
- DORA
- Digital Operational Resilience Act. EU regulation for the financial sector.
- DPIA
- Data Protection Impact Assessment.
- EES
- European Economic Area (EEA).
- ENISA
- European Union Agency for Cybersecurity.
- EU
- European Union.
- EUCS
- European Cybersecurity Certification Scheme for Cloud Services.
- FIPS
- Federal Information Processing Standards. United States.
- FISA
- Foreign Intelligence Surveillance Act. United States.
- FMV
- Swedish Defence Materiel Administration.
- FRA
- Swedish National Defence Radio Establishment.
- GDPR
- General Data Protection Regulation. The EU data protection regulation.
- GNSS
- Global Navigation Satellite System.
- GPS
- Global Positioning System.
- GRC
- Governance, Risk and Compliance.
- HMI
- Human-Machine Interface.
- HR
- Human Resources.
- IAM
- Identity and Access Management.
- IEC
- International Electrotechnical Commission.
- IKT
- Information and communications technology (ICT).
- IMY
- Swedish Authority for Privacy Protection.
- IP
- Internet Protocol.
- IRT
- Incident Response Team.
- ISMS
- Information Security Management System (LIS in Swedish).
- ISO
- International Organization for Standardization.
- IT
- Information technology.
- ITIL
- Information Technology Infrastructure Library.
- LEC
- Loss Exceedance Curve.
- LEK
- Swedish Electronic Communications Act (2022:482).
- LIS
- Swedish term for an information security management system (equivalent to ISMS).
- MCF
- Swedish Civil Defence Agency (formerly MSB).
- MCFFS
- Code of statutes of the Swedish Civil Defence Agency.
- MDR
- Managed Detection and Response.
- MEUR
- Millions of euro.
- MFA
- Multi factor authentication.
- MISP
- Malware Information Sharing Platform.
- MISP-SE
- Swedish national platform for threat intelligence sharing.
- MPF
- Swedish Agency for Psychological Defence.
- MSB
- Swedish Civil Contingencies Agency (reshaped into MCF in 2026).
- MSBFS
- Code of statutes of the Swedish Civil Contingencies Agency.
- MSEK
- Millions of Swedish kronor.
- MSSP
- Managed Security Service Provider.
- MTPD
- Maximum Tolerable Period of Disruption. The longest a critical process can be down before the business is seriously threatened.
- NATO
- North Atlantic Treaty Organization.
- NCSC
- Swedish National Cybersecurity Centre (part of FRA).
- NIS
- Network and Information Security. EU directive 2016/1148.
- NIS2
- EU directive 2022/2555 on cybersecurity.
- NIST
- National Institute of Standards and Technology. United States.
- OSL
- Swedish Public Access to Information and Secrecy Act (2009:400).
- OT
- Operational Technology.
- PDCA
- Plan-Do-Check-Act. Improvement cycle.
- PIR
- Priority Intelligence Requirements.
- PKI
- Public Key Infrastructure.
- PLC
- Programmable Logic Controller.
- PTS
- Swedish Post and Telecom Authority.
- RFID
- Radio-Frequency Identification.
- RPO
- Recovery Point Objective. Target for maximum tolerable data loss.
- RTO
- Recovery Time Objective. Target for maximum tolerable recovery time.
- SBOM
- Software Bill of Materials.
- SCADA
- Supervisory Control and Data Acquisition.
- SCC
- Standard Contractual Clauses.
- SIEM
- Security Information and Event Management.
- SIS
- Swedish Institute for Standards.
- SLA
- Service Level Agreement.
- SoA
- Statement of Applicability. Statement of which controls apply, which do not, and why.
- SOAR
- Security Orchestration, Automation and Response.
- SOC
- Security Operations Center.
- SOU
- Statens offentliga utredningar, Swedish government official reports.
- STIX
- Structured Threat Information eXpression.
- SWOT
- Strengths, Weaknesses, Opportunities, Threats. Method for strategic assessment.
- TAXII
- Trusted Automated eXchange of Indicator Information.
- TIA
- Transfer Impact Assessment. Assessment of a transfer to a third country.
- TIP
- Threat Intelligence Platform.
- TLP
- Traffic Light Protocol.
- TLPT
- Threat-Led Penetration Testing.
- TTP
- Tactics, Techniques and Procedures.
- USB
- Universal Serial Bus.
- VD
- Verkstallande direktor, Swedish for chief executive officer.
- VPN
- Virtual Private Network.
- WPA2/WPA3
- Wi-Fi Protected Access. Encryption standard for wireless networks.
- XSS
- Cross-Site Scripting.
Glossary
- AEL (Annual Expected Loss)
- Expected annual loss. Calculated as likelihood times average consequence, and used in quantitative risk analysis to compare and prioritise risks in financial terms.
- Authenticity
- The property that the origin, sender and genuineness of information can be verified. Under MCFFS 2026:11 it forms part of the concept of integrity.
- BIA (Business Impact Analysis)
- Identifies the critical processes of an organisation, their maximum tolerable period of disruption and their dependencies on systems, suppliers and staff. The basis for continuity planning.
- CERT-SE
- The Swedish national CSIRT. Part of NCSC and, from July 2026, placed organisationally under FRA. Receives incident reports and issues warnings.
- Compliance
- Adherence to regulation. Often used in contrast to resilience: meeting the requirements on the documentation is not the same as actual resistance to attack.
- Crypto agility
- The ability to change cryptographic algorithms without major system change. Central ahead of the move to quantum safe cryptography.
- CTI (Cyber Threat Intelligence)
- The systematic collection, analysis and dissemination of information about cyber threats, their techniques, motives and indicators. A core function for preventive detection.
- DLP (Data Loss/Leak Prevention)
- Technology and processes preventing sensitive information from leaving the organisation, whether accidentally or through an attacker. Built on classification, monitoring and blocking.
- Entity covered by the law
- The party the Swedish Cybersecurity Act is aimed at. Divided into essential, important and public, which determines supervision and sanctions.
- LEC (Loss Exceedance Curve)
- Visualises the likelihood that a total loss over a period, usually a year, exceeds various amounts. A central tool in quantitative cyber risk analysis.
- LIS
- Ledningssystem for informationssakerhet, the Swedish term for what ISO 27001 calls an ISMS. Covers the policy, processes, roles and controls that govern systematic security work.
- MISP-SE
- The Swedish national platform for threat intelligence sharing, launched in February 2026 and run by CERT-SE. Enables sharing of indicators and analysis between participating organisations.
- MTPD (Maximum Tolerable Period of Disruption)
- The longest a critical process can be interrupted before the business is seriously threatened. Distinct from RTO, which is a target for recovery.
- Resilience
- The ability to withstand, adapt to and recover from disruption. The central goal, in contrast to invulnerability.
- RPO (Recovery Point Objective)
- Target for maximum data loss on recovery. It determines how often backups have to be taken: an RPO of four hours means up to four hours of data can be lost.
- RTO (Recovery Time Objective)
- Target for maximum recovery time. The time it may take to restore a process after an interruption. Distinct from MTPD, which is what the business can actually tolerate.
- SBOM (Software Bill of Materials)
- A structured list of every component, dependency and version in a piece of software. Required under the Cyber Resilience Act for products on the EU market.
- Sector wide approach
- The Swedish implementation of NIS2 means that if an organisation is covered, the obligations apply to the whole operation, not only to the systems delivering the essential service.
- SoA (Statement of Applicability)
- The central document in ISO 27001 stating which of the 93 controls in Annex A apply, which do not, and the reasoning in each case.
- Sovereignty, digital
- The ability to take independent decisions about digital infrastructure, data and services without depending on actors or jurisdictions you do not trust. Not an absolute level but a freedom of action that varies with context.
- TIA (Transfer Impact Assessment)
- Assessment of a planned transfer of personal data to a third country. Required after the Schrems II ruling to ensure the level of protection in the receiving country is sufficient.
- TLP (Traffic Light Protocol)
- Protocol governing onward sharing of sensitive information. Four levels: TLP:RED (the recipient only), TLP:AMBER (the recipient and their organisation), TLP:GREEN (community wide), TLP:CLEAR (open).
- Traceability
- The ability to establish afterwards which events affected the information and who carried them out. In practice it rests on logging. Whether traceability forms part of integrity is disputed, and MCFFS 2026:11 does not take a position.
- Zero Trust
- Architectural principle: always verify, never trust implicitly. No user or device is trusted merely for its place in the network.
Resource catalogue
- Swedish Civil Defence Agency (MCF) Registration, incident reporting, regulations, methodological support. In Swedish.
- National Cybersecurity Centre (NCSC) Situational awareness, warnings, coordination. In Swedish.
- CERT-SE The national CSIRT. Incident support, threat intelligence, MISP-SE. In Swedish.
- Swedish Authority for Privacy Protection (IMY) Reporting of personal data breaches under GDPR. In Swedish.
- Swedish Agency for Psychological Defence (MPF) Guidance on disinformation and influence operations. In Swedish.
- Swedish Security Service Protective security matters and threat assessments. In Swedish.
- Swedish Institute for Standards (SIS) ISO 27001, ISO 42001, IEC 62443 and the other standards.