Cybersecurity Dictionary
A comprehensive bilingual (Arabic–English) reference for cybersecurity terminology.
Access Control
Mechanisms that restrict access to resources based on identity and permissions.
آليات تقييد الوصول إلى الموارد بناءً على الهوية والأذونات.
Authentication
The process of verifying the identity of a user, device, or system.
عملية التحقق من هوية المستخدم أو الجهاز أو النظام.
Authorization
The process of granting or denying access rights to resources after authentication.
منح أو رفض حقوق الوصول إلى الموارد بعد المصادقة.
Availability
The property of being accessible and usable on demand by an authorized entity.
خاصية إمكانية الوصول والاستخدام عند الطلب من قبل كيان مصرح له.
Botnet
A network of private computers infected with malicious software and controlled as a group.
شبكة من أجهزة الكمبيوتر المصابة ببرامج خبيثة ويتم التحكم فيها كمجموعة.
Brute Force
An attack that tries all possible combinations to find a password or encryption key.
هجوم يجرب جميع التوليفات الممكنة للعثور على كلمة مرور أو مفتاح تشفير.
Certificate Authority
A trusted entity that issues digital certificates for verifying the identity of websites and systems.
جهة موثوقة تصدر شهادات رقمية للتحقق من هوية المواقع والأنظمة.
Confidentiality
The protection of information from unauthorized access or disclosure.
حماية المعلومات من الوصول غير المصرح به أو الإفصاح.
Cryptography
The science of securing information through mathematical algorithms.
علم تأمين المعلومات من خلال الخوارزميات الرياضية.
DDoS Attack
A distributed denial-of-service attack that overwhelms a target system with traffic from multiple sources.
هجوم حرمان موزع من الخدمة يُغرق نظاماً مستهدفاً بحركة مرور من مصادر متعددة.
Digital Forensics
The practice of collecting, preserving, and analyzing digital evidence for legal proceedings.
ممارسة جمع الأدلة الرقمية وحفظها وتحليلها للإجراءات القانونية.
Encryption
The process of converting readable data into an unreadable format using an algorithm and key.
عملية تحويل البيانات القابلة للقراءة إلى تنسيق غير قابل للقراءة باستخدام خوارزمية ومفتاح.
Firewall
A network security device that monitors and controls incoming and outgoing network traffic.
جهاز أمان شبكي يراقب ويتحكم في حركة مرور الشبكة الواردة والصادرة.
Governance
The framework of rules, practices, and processes by which an organization is directed and controlled.
إطار القواعد والممارسات والعمليات التي من خلالها يتم توجيه المنظمة والتحكم فيها.
Hash Function
A mathematical function that converts data of arbitrary size to a fixed-size value (hash).
دالة رياضية تحوّل بيانات ذات حجم اعتباطي إلى قيمة ذات حجم ثابت (تجزئة).
Incident Response
The methodology an organization uses to respond to and manage a cyberattack or data breach.
المنهجية التي تستخدمها المنظمة للاستجابة لهجوم إلكتروني أو اختراق بيانات وإدارته.
Integrity
The assurance that data has not been tampered with and remains accurate.
التأكيد على أن البيانات لم يتم التلاعب بها وأنها لا تزال دقيقة.
Malware
Software intentionally designed to cause damage, gain unauthorized access, or disrupt operations.
برامج مصممة عمداً للتسبب في الضرر أو الوصول غير المصرح به أو تعطيل العمليات.
Non-repudiation
The ability to prove that a message was sent and received, preventing either party from denying it.
القدرة على إثبات أن رسالة قد أُرسلت واستُلمت، مما يمنع أي طرف من إنكارها.
Penetration Testing
A simulated cyberattack to evaluate the security of a system and identify vulnerabilities.
هجوم إلكتروني محاكى لتقييم أمان النظام وتحديد نقاط الضعف.
Phishing
A social engineering attack that tricks users into revealing sensitive information via deceptive communication.
هجوم هندسة اجتماعية يخدع المستخدمين لإفصاح معلومات حساسة عبر اتصالات مضللة.
Public Key Infrastructure
A set of roles, policies, and procedures to create, manage, and distribute digital certificates.
مجموعة من الأدوار والسياسات والإجراءات لإنشاء الشهادات الرقمية وإدارتها وتوزيعها.
Ransomware
Malicious software that encrypts data and demands payment for decryption.
برامج خبيثة تشفر البيانات وتطلب دفع فدية مقابل فك التشفير.
Risk Management
The systematic process of identifying, assessing, and mitigating threats to organizational assets.
العملية المنهجية لتحديد التهديدات التي تواجه أصول المنظمة وتقييمها والتخفيف منها.
Social Engineering
Manipulation of people into performing actions or divulging confidential information.
التلاعب بالأشخاص لأداء إجراءات معينة أو الإفصاح عن معلومات سرية.
Threat Intelligence
Evidence-based knowledge about cyber threats used to inform security decisions.
المعرفة القائمة على الأدلة حول التهديدات الإلكترونية والمستخدمة لإبلاغ قرارات الأمان.
Two-Factor Authentication
A security process requiring two separate forms of identification to access a system.
عملية أمان تتطلب شكلين منفصلين من التعريف للوصول إلى النظام.
Vulnerability
A weakness in a system that can be exploited to compromise security.
ضعف في النظام يمكن استغلاله للمساس بالأمان.
Zero-Day
A previously unknown vulnerability that has been disclosed but not yet patched.
ثغرة غير معروفة سابقاً تم الكشف عنها ولم يتم إصلاحها بعد.